Malwarebytes

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> AVG detected trojan; Generic11.BEOG
kevbuck
post Oct 17 2008, 08:26 AM
Post #1


New Member
*

Group: Members
Posts: 27
Joined: 5-October 08
Member No.: 4,320



Has anyone heard of the trojan Generic11.BEOG? AVG found this tonight. Yet there is no information in the forums or virus encyclopedia. I tried googling-nothing either.

Please note that my experience is very limited. I have Windows XP sp3 with AVG(free8.0), MBAM and Zonealarm(firewall)

I ran all updates, ran an AVG and MBAM scan tonight- nothing. Ran second AVG after another update and the scan found this;
Trojan horse Generic11.BEOG
C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe

Sent it to AVG for analysis as false positive. Unfortunately, I have heard that can take some time.
Does anyone know what or heard anything about this? Is it a false positive or Trojan???

MBSM found Trojan.Agent and Rogue.Suspect(both quarantined) last week which i posted in the General Forum and was advised to run HJT, Panda and Spybot(tomorrow for sure) Could all of these be linked somehow????
Any advice/input would be greatly appreciated

Thanks
Go to the top of the page
 
+Quote Post
john.kreelman
post Oct 17 2008, 11:10 AM
Post #2


New Member
*

Group: Members
Posts: 1
Joined: 17-October 08
Member No.: 4,547



I have a feeling that it's attributed to Adobe reader in some way. I was clear until I installed the reader from the adobe site. After a scan it brought up the same instance you reported. AVG couldn't heal nor remove so hopefully Adaware or Spybot will do the trick - will run in a mo.

Thoughts anyone?
Go to the top of the page
 
+Quote Post
brannka
post Oct 17 2008, 11:14 AM
Post #3


New Member
*

Group: Members
Posts: 1
Joined: 17-October 08
From: malta
Member No.: 4,546



QUOTE (kevbuck @ Oct 17 2008, 09:26 AM) *
Has anyone heard of the trojan Generic11.BEOG? AVG found this tonight. Yet there is no information in the forums or virus encyclopedia. I tried googling-nothing either.

Please note that my experience is very limited. I have Windows XP sp3 with AVG(free8.0), MBAM and Zonealarm(firewall)

I ran all updates, ran an AVG and MBAM scan tonight- nothing. Ran second AVG after another update and the scan found this;
Trojan horse Generic11.BEOG
C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe

Sent it to AVG for analysis as false positive. Unfortunately, I have heard that can take some time.
Does anyone know what or heard anything about this? Is it a false positive or Trojan???

MBSM found Trojan.Agent and Rogue.Suspect(both quarantined) last week which i posted in the General Forum and was advised to run HJT, Panda and Spybot(tomorrow for sure) Could all of these be linked somehow????
Any advice/input would be greatly appreciated

Thanks


I found same "problem" this morning...Yesterday at the same time the scan was done none of those "infections"were there. In mean time Avg did update and "infections" were there. I have send files as well for check up. I went on google to find "virus" but there was nothing except your post!
I also have these in vault:
C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0010583.exe
and this one :

C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0000038.exe


and same as yours:
C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe

if i do get some answers i will keep your posted and please do the same!
Tnx
Go to the top of the page
 
+Quote Post
marie
post Oct 17 2008, 11:38 AM
Post #4


New Member
*

Group: Members
Posts: 1
Joined: 17-October 08
From: England
Member No.: 4,543



QUOTE (kevbuck @ Oct 17 2008, 08:26 AM) *
Has anyone heard of the trojan Generic11.BEOG? AVG found this tonight. Yet there is no information in the forums or virus encyclopedia. I tried googling-nothing either.

Please note that my experience is very limited. I have Windows XP sp3 with AVG(free8.0), MBAM and Zonealarm(firewall)

I ran all updates, ran an AVG and MBAM scan tonight- nothing. Ran second AVG after another update and the scan found this;
Trojan horse Generic11.BEOG
C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe

Sent it to AVG for analysis as false positive. Unfortunately, I have heard that can take some time.
Does anyone know what or heard anything about this? Is it a false positive or Trojan???

MBSM found Trojan.Agent and Rogue.Suspect(both quarantined) last week which i posted in the General Forum and was advised to run HJT, Panda and Spybot(tomorrow for sure) Could all of these be linked somehow????
Any advice/input would be greatly appreciated

Thanks


I found the same Trojan in the same place as you, when i did a scan with avg this morning.
I find this odd because i have not just downloaded the adobe reader its been on my computer for a while. unsure.gif
I have done many scans before this morning that have not found this Trojan. Anyway for now i have moved it to the virus vault
Go to the top of the page
 
+Quote Post
mona7865
post Oct 17 2008, 11:55 AM
Post #5


True Member
****

Group: Honorary Members
Posts: 499
Joined: 29-March 08
From: Merksem-Antwerp, Belgium
Member No.: 2,252



AVG gave me this message this morning as well (when my notebook was idle!). I decided to ignore it since I haven't updated Adobe Reader for ages.

Kindly regards,

Mona.


--------------------
Kindly Regards.

Mona.


Dell Inspiron 1501: DUTCH OS/WIN XP-SP3 - OA Premium 4.0.0.45, Eset Nod32 4.2.58.3, MBAM Paid version, WinPatrol Plus, SpywareBlaster paid, KeyScrambler Professional


Dell Inspiron Mini 1012: DUTCH OS/Windows 7 Home Premium - OA Premium 4.0.0.45, MSE, MBAM Paid version, WinPatrol Plus, SpywareBlaster free, KeyScrambler free
Go to the top of the page
 
+Quote Post
Mart007
post Oct 17 2008, 12:38 PM
Post #6


New Member
*

Group: Members
Posts: 1
Joined: 17-October 08
Member No.: 4,550



I too have the same problem i have moved it to the virus vault while sum1 works out what it is
Go to the top of the page
 
+Quote Post
rayanne
post Oct 19 2008, 06:48 PM
Post #7


New Member
*

Group: Members
Posts: 1
Joined: 17-October 08
Member No.: 4,559



I too got the message re: Trojan Horse Generic11.BEOG which infected the setup.exe file in Adobe Reader 9. I moved it to the Virus Vault. Does anyone know what to do about this? Should I simply delete it from the Virus Vault? Will it affect the usability of Adobe Reader? Any insight on this would be appreciated.
Go to the top of the page
 
+Quote Post
Tigger93
post Oct 19 2008, 08:39 PM
Post #8


Forum Deity
******

Group: Moderators
Posts: 1,619
Joined: 27-November 06
Member No.: 775



It is not a virus, it is a false positive by AVG.
Go to the top of the page
 
+Quote Post
kevbuck
post Oct 21 2008, 12:12 AM
Post #9


New Member
*

Group: Members
Posts: 27
Joined: 5-October 08
Member No.: 4,320



QUOTE (brannka @ Oct 17 2008, 05:14 AM) *
I found same "problem" this morning...Yesterday at the same time the scan was done none of those "infections"were there. In mean time Avg did update and "infections" were there. I have send files as well for check up. I went on google to find "virus" but there was nothing except your post!
I also have these in vault:
C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0010583.exe
and this one :

C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0000038.exe


and same as yours:
C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe

if i do get some answers i will keep your posted and please do the same!
Tnx


Hi brannka,
I did a second scan and came up with similar System Volume Information\_restore entries.
Tigger93(moderator) has posted that it is a false positive. I have requested info as to whether we restore all quarantined items or not
No response from AVG, not expecting to see one either. Thank god for MBAM and this forum--awesome
Will keep you posted
Go to the top of the page
 
+Quote Post
kevbuck
post Oct 21 2008, 12:28 AM
Post #10


New Member
*

Group: Members
Posts: 27
Joined: 5-October 08
Member No.: 4,320



QUOTE (Tigger93 @ Oct 19 2008, 02:39 PM) *
It is not a virus, it is a false positive by AVG.



Thanks Tigger93
So now do i restore it? Also what do the entries below mean? Restore them all??
FYI, a second scan showed two entries similar to brannka's post below:


I found same "problem" this morning...Yesterday at the same time the scan was done none of those "infections"were there. In mean time Avg did update and "infections" were there. I have send files as well for check up. I went on google to find "virus" but there was nothing except your post!
I also have these in vault:
C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0010583.exe
and this one :

C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0000038.exe
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 29th July 2010 - 10:30 PM ()