![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Last night my Zone Alarm and AVG Antivirus both started throwing warnings left and right at the saem time. I remember seeing Generic11.gdc, Pakes.O, and dialer.sap. Some of the zone alarm alerts refered to beauty.exe, a.exe, and c.exe trying to run.
So this morning I booted the machine and attempted to restore to my last restore point thinking I had only gone to two websites that were out of the ordinary to me yesterday (both of which I wouldn't have expected would be contaminated but wouldn't rule it out). After restoring to that point I did full scan with AVG and it again found the Generic11 again. From there I did a quick google search and found this forum and a couple other posts in recent days referring to these trogans, both of which refered the users to the Read & Run Me First Malware Removal Guide. So I went ahead and followed the guide as a starting point. The system seems to be running better now but I'd still like someone to take a look at the logs if you don't mind before stoping and restarting the restore program. Edit to add.........after all the alerts last night my wifi monitor in the tray started showing my linksys network had assigned an unusual IP address (don't remember what it was and didn't think to write it down at the time) while other computers using the router still showed the proper address. I wasn't able to resolve this until doing the restore this morning. Thanks, OL79 |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Just adding the last log attachment
|
|
#3
|
||||
|
||||
|
Welcome to Major Geeks!
You are in pretty good shape. We just have some minor finishing touches to do. Did you copy tasklist.exe here like this or is this malware? It does not belong here! Code:
2008-08-02 17:51 . 2008-08-02 17:51 72,192 --a------ C:\Documents and Settings\Sara\tasklist.exe Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Uninstall the below software: Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot After clicking Fix, exit HJT. Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. Quote:
to the registry. If you do not get a success message, it definitely did not work. Now run Ccleaner! Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below log:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#4
|
|||
|
|||
|
Ok I've followed all the instructions in the last post and was successfull with the fixme.reg changes. I did not put that tasklist.exe there that I remember, I have deleted it. Attached is the new log as requested.
I'd also like to add that AVG has alerted me today to two different generic viruses, one was generic7.**** (if I recall the **** were abfx but I won't swear to it) and the other was another variant of Generic11. Both of these appeared to be in the system restore files (which if I read correctly will be wiped out once I'm clean of the other stuff and reset the system restore program). Or should I go ahead and reset it now and see if they quit appearing? Thanks, OL79 |
|
#5
|
||||
|
||||
|
You're welcome.
Quote:
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
All seems to be ok so far. Thanks for all your help! I'll be back if any more issues pop up in the next few days.
|
|
#7
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Trying to make sure my PC is clean | MFLucky7 | Malware Removal | 1 | 04-13-08 08:04 |
| Trogans & Pop Ups | irishpooh | Malware Removal | 7 | 07-27-07 14:39 |
| Please make sure I'm clean | chadwilson7 | Malware Removal | 14 | 08-27-06 22:40 |
| Someone's Getting Canned Over This (I've Cleaned up, just make sure I'm clean) | orty | Malware Removal | 2 | 07-03-06 22:57 |
| Want to make sure I am clean now | Alicia74 | Malware Removal | 3 | 10-18-05 00:28 |