help please

Discussion in 'malware problems & news' started by unicornia_34, Apr 27, 2004.

Thread Status:
Not open for further replies.
  1. unicornia_34

    unicornia_34 Registered Member

    Joined:
    Apr 23, 2004
    Posts:
    8
    i have picked up yet another virous and the online scan finds it but will not disinfect it what nowo_O

    this is the result

    Memory unable to check
    C:\Program Files\Internet Explorer\update.exe=>(Upx) infected: Win32.Bagle.Gen@mm
    C:\Program Files\Internet Explorer\update.exe=>(Upx) unable to disinfect
    C:\WINDOWS\Downloaded Program Files\update.exe=>(Upx) infected: Win32.Bagle.Gen@mm
    C:\WINDOWS\Downloaded Program Files\update.exe=>(Upx) unable to disinfect
    C:\WINDOWS\system32\realupd.exe=>(Upx) infected: Win32.Bagle.Gen@mm
    C:\WINDOWS\system32\realupd.exe=>(Upx) unable to disinfect
    C:\WINDOWS\system32\realupd32.exe suspect: Trojan.Downloader.Gen
    C:\WINDOWS\system32\realupd32.exe copied
     
  2. JimIT

    JimIT Registered Member

    Joined:
    Jan 22, 2003
    Posts:
    1,035
    Location:
    Denton, Texas
    Hi Unicornia,

    1. Can you please let us know which operating system you are using (98/ME)?

    2. Do you have an installed and up-to-date antivirus installed?

    This will make it easier to help.

    Thanks!

    :D
     
  3. unicornia_34

    unicornia_34 Registered Member

    Joined:
    Apr 23, 2004
    Posts:
    8
    i'm running xp pro i have AVG, stinger, spybot, ad-aware 6.0, spy blaster, spyware guard, sw shredder and last but not least voptxp. so you tell me why i am not protectedo_O o_O :doubt:
     
  4. JimIT

    JimIT Registered Member

    Joined:
    Jan 22, 2003
    Posts:
    1,035
    Location:
    Denton, Texas
    Could be any number of reasons, and frankly, it would be conjecture, which is "neither here, nor there", is it? From the looks of your infection, it's probably a new variant of Bagle which AVG didn't have a pattern file for. ;)

    At any rate, that's the only program in your arsenal that had any chance of snagging that badboy in real time before it hosed you.

    If you haven't already, I would first disable system restore, make sure AVG is up to date, and reboot your computer in Safe Mode. Then I would scan your pc with AVG and manually delete any files it cannot "heal".

    You can also download and run the worm cleaners from www.sarc.com, and/or www.avast.com, which may also do the trick for you. Make sure System Restore is disabled when you do this, or the infection will return.

    Post back here your findings, and good luck!

    ;)
     
  5. unicornia_34

    unicornia_34 Registered Member

    Joined:
    Apr 23, 2004
    Posts:
    8
    bit defender finally picked it up and got rid of it so hopefully every thing will be good for a while now thanks for you help every one
     
Loading...
Thread Status:
Not open for further replies.