|
Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs |
|
Topic Tools |
#16
|
|||
|
|||
Ok lets try "Stinger" on my list
|
#17
|
|||
|
|||
Nada, thanks a lot pancake for the continuing support
|
#18
|
|||
|
|||
I am able to locate and delete the file, however after a few minutes it is regenerated.
|
#19
|
|||
|
|||
Check out Windows Task Manager and see if its running from in there.
|
#20
|
|||
|
|||
Nope, no odd processes found. Switched from Panda to NOD32 and the same file is being detected as having Agobot.NPZ yet is still having trouble permanently removing it
|
#21
|
|||
|
|||
Its the WORM_NETSKY.Z try this site for removing it from the registry..I'm suprised its still there after running Stinger.
http://www.trendmicro.com/vinfo/viru...=WORM_NETSKY.Z |
#22
|
|||
|
|||
re: ccupdate.exe - i'm in the same boat bob
hey bob i'm in the same boat as you. i came across this posting while searching for a way to remove this thing. wondering if you also had a file named testfile in the same directory as the ccupdate.exe
no extension, and 0 kb file named testfile anyway, i'm using sophos and it identified it as W32/Agobot-Fam, but like what you said, the registry keys that it said to remove aren't in the registry. i have noticed my computer shutting down at unexpected times recently. other than that, don't notice anything different. anyway, i downloaded newest trial of norton. gonna give that a try. if anything works, i'll post it here. good luck to you. greg |
#23
|
|||
|
|||
okay, got ride of ccupdate.exe
i noticed a folder on my c drive named package cache
there were 1 or 2 files in there (wee hrs of morning, can't remember) and i had no clue what it was, so i deleted it. this was after i deleted ccupdate and testfile again. anyway, after installing norton, i had to reboot. upon rebooting, the ccupdate.exe and testfile did not reappear. now i do however have other copies of (norton calls it) Gaobot.afj virus. all files under c:\windows\temp\ and filenames are tmp***.tmp where *** goes through all hexidecimal characters from 000 to FFF i just deleted the whole temp directory and will make it again since the continuous error messages from both norton and sophos were driving me nuts. i couldn't prevent them from popping up until i deleted the temp directory, and it still took some more time after that. anyway, hope the package cache thing is there with you and works greg |
#24
|
|||
|
|||
I do not have a package cache folder but I do also have the testfile file. So far, Panda Titanium, Platinum, NOD32, and PC-cillin have detected it yet no registry entires.
Just deleted the testfile and a few temp** files and will see what happens |
#25
|
|||
|
|||
|
Bookmarks |
«
Previous Topic
|
Next Topic
»
|
|
Similar Topics | ||||
Topic | Topic Starter | Forum | Replies | Last Post |
Help needed Re: W32/Gaobot.worm.gen.u virus ? | vincemann | Malware Removal | 12 | November 2nd, 2009 05:14 AM |
gaobot ao virus need seriuos help | paul_danzig | Malware Removal | 3 | March 4th, 2006 01:49 AM |
problems: gaobot virus & more | valkyrie_lisa | Malware Removal | 2 | December 1st, 2004 10:10 PM |
I have the w32.gaobot virus and cant get it off. please help | BackdoorGarbage | Malware Removal | 11 | November 16th, 2004 09:44 PM |
W32/Gaobot.CR virus | nebsta | Malware Removal | 3 | June 20th, 2004 12:59 PM |
All times are GMT +1. The time now is 02:06 PM.