The original version of this page can be found at : http://forum.bullguard.com/forum/10/How-to-remove-Trojan-horse-gen_60660.html
Posted By : Thinh - 3-19-2008 10:16
When I open any partitions of my computer first time then AVG antivirus inform that my computer is infected with Trojan Horse Generic 10.BJE with the location of the file is: E:\ta2.cmd (If I open partition E), C:\ta2.cmd (If I open partition C)... When I open this partition second time then appear the window: "choose the program you want to use to open this file:
File: C:\ (or F:\) (Picture).
 

Posted By : Doctor Jim - 3-20-2008 3:17
If your computer is infected with the AMVO.exe and/or ta2.cmd, you will be unable to access your disk drives by double-clicking on the drive icons. Most antivurs programs will be able to detect these viruses but will be unable to successfully remove them.
The following are the steps i did to rid my computer of this problem. I hope this step-bystep instruction list will be of help! :-)

1. dont double-click on any disk drive icon on My Computer. Clicking this will activate the virus.
should you really have to access a drive, click the START button, click run, then type C: or D: or E:, depending on the drive letter you wish to access.
2. download a free version of ESEt NOD32 antivirus. It is sensitive to ta2.cmd and amvo.exe viruses. However you must disable your existing AV program
3. run the antivirus and allow the AV to delete/heal all found threats.
4. After the scan, press CTRL+ALT+DEL
5. In the Procceses tab, end the process of EXPLORER.exe
6. Click file tab
7. Click New Task.
8. Type CMD. The black Command prompt will pop out.
9. On the prompt, type del /a:h /f c:\autorun.*
the virus makes an autorun.inf file which is invisible to any windows search (even if hidden files are shown). doing step #9 will erase this autorun file.
10. If you have multiple drive/partition, repeat this step to all drive/partition (including removable disks), replacing "C:" with the appropriate drive letter.
11. search whether there are remnants of the virus which the AV failed to find. Type the following:
cd c:\windows\system32
12. Type dir /a:h /f amvo*.*
13. If you find a file named amvo.exe, amvo0.exe, or amvo0.dll, type:
del /a:h /f amvo*.exe

and
del /a:h /f amvo*.dll

14. Disable the virus which might have been put in autoplay during startup. Click on the START button. Click run and then type: MSCONFIG
15. go to Startup tab and uncheck amvo.exe
16. Remove traces of the viruses which might be left in the memory registry. Leaving them untouched may lead to the viruses' re-activation. Click on the START button. Click Run and type regedit.
17. Click on the edit tab, then the find button. search for these:
amvo
amvo*
amvo.exe
amvo*.*
ta2.cmd

whenever your search finds any of the mentioned files, delete the button where the file is found (located on the right window). after deleting, click f3 to find similar files in other pockets of the registry. when further copies are found, keep on deleting until the entire registry is rid of the mentioned virus files.
18. to make sure that the computer will not automatically revert back to the previous problematic settings. go to My Computer. right click and go to properties. go to system restore. Check the Turn OFF system restore.
19. Remember that up to this point you should not double click on any drive icon on the My Computer folder, for whatever reason.
20. Reboot your computer.
21. At this point your computer should be free of ta2.cmd and amvo.exe viruses. you may now double-click on any drive on My Computer.
22. return to My Computer properties and un check the Turn Off System restore Button.
 
good luck with your computer!

Posted By : Thinh - 3-20-2008 11:09
OK, I will try! Thank you very much!
I scaned with NOD32 and found amvo.exe in system32. First, I think that scan with AVG has already cleaned ta2.cmd and my computer is clean but the AVG could't find amvo.exe . So, I have spent all the day with Hijackthis and received no result. Now my computer is in progress of scanning. When the scan is finished, I will do next steps and tell you the last result. I think everything will be OK.

Posted By : Thinh - 3-21-2008 9:01
After I have finished the steps you told, amvo.exe and ta2.cmd are destroyed.My computer is clean. Now I can access my disk drives by double-click on the drive icons. Thank you Doctoc Jim very very much!

Posted By : Doctor Jim - 3-22-2008 3:42
thinh, try checkin if you are able to view your hidden files.  ta2.cmd and amvo affects that. go to My Computer. go to tools. go to
folder options. go to view. select show hidden files. click apply then ok. then go back to check if the show hidden files is still selected. if it automatically select back to "do not show hidden files" tell me. :-)

Posted By : Thinh - 3-22-2008 7:05
Doctor Jim!
When I select "show hidden files", it automatically select back to "do not show hidden files". This means my computer is still infected with ta2.cmd, amvo or I didn't completely clean them. Please tell me what do I have to do?


I'm a vietnamese!


Posted By : Doctor Jim - 3-24-2008 7:40
hi thinh!
 
here's what you can do.
 
1. click start button
2. click run
3. type cmd, then ok
4. type c:\windows\system32, then enter
5. type del /a:h /f amvo*.*
6. click my computer
7. right click then properties, then click system restore
8. check "turn off system restore", then ok
9. click start button
10. clcik run
11. type regedit, then ok
12. click edit, then find.. then type amvo.exe
13. if the computer can find a file, delete the on the right window the highlighted icon which contains the amvo.exe.
14. click F3, if computer finds another amvo.exe delete. keep on clciking f3 then delete until the computer cannot find any amvo.exe anymore.
15. do the same thing for amvo.dll and amvo0.dll
16. restart computer
17. clcik start, regedit, then ok
18. open the folder HKEY_CURRENT_USER....then under  it the folder software, then microsoft, then windows, then current version, then explorer, then advanced.
19. on the right window double click on the icon hidden, then type the value 1.
19. back on the left window, open the folder HKEY_LOCAL_MACHINE\microsoft\windows\current version\explorer\advanced\folder\hidden\showall.
20. on the right window, double click on checked value, then type the value 1.
21. restart computer.
22. go to my computer, then right click, then properties, system restore. then uncheck "turn off system restore".
23. woopeedoo! your computer is now ok! :-)
 
i'm filipino, by the way :-)

Posted By : peterdab - 3-24-2008 11:28
Hy there

I´ve had the same problem. I´ve done all these steps and now my computer is clean from the virus and traces but I still can´t double click on c: and d:.
It appears again the "choose the program you want to use to open this file:"

I´ve pressed examinate and chose the explorer.exe and it worked but I have to do this any time I want to open c:
How do I fix this? Don´t know how to get back the double click working


any idea?

thanks

Posted By : Thinh - 3-25-2008 12:16
Thank Doctor Jim!
I have done the steps you told and now I can show hidden files!
Hey, we are neighbours!
to: peterdab!
1/In the command prompt I type dir /a:h C:\autorun.*, I find the file named autorun.inf. Try to do this! If you find this file, delete it by command: del /a:h /f C:\autorun.inf. Do the same steps for other partitions!
2/Maybe you have omitted any step? Start from beginning to end again!
This is my idea, I don't know it helps you or not.


I'm vietnamese!

Post Edited (Thinh) : 24-03-2008 23:36:42 GMT


Posted By : peterdab - 3-25-2008 12:42
thanks man!!!. that was the problem

Happy to have my hard disk back:D

Posted By : oroggi - 3-29-2008 1:38
2 Doctor Jim:

Thanks for advise how to enable displaying hidden files after attack by amvo virus!

It was very useful for me!!

Posted By : +++CroW+++ - 5-4-2008 8:47
hey doctor Jim..I have a problem in my PC..I have avg internet security 8 and it is great..!It has blocked many things but every day i put in my vault a files from Trojan horse Generic10!!And when I start me pc it says error..but there are no practical problems..!how can i clean me pc
 totally?

Posted By : +++CroW+++ - 5-4-2008 9:23
this is what i have in my vault..!
Trojan horse Generic10.QHJ
Trojan horse Vundo.N
Trojan horse Generic10.SHE
Virus Vundo
 
but they are all in vault and have not problems..but every day there is a new .dll in vault!
Anyone can help me:S?

Posted By : Doctor Jim - 5-25-2008 1:49
i read ur message just now. sorry for late reply. og the various antivirus programs, AVG is one of the weakest. i suggest you uninstall your AVG, then download a free copy of ESET NOD32. it would run for 90 days, after which search for a crack to have it activated unlimitedly. the 2 most effectve anti virus programs are Kaspersky and ESET NOD32. i use eset. i hope this helps!

doctor jim

Posted By : meshel - 6-13-2008 7:52
please help!!
 
my computer is infected with a trojan hourse generic 10 virus...... im not sure whats causing this problem but i cant access google, yahoo, download, or mayspace.. when i try to entre, the page just lags and it just does not go through!...... can anyone please help me

Posted By : kscullin - 7-2-2008 2:33
My wife got a nice copy of Generic 10 on her computer. I put a copy of NOD32 on it (had to download and burn it on my computer), disabled her AVG 8 and ran it. It seemed to go OK that far, but I have a twist.
 
Among other things, her Generic 10 has disabled the taskmanager. I can't even run it directly from the "run" command; it just does nothing at all - no error messages, nothing.
 
In Windows XP, is there another way I can access the running processes to continue with Dr. Jim's instructions? If I knew of one, I've forgotten it.
 
Thanks in advance.

Posted By : Doctor Jim - 7-2-2008 1:03
hi kscullin. im sorry to hear about your computer. unfortunately i dont have any idea how to go about your problem. at least at the moment. i will try to ask around then i will post asap. in the meantime, i suggest ou try to download avast antivirus, i heard it's  a good AV as well.

Posted By : kscullin - 7-2-2008 7:39
Thanks for the prompt response.
I did find something useful - a post somewhere reminded me of SuperAntiSpyware, so I gave that a shot. It gave me back my taskmanager. Regedit was giving me a "another process is using this" error message and my system tray icons were gone.


Possibly the same source indicated that I could make a copy of regedit.exe and rename it regedit.com, then run that from the "run" command (a handy back door) that let me in there. With SuperAntiSpyware, I've got the system tray icons back as well.


In the regsitry, I could find no trace of amvo or tc2 anything, so I think I have a different variation from the one you're describing. SuperAntiSpyware found a Vundo variant, NewJuan downloader, a fake SVCHost file, some MalwareAlarm (which I assume is a generic result, if you'll pardon the pun) in HKCR\MalwareAlarm.WebInstall, and indicated that B4FM.dll was suspicious but didn't automatically mark that one for quarantine. I quranatined it anyway. Unfortunately, since I can't get on here yet on her computer, I can't paste the logfile yet. When I can, I will.
My automatic updates won't turn on, no matter what I do, and I still can't get to any pages with search engines in IE, so I've got some improvement, but I'm not fully functional yet.

Posted By : Doctor Jim - 7-6-2008 11:42
try downloading the avg anti spyware. it helped me get rid of alot of problems with my computer--like last week, all the sound alerts of my computer were disabled no matter how i adjust the settings in control panel. antivirus programs did not help, but when i ran the antispyware, my system was back to normal! :-)

as for your problem with IE, i think IE is having problems with microsoft or some scenario similar to that. i read a forum string discussing problems opening IE some time ago. i just cant remember exactly. anyway, the posted solution which i can remember was to download mozilla firefox, then use that to open pages IE can not :-)

dr jim

Posted By : rodleggett - 11-16-2008 4:36
Trojan horse Generic12.NIH
AVG Free Edition - Program Version 7.5.549 - Release date 11/15/2008
will not only find it and remove it, it will tell you what is was in.
In my case it was in C:\Program Files\Absolute Poker\mainclient.exe