Показано с 1 по 18 из 18.

packed.generic.200 virus

  1. #1
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    Thumbs up packed.generic.200 virus

    I have installed and used the following, Combo Fix, Gmer rootkit, Root repeal (didn't work),ATF cleaner and now using Kasperski's Manual fix option. It has brought me here to send reports (attached) I am awaiting a script to paste in the Kas. window to exec. My avf file will not upload onto this site??????
    Вложения Вложения
    Последний раз редактировалось Rene-gad; 17.03.2009 в 10:56. Причина: only 3 log files in accordance with the rules should be attached

  2. #2
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    Please, don't do anything without our request.
    Now, disconnect from internet, disable your symantec.
    Execute this script in avz ( i know, you have it ) http://virusinfo.info/showthread.php?t=9207
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     DelBHO('{07B18EA9-A523-4961-B6BB-170DE4475CCA}');
     DelBHO('{07B18EA1-A523-4961-B6BB-170DE4475CCA}');
     DelBHO('{02478D38-C3F9-4efb-9B51-7695ECA05670}');
     QuarantineFile('C:\WINDOWS\system32\ps2.exe','');
     QuarantineFile('C:\Program Files\MX610LL\MX610LL.exe','');
     QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe','');
     QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe','');
     QuarantineFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL','');
     DeleteService('rootrepeal');
     QuarantineFile('C:\WINDOWS\system32\drivers\rootrepeal.sys','');
     QuarantineFile('C:\WINDOWS\System32\drivers\AEC6710D.sys','');
     QuarantineFile('C:\WINDOWS\System32\drivers\CdaC15BA.SYS','');
     QuarantineFile('C:\WINDOWS\system32\UACunhsvgrq.dll','');
     TerminateProcessByName('c:\progra~1\mywebs~1\bar\2.bin\m3srchmn.exe');
     QuarantineFile('c:\progra~1\mywebs~1\bar\2.bin\m3srchmn.exe','');
     DeleteFile('c:\progra~1\mywebs~1\bar\2.bin\m3srchmn.exe');
     DeleteFile('C:\WINDOWS\system32\UACunhsvgrq.dll');
     DeleteFile('C:\WINDOWS\system32\drivers\rootrepeal.sys');
     DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL');
     DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe');
     DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe');
    BC_ImportAll;
    ExecuteSysClean;
    BC_Activate;
    ExecuteRepair(6);
    ExecuteRepair(8);
    ExecuteRepair(9);
    RebootWindows(true);
    end.

    Please upload the quarantine according to appendix 3 of rules(http://virusinfo.info/showthread.php?t=9184) , by link http://virusinfo.info/upload_virus_eng.php?tid=41846
    After that make a set of logs according to rules: http://virusinfo.info/showthread.php?t=9184

    Upgrade acrobat reader or better remove it at all. You can use for example: http://portableapps.com/apps/office/...a_pdf_portable
    Последний раз редактировалось drongo; 16.03.2009 в 23:30.

  3. #3
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    Ok, I have exec...

    I have executed the script that you gave me. What do I do next?

  4. #4
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    quarantine,
    acrobat reader
    new logs...

  5. #5
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32
    I have got the new reports....attached. Acrobat has been updated and I am having problems trying to get a Quarantine file in avz, The quar. is empty....?? How do I get them?

    Are you there?
    Вложения Вложения
    Последний раз редактировалось Rene-gad; 17.03.2009 в 10:57. Причина: only 3 log files in accordance with the rules should be attached

  6. #6
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация
    Регистрация
    03.04.2006
    Сообщений
    21,108
    Вес репутации
    3000
    Where ist the log virusinfo_syscure.zip?

  7. #7
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32
    Is this it? I am from the US. Our hours are much different. Sorry for the delay.
    Последний раз редактировалось Rene-gad; 17.03.2009 в 17:47. Причина: wrong file removed

  8. #8
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    No, your file is wrong.

    Instruction how to create virusinfo_syscure.zip :
    http://virusinfo.info/showthread.php?t=9184
    Read carefully, specially the part: Analysis 1

  9. #9
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    New Logs

    Thanks, I have attached a new set of logs as directed in the rules. Thank you for your patients.
    Вложения Вложения

  10. #10
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    Do you need BackWeb ? I suggest you to go to add/remove programs and uninstall it. It is kind of nasty program.

    Don't forget to disable norton antivirus and disconnect from internet, only then execute this script in avz:
    Код:
    begin
    SearchRootkit(true, true);
    SetAVZGuardStatus(True);
     QuarantineFile('C:\WINDOWS\COUPON~1.OCX','');
     QuarantineFile('C:\Program Files\NetZero\qsacc\X1IEBHO.dll','');
     QuarantineFile('C:\WINDOWS\system32\ps2.exe','');
     QuarantineFile('C:\WINDOWS\system32\UACphwtkuin.dll','');
     QuarantineFile('C:\WINDOWS\system32\UACqeystrqv.dll','');
     QuarantineFile('C:\WINDOWS\system32\UACsyxarhca.dll','');
     QuarantineFile('C:\WINDOWS\system32\UACtuaiisko.dll','');
     QuarantineFile('C:\WINDOWS\system32\drivers\UACagvatkkj.sys','');
     DeleteService('MyWebSearchService');
     QuarantineFile('\\?\globalroot\systemroot\system32\UACqeystrqv.dll','');
     DeleteFile('\\?\globalroot\systemroot\system32\UACqeystrqv.dll');
     DeleteFile('C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe');
     DeleteFile('C:\WINDOWS\system32\ps2.exe');
     DeleteFile('C:\WINDOWS\system32\UACphwtkuin.dll');
     DeleteFile('C:\WINDOWS\system32\UACqeystrqv.dll');
     DeleteFile('C:\WINDOWS\system32\UACsyxarhca.dll');
     DeleteFile('C:\WINDOWS\system32\UACtuaiisko.dll');
     DeleteFile('C:\WINDOWS\system32\drivers\UACagvatkkj.sys');
     DeleteFile('C:\WINDOWS\COUPON~1.OCX');
    BC_ImportAll;
    ExecuteSysClean;
    BC_Activate;
    ExecuteRepair(6);
    ExecuteRepair(8);
    ExecuteRepair(9);
    SetAVZPMStatus(true);
    RebootWindows(true);
    end.
    System will reboot.
    Please upload a quarantine by http://virusinfo.info/upload_virus_eng.php?tid=41846
    The avz's database was last updated 2/8/2009 it is necessary to update the bases using automatic updates (File/Database update). Please do update, then make a set of new logs and attach them to next post in this topic.

  11. #11
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    back web

    There is no program called "Backweb" in the program list given in my add/remove programs. should I proceed with the script you gave me?

  12. #12
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    Цитата Сообщение от arthur Посмотреть сообщение
    There is no program called "Backweb" in the program list given in my add/remove programs. should I proceed with the script you gave me?
    yes, proceed.
    i will try to find the original uninstaller.



    Could you find in add/remove programs? : something like
    Updates from HP/Compaq Connections
    Uninstall it. It should remove your backweb client
    Последний раз редактировалось drongo; 18.03.2009 в 23:16. Причина: add

  13. #13
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    Ok

    I have run the script, updated avz database, and created new logs. I am having a problem with uploading the quarantine files, because they are not zip files they are data files. Is there something I can do to turn them into zips and send? HP also deleted.....
    Вложения Вложения
    Последний раз редактировалось arthur; 19.03.2009 в 01:18. Причина: Hp fix

  14. #14
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация
    Регистрация
    03.04.2006
    Сообщений
    21,108
    Вес репутации
    3000
    Цитата Сообщение от arthur Посмотреть сообщение
    Is there something I can do to turn them into zips and send?
    File/Quarantine folder viewer..

  15. #15
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    Код:
    Appendix 3. How to send us requested files.
    
    1. Start AVZ, choose from the menu "File"-> "Quarantine folder viewer ".
    2. Mark files in the list which should be sent.
    3. Click "Archive" and specify a place on the disk where the archive should be kept. We recommend to accept the default filename, i.e. virus.zip.
    4. Upload the archive using the download link (Upload quarantined files) at the top of your thread (the "thread link" field will be filled automatically), or use this link: http://virusinfo.info/upload_virus_eng.php, where you need to fill the "thread link" field manually. (It should look like httр: // virusinfo.info/showthread.php?t=XXXX).

  16. #16
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    Uploaded Quarantine files

    Thank you for you patients. This morning my system has not been showing any signs of the virus in Norton and is working quite well. No unusual search problems or strange activity. Am I clean?

  17. #17
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для drongo
    Регистрация
    17.09.2004
    Адрес
    Israel
    Сообщений
    7,165
    Вес репутации
    971
    I don't see something unusual either.
    The backweb client's dll still exist, lets remove it along with avz trails:
    Execute this script in avz:
    Код:
    begin
    SetAVZGuardStatus(true);
     DeleteFile('C:\Program Files\BackWeb\BackWeb Client\6.1.0.153\Program\IAdHide.dll');
    SetAVZPMStatus(false);
    ExecuteStdScr(6);
    BC_ImportAll;
    ExecuteSysClean;
    BC_Activate;
    RebootWindows(true);
    end.
    After restart you will be able delete \BackWeb\ folder in C:\Program Files\ manually.
    You should upgrade acrobat reader. Or uninstall and use an alternative.(for example: http://portableapps.com/apps/office/...a_pdf_portable )
    Uninstall kaspersky virus removal tool.
    You may now enable system restore, or do much better -> to use another program for creation image of your system disk like acronis, norton go back, etc.

    P.s. on "Thanks" you are welcome to click, as well you welcome to help us too:
    http://virusinfo.info/showthread.php?t=15313 &
    http://virusinfo.info/showthread.php?t=28583
    Последний раз редактировалось Rene-gad; 19.03.2009 в 19:50.

  18. #18
    Junior Member Репутация
    Регистрация
    16.03.2009
    Адрес
    USA
    Сообщений
    11
    Вес репутации
    32

    Sent packed generic...Packing its bags! YES!

    Drongo,
    I cannot express my graditude enough. You are a genius! Thank you SO much my friend. I uploaded the clean files sucessfully to help out. It has been an honor working with you. Again Thank you!

    For anyone reading this thread:

    If you have a problem and want assistance at this forum. Please read the rules VERY CAREFULLY before doing so, and follow the moderators instructions to the tee. It may take a while to fix, but the results are blissful. These pros know what they are doing. I sought they're help without knowing anything about viruses, scripts or even where to start. Now my system is running tops again and all I had to do is carefully follow instructions. I have Norton 360, which picked up the virus. When I went to Norton support, they were going to charge me $99 to remove the virus (packed.generic.200). These wonderful people at Virus Info fixed my problem for free, saving me time , money and agrivation. I recommend this site for anyone who is willing to work under instruction to fix the problem. I would like to personally thank everyone at Virus info for your help.

Похожие темы

  1. Packed.Generic.237
    От elpago в разделе Помогите!
    Ответов: 4
    Последнее сообщение: 17.07.2009, 11:15
  2. Не запускается exe и packed generic 200
    От Lamer123 в разделе Помогите!
    Ответов: 12
    Последнее сообщение: 17.03.2009, 05:26
  3. packed.generic.200 virus
    От arthur в разделе Malware Removal Service
    Ответов: 1
    Последнее сообщение: 16.03.2009, 20:43
  4. Packed.generic.200 HOW TO REMOVE?
    От Lasse в разделе Malware Removal Service
    Ответов: 1
    Последнее сообщение: 10.03.2009, 16:05
  5. Packed.Generic.61
    От Curator в разделе Помогите!
    Ответов: 1
    Последнее сообщение: 23.06.2008, 12:12

Свернуть/Развернуть Ваши права в разделе

  • Вы не можете создавать новые темы
  • Вы не можете отвечать в темах
  • Вы не можете прикреплять вложения
  • Вы не можете редактировать свои сообщения
  •  
Page generated in 0.01449 seconds with 17 queries