Trojan Horse Crypt4.BBEW?

Jeffsta

Estimable
May 7, 2015
32
0
4,580
I ran a AVG scan at 9:55am ET today and had 0 viruses. I ran a AVG scan at 4:00pm ET and had these 3;

Trojan horse Crypt4.BBEW (C:\Windows\Installer\29c62e.msi)
Trojan horse Crypt4.BBEW (C:\Windows\Installer\29c62a.msi)
Trojan horse Crypt4.BBEW (C:\Windows\Installer\29c632.msi)

AVG says it removed these 3 threats, and when I click view detections it shows they are secured. I have done a few reboots and scans since and AVG detects nothing.

I'm trying to figure out how this happened. Between the 9:55am scan and 4:00pm scan I was not even on the internet. The only things that occurred was a 3:00pm AVG update, and I was decluttering my secondary hard drive (containing old gifs and videos).

1) Can Gifs and Videos contain viruses?
2) Should I trust that AVG took care of them as it says it did?
3) Is it possible that it messed up other files on computer that I'm not noticing?
4) If I go back to a system restore point I created yesterday, will that undo anything the viruses might have done to other files?

Thanks

 
Solution
4 - Usually no and there a chance you would resurrect the virus from the past.

I would run
http://www.bleepingcomputer.com/download/tdsskiller/
http://www.bleepingcomputer.com/download/roguekiller/
http://www.bleepingcomputer.com/download/hitmanpro/
http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/

to make sure there is no a backdoor allowing malwares in.

CWEric

Estimable
Jun 13, 2015
170
0
4,710
4 - Usually no and there a chance you would resurrect the virus from the past.

I would run
http://www.bleepingcomputer.com/download/tdsskiller/
http://www.bleepingcomputer.com/download/roguekiller/
http://www.bleepingcomputer.com/download/hitmanpro/
http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/

to make sure there is no a backdoor allowing malwares in.
 
Solution

Jeffsta

Estimable
May 7, 2015
32
0
4,580


I ran the programs you mentioned.

1) tdsskiller found nothing
2) hitmanpro found nothing
3) malwarebytes found nothing
4) roguekiller found nothing but these 3 processes;

[AV.Killer] avgidsagent.exe(1972) -- C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[7] VT(1) -> ERROR [12]
[AV.Killer] avgwdsvc.exe(1988) -- C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe[7] VT(1) -> ERROR [12]
[AV.Killer] avgui.exe(3552) -- C:\Program Files (x86)\AVG\AVG2015\avgui.exe[7] VT(1) -> ERROR [12]

Is this normal for AVG? The RogueKiller site has no info on it. I did a yahoo search, and everything I read says that those exe files should run. But is roguekiller telling me they're infected?