Generic.tfr!k!D9296BE​1A117 Trojan Virus and how to clean

This Trojan virus is simple to clean but if left untreated, it will enter into your source data applications in windows and corrupted your system.

To clean, simply run your anti virus software, we suggest Microsoft Security Essentials. If your anti-spyware app closes, this means the virus has blocked access to your app. You may either do a system scan online via Panda, or try running your antispyware in safemode.

Other Aliases from other anti virus companies

Company
Virus Names
AVG (GriSoft) Generic19.BWBB
Microsoft Trojan:Win32/Rodecap.A
norman W32/Malware.TUMA

The following files were analyzed:

3766d83c6754d41c912c87b1f001fe2a1eea6747

The following files have been added to the system:
  • %WINDIR%\cmstp.exe
  • %USERPROFILE%\Local Settings\Application Data\ieudinit.exe
  • %APPDATA%\esentutl.exe
  • %WINDIR%\SYSTEM32\drivers\mqtgsvc.exe
The following registry elements have been created:
  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\
  • HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\
The following registry elements have been changed:
  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS\LOAD = %WINDIR%\SYSTEM32\drivers\mqtgsvc.exe
  • HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\CMSTP = %WINDIR%\cmstp.exe /waitservice
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\IEUDINIT = C:\DOCUME~1\ADMINI~1.VMG\LOCALS~1\APPLIC~1\ieudinit.exe /waitservice
  • HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN\ESENT UTL = C:\DOCUME~1\ADMINI~1.VMG\APPLIC~1\esentutl.exe /waitservice
 

Generic BackDoor!djf!5D41C80E​A0DA malware Trojan Virus

These files were added to the system:

  • %APPDATA%\services.exe
  • %TEMP%\e3c1c08557a0d0feee33b9c9d18b4e6c129b553f.exe

This Trojan will attempt to fiddle with your network conection, e.g hxxp://www.maxmind.com/app/***

Virus app’s
Detection Names
EMSI Software Trojan.Backdoor.Ircbot!IK
avast Win32:Ruskill-F
Kaspersky Backdoor.Win32.IRCBot.tjd
BitDefender Backdoor.Bot.138642
Microsoft VirTool:Win32/CeeInject.gen!EI
Symantec Backdoor.IRC.Bot
Eset a variant of Win32/Injector.GLN trojan
norman W32/Suspicious_Gen3.TYCW
Sophos Mal/Generic-L
Trend Micro PAK_Generic.001
vba32 Backdoor.IRCBot.tjd

How to remove Generic BackDoor!djf!5D41C80E​A0DA

Removal should be easy given the fact that you are able to follow directions ;)

First thing to do is disconnect your network or internet. Now you will need to reboot your PC and enter safe mode, if you do not know how to enter safe mode, please search above for ” how to enter safe mode”

Now you will need to do a system scan using these apps below:

1. your favorite virus app, i suggest AVG or Microsoft security essentials
2. do a system scan using Malwarebytes
3. do a system scan using spybot
4. do a system scan using hijackthis

if the virus  is not letting you do these scans, you must :

1.Disable System Restore on Windows ME and windows XP only.
2.Update to current engine and DAT files for detection and removal.
3.Run a complete system scan.

This should remove the threat, this threat is a low security threat but never the less it should always be cleaned before using the world wide web.