Help! With TROJ_GEN.RFFC2CU Here Are My Logs.

After reading a combofix log, I was startled to find that system32 was infected...repeatedly. I've added a HijackThis log and an aswmbr log.

Then it will reconnect itself, and although it pauses, the computer resumes working properly, although slow.

I was running a "Trend Micro Internet Security Pro" scan on all the machines at work and I have one that is infected with TROJ_Gen.4X0444 in file name lzx32.sys. Using an audio editor while an antivirus is working in the background is impossible.

Generic detections are usually a heuristics engine detection of possible new variants of malware before the vendor can get samples and update the program's definitions for detection.

I have had several attempts at deleting this virus, beginning with ccleaner, malwarebytes and then combofix. I still had the virus and unable to open google - see error report "ERROR 404 http://www.google.com/support/bin/topic.py?topic=360"

I tried to scan the computer in safe mode and I found out that Windows/System32/services.exe was infected. The actual message reads "An untreatable virus has infected one of your files."

Virut is a polymorphic file infector which infects the executable files (.exe) including critical Windows files, and screensaver files (.scr) corrupting them beyond repair in most cases.

I tried to reinstall and scan the computer but a message popped up telling me that Windows had encountered a problem and had to restart in 1 minute. On reboot following the MBAM scan (quarrantining and 'deleting'), windows system config.

Malware, though, such as Trojans, scripts, overwriting viruses and joke programs which are identified as uncleanable, should simply be deleted. Now, cybercriminals use Trojans to gain profit by stealing user data like banking credentials and personal identifiable information (PII).

House call says its TROJ_GEN.R1ECDFT & TROJ_SPNR.19FH12. About a week ago i told it to remove the files then it said i had to restart my computer once it was done.

To enter System Recovery Options from the Advanced Boot Options:Restart the computer.As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.Use the arrow keys c:\windows\system32\lsass.exe . . . The list is not all inclusive. Copy and paste all logs requested in you reply, Do not attach them unless asked too.

For non-Trend Micro customers, scan your system with HouseCall, our highly popular and capable on-demand scanner for identifying and removing viruses, Trojans, worms, unwanted browser plug-ins, and other malware.


To change to the new SSD on NB1 (Notebook1) I cloned the old HD to the new SSD. Then I put the SSD in NB1's harddisk slot.

When I delete the autorun.exe file and the "ice" folder, it clears and then they replicate in about 3-5 seconds. After 2 hours of a full system scan, it turns out that the malware has spread far and wide, infecting around 2500+ files.