Inject3.CGMC tojan horse removal

Hello guys thanks for your answers.

I understand the conflict potential you mentioned and have removed Malwarebytes from my system.

However, there was a real trojan problem and the Malwarebytes scan in fact activated this virus during its scan (I suppose as it attempts to analyse the file) which AVG resident shield then rightfully picked up as the Inject3.CGMC trojan.  This does not appear to be a conflict problem between the two programs but each doing its job.

The various steps I have mentioned above in the 19/04/2017 email now result in a clean AVG full system scan. However, I cannot be sure that all sources of the trojan/ visurs have been fully removed as this seemed to be a particular clever animal.  

For example the creation in the temp and application data of hundreds of infected exe files by the trojan / virus resulted in AVG being saturated (Denial Of Service) which is why I installed Malwarebytes i.e. after the initial problem.  It is only after manually deleting all the bad exe files that AVG could function porperly again. It then seemed to pick up the trojan in its scan in the System Volume Information directory.  This was cleared manually by switching of restore which apparently clears this locked directory. 

I would welcome any information on how this trojan works and where it installs itself etc. if you have this information?

Again thanks for the assistance.

Steven

Hi Steven,
We understand your concern and To assist with the issue better Please kindly provide the screenshot using below link.
http://avgclick.me/getscreenshot
Thank you.

Hi guys,

Being getting a lot of problems trying to remove this trojan horse.  AVG resident picks it up but does not remove it.

Any ideas ?

Steven

Steven, For your info, just in case that you are unaware, you can post the screenshot here in your topic. Click on 'Answer' & then click on the 'Image' [mountain symbol] & follow the instructions. 
AVG Guru

Hi Steven,
We apologize for the inconvenience caused due to this issue. Let us explain you in detail. As per the screenshot you have provided, It comes from the malwarebytes application.
In this case I will suggest you to uninstall the Malwarebytes and check with the scan, If you have noticed the same file after uninstall please contact us again.
Thank you.

Hi Steven,
We understand your concern and To assist with the issue better Please kindly provide the screenshot using below link.
http://avgclick.me/getscreenshot
Thank you.

Hello Steven,
Could you please run a whole system scan with AVG and check if you detect any threats?
Please run the scan after updating AVG.
Thank you.

Extra information about this trojan:

Created hundreds of exe files in /temp directory. When scanned resident shield picks it up.  Unable to delete files.  Deleted files manually when in safe mode. Reading the file seems to activate virus ?

Also same thing happened in application data directory also deleted in safe mode.

AVG found trojan in System Volume Information.  Did a remove restore points which apparently clears this otherwise unaccessible directory.  

However still not sure this has fully removed the problem as the root cause i.e. origin is not known. 

Thanks for looking at this.

Steven



Hello guys thanks for your answers.

I understand the conflict potential you mentioned and have removed Malwarebytes from my system.

However, there was a real trojan problem and the Malwarebytes scan in fact activated this virus during its scan (I suppose as it attempts to analyse the file) which AVG resident shield then rightfully picked up as the Inject3.CGMC trojan.  This does not appear to be a conflict problem between the two programs but each doing its job.

The various steps I have mentioned above in the 19/04/2017 email now result in a clean AVG full system scan. However, I cannot be sure that all sources of the trojan/ visurs have been fully removed as this seemed to be a particular clever animal.  

For example the creation in the temp and application data of hundreds of infected exe files by the trojan / virus resulted in AVG being saturated (Denial Of Service) which is why I installed Malwarebytes i.e. after the initial problem.  It is only after manually deleting all the bad exe files that AVG could function porperly again. It then seemed to pick up the trojan in its scan in the System Volume Information directory.  This was cleared manually by switching of restore which apparently clears this locked directory. 

I would welcome any information on how this trojan works and where it installs itself etc. if you have this information?

Again thanks for the assistance.

Steven