Computing.Net > Forums > Security and Virus > Help on Packed.Generic.200, Trojan

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Help on Packed.Generic.200, Trojan

Reply to Message Icon

Name: ezfaer
Date: April 8, 2009 at 01:17:00 Pacific
OS: Windows XP Home SP3
CPU/Ram: P4, 480 MB
Subcategory: Viruses
Comment:


Hi,my norton hv detected Packed.Generic.200 & Trojan.Metajuan. Subsequently, i downloaded ad-aware, it also detected Win32.trojan Olmarik

Try the Symantec removal, but unsuccessful. Also try to download malwarebytes' anti-malware, it doesnt seems to run.

PLEASE ASSIST ME STEP BY STEP, IM NEW.
thks so much



Sponsored Link
Ads by Google

Response Number 1
Name: Rickyneck (by Ricky neck)
Date: April 8, 2009 at 01:53:20 Pacific
Reply:

You should try to install and run Malwarebytes in Safe Mode.


0

Response Number 2
Name: ezfaer
Date: April 8, 2009 at 02:53:07 Pacific
Reply:

here are my logs, please advise what is the next step i shld do.

thks

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 3

4/8/2009 5:29:46 PM
mbam-log-2009-04-08 (17-29-46).txt

Scan type: Quick Scan
Objects scanned: 95827
Time elapsed: 8 minute(s), 20 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\UACoiwberuf.dll (Trojan.TDSS) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\system32\UACoiwberuf.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot.


0

Response Number 3
Name: Rickyneck (by Ricky neck)
Date: April 8, 2009 at 03:13:51 Pacific
Reply:

After scanning, you click on next and click on "remove all". After remove, go to "quarantine" tab and "Delete all".
And restart the computer.


0

Response Number 4
Name: ezfaer
Date: April 8, 2009 at 18:28:34 Pacific
Reply:

yes, i hv done that.... next?


0

Response Number 5
Name: Rickyneck (by Ricky neck)
Date: April 8, 2009 at 22:31:05 Pacific
Reply:

You should delete all temporary files, temporary internet files, prefetch and then check.

Start > Run > type temp and click OK. Delete all
Start > Run > type %temp% and click OK. Delete all
Start > Run > type prefetch and click OK. Delete all.

You can run disk cleanup utility.
Start > programs> accessories > system tools > Disk cleanup.
Ticked mark all the check box and click OK.
After that all, I think your problem will be resolve.


0

Related Posts

See More



Response Number 6
Name: ezfaer
Date: April 9, 2009 at 00:42:22 Pacific
Reply:

Thks
I suppose the issue hv been solve. But i hv another problem, i try to do the disk defragmentation but it show error msg ' disk defragmenter could not start'.

Does that mean the virus is still there?


0

Response Number 7
Name: Rickyneck (by Ricky neck)
Date: April 9, 2009 at 03:37:34 Pacific
Reply:

Start > Run > type services.msc
Browse " Logical disk manager from the list.
Set on automatic and stop, then start.

You can also run check disk utility.
Start > Run > cmd > OK.
Command prompt will be open then type chkdsk and press enter.

Chkdsk utility can fix logical file system error.


0

Response Number 8
Name: ezfaer
Date: April 12, 2009 at 19:49:50 Pacific
Reply:

Hi i hv done,

Start > Run > type services.msc
Browse " Logical disk manager from the list.
Set on automatic and stop, then start.

seems like nothing is happening. after running the check disk utility, window found problem with the file system. I was told to run chkdsk with the /F (fix) option to correct these.

having done so, i received this msg
"Chkdsk cannot run because the volume is in use by another process. would you like to schedule this volume to be checked the next time system restart? <Y/N>"

after typing Y, i restarted my pc, yet nothing happen.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Help on Packed.Generic.200, Trojan

I have Packed.Generic.200 www.computing.net/answers/security/i-have-packedgeneric200-/26579.html

Packed generic 200 virus removal www.computing.net/answers/security/packed-generic-200-virus-removal/26275.html

Packed.Generic.200 Detected www.computing.net/answers/security/packedgeneric200-detected/26821.html