Trojan_Generic

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Run a few times Housecall scan and found Trojan_Generic and it does not seems
to be able to clean it. An on line scan from Symanyec also does not
help.Please advice how can I get rid of this, Thanks
 
lhs said:
Run a few times Housecall scan and found Trojan_Generic and it does not seems
to be able to clean it. An on line scan from Symanyec also does not
help.Please advice how can I get rid of this, Thanks

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Include scanning with either Sysclean or Multi_AV, plus AVG Anti-Spyware
(formerly Ewido - http://www.ewido.net/en/) and follow instructions to
do all scans in Safe Mode.

When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the link above (not here, please).

Standard caveat: If the procedures look too complex - and there is no
shame in admitting this isn't your cup of tea - take the machine to a
professional computer repair shop (not your local version of
BigStoreUSA). Please be aware that not all local shops are skilled at
removing malware and even if they are, your computer may be so infested
that Windows will need to be clean-installed. Have all your data backed
up before you take the machine into a shop.


Malke
 
Fyi, Housecall identify it at c:\Doc and setting\......\pstord.exe is
infected. When I try to delete this, it says this is a system file which may
cause the pc or another prog to stop functioning......."

I install AVG 7.5 antispyware and run the scan in safemode. It identified a
folder infected with BACKDOOR.Virkel.b which it recommends to quaratine.
However I choose to delete it. A rerun in safe mode of the AVG finds nothing.

Then I try to run the Housecall again (normal mode) and the strange thing is
when it reaches step 2, the "page cannot be display' wil appears but it will
continue scanning or running. Thus there is no way to apply the necessary
action after it finished. Any idea why is this so that the page cannot be
display while I can see other web pages?

I also notice that everytime when I try to "Run LiveUpdate" NAV2007, a
message wil appears SYMANTEC LOGO "LiveUpdate Securrity Warning appears
saying that LiveUpdate detected the following items oin the Windows hosts file

1.1.1.1 liveupdate.symantec.com
and there are altogether 7 entries all with 1.1.1.1 and pertaining to
Symantec website. and the recommended action is to remove these from the
hosts file.

When I check the host file, there are no such entries. It seems strange
that these message are coming with Symantec icon. I suppose I will check with
Symantec but is there anyone with such experience or is it because my pc is
infected with.......

Back to my pc, I guess its time to run HJT.......
 
Adding to Malke Advice, you Got this Worm: W32/Chode-W
First I recommend Uninstall Norton since Norton have been sitting Ducks for
this Worm, ehnce you said you got AVG ( did you update it's definitions yet).

= You mentioned this path:
C:\Documents and settings\...\pstord.exe Delete the executable file/folder
since it is in the My Documents and look here for Temp Files:
Then Open windows explorer and delete the Temp:
C:\Windows\Temp\TemporaryInternet Files =< Delete all sub-folders in capital
letters they will be here>

= To access the Hosts file do the following:
Open the Windows Explorer and locate this path:
C:\Windows\System32\drivers\etc = look in the Right Pane/window for this
file called the HOSTS file but not the one with the extension *.SAM* leave
this as is.
If you can't see it try to click Tools >> Folder Options and select show
Hidden files and folder, then right Click the Hosts file and select open with
Notepad. //*** Remember to Hide your system files after you find your
file***//
There see any reference for that site and remove it, you Hosts file will
looks like this:
# 102.54.94.97 rhino.acme.com # Source server
# 38.25.63.10 x.acme.com # Client Host
127.0.0.1 LocalHost
------------------------------------------
Remove all other References other than those above.


= Description of W32/Chode-W
http://www.sophos.com/security/analyses/w32chodew.html

= Then Download the Hijackthis and send the report to one of many
forums for analysis and troubleshooting:
When all else fails, HijackThis v1.99.1
(http://aumha.org/downloads/hijackthis.zip) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware. Post
your log to http://aumha.net/viewforum.php?f=30,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7, or other appropriate
forums for expert analysis, not here.
Does your Norton Up and current for updates and subscriptions?.
HTH.
nass
 
Back
Top