![]() ![]() |
Oct 17 2008, 08:26 AM
Post
#1
|
|
![]() New Member ![]() Group: Members Posts: 27 Joined: 5-October 08 Member No.: 4,320 |
Has anyone heard of the trojan Generic11.BEOG? AVG found this tonight. Yet there is no information in the forums or virus encyclopedia. I tried googling-nothing either.
Please note that my experience is very limited. I have Windows XP sp3 with AVG(free8.0), MBAM and Zonealarm(firewall) I ran all updates, ran an AVG and MBAM scan tonight- nothing. Ran second AVG after another update and the scan found this; Trojan horse Generic11.BEOG C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe Sent it to AVG for analysis as false positive. Unfortunately, I have heard that can take some time. Does anyone know what or heard anything about this? Is it a false positive or Trojan??? MBSM found Trojan.Agent and Rogue.Suspect(both quarantined) last week which i posted in the General Forum and was advised to run HJT, Panda and Spybot(tomorrow for sure) Could all of these be linked somehow???? Any advice/input would be greatly appreciated Thanks |
|
|
|
Oct 17 2008, 11:10 AM
Post
#2
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 17-October 08 Member No.: 4,547 |
I have a feeling that it's attributed to Adobe reader in some way. I was clear until I installed the reader from the adobe site. After a scan it brought up the same instance you reported. AVG couldn't heal nor remove so hopefully Adaware or Spybot will do the trick - will run in a mo.
Thoughts anyone? |
|
|
|
Oct 17 2008, 11:14 AM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 17-October 08 From: malta Member No.: 4,546 |
Has anyone heard of the trojan Generic11.BEOG? AVG found this tonight. Yet there is no information in the forums or virus encyclopedia. I tried googling-nothing either. Please note that my experience is very limited. I have Windows XP sp3 with AVG(free8.0), MBAM and Zonealarm(firewall) I ran all updates, ran an AVG and MBAM scan tonight- nothing. Ran second AVG after another update and the scan found this; Trojan horse Generic11.BEOG C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe Sent it to AVG for analysis as false positive. Unfortunately, I have heard that can take some time. Does anyone know what or heard anything about this? Is it a false positive or Trojan??? MBSM found Trojan.Agent and Rogue.Suspect(both quarantined) last week which i posted in the General Forum and was advised to run HJT, Panda and Spybot(tomorrow for sure) Could all of these be linked somehow???? Any advice/input would be greatly appreciated Thanks I found same "problem" this morning...Yesterday at the same time the scan was done none of those "infections"were there. In mean time Avg did update and "infections" were there. I have send files as well for check up. I went on google to find "virus" but there was nothing except your post! I also have these in vault: C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0010583.exe and this one : C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0000038.exe and same as yours: C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe if i do get some answers i will keep your posted and please do the same! Tnx |
|
|
|
Oct 17 2008, 11:38 AM
Post
#4
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 17-October 08 From: England Member No.: 4,543 |
Has anyone heard of the trojan Generic11.BEOG? AVG found this tonight. Yet there is no information in the forums or virus encyclopedia. I tried googling-nothing either. Please note that my experience is very limited. I have Windows XP sp3 with AVG(free8.0), MBAM and Zonealarm(firewall) I ran all updates, ran an AVG and MBAM scan tonight- nothing. Ran second AVG after another update and the scan found this; Trojan horse Generic11.BEOG C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe Sent it to AVG for analysis as false positive. Unfortunately, I have heard that can take some time. Does anyone know what or heard anything about this? Is it a false positive or Trojan??? MBSM found Trojan.Agent and Rogue.Suspect(both quarantined) last week which i posted in the General Forum and was advised to run HJT, Panda and Spybot(tomorrow for sure) Could all of these be linked somehow???? Any advice/input would be greatly appreciated Thanks I found the same Trojan in the same place as you, when i did a scan with avg this morning. I find this odd because i have not just downloaded the adobe reader its been on my computer for a while. I have done many scans before this morning that have not found this Trojan. Anyway for now i have moved it to the virus vault |
|
|
|
Oct 17 2008, 11:55 AM
Post
#5
|
|
![]() True Member ![]() ![]() ![]() ![]() Group: Honorary Members Posts: 499 Joined: 29-March 08 From: Merksem-Antwerp, Belgium Member No.: 2,252 |
AVG gave me this message this morning as well (when my notebook was idle!). I decided to ignore it since I haven't updated Adobe Reader for ages.
Kindly regards, Mona. -------------------- Kindly Regards.
Mona. Dell Inspiron 1501: DUTCH OS/WIN XP-SP3 - OA Premium 4.0.0.45, Eset Nod32 4.2.58.3, MBAM Paid version, WinPatrol Plus, SpywareBlaster paid, KeyScrambler Professional Dell Inspiron Mini 1012: DUTCH OS/Windows 7 Home Premium - OA Premium 4.0.0.45, MSE, MBAM Paid version, WinPatrol Plus, SpywareBlaster free, KeyScrambler free |
|
|
|
Oct 17 2008, 12:38 PM
Post
#6
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 17-October 08 Member No.: 4,550 |
I too have the same problem i have moved it to the virus vault while sum1 works out what it is
|
|
|
|
Oct 19 2008, 06:48 PM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 17-October 08 Member No.: 4,559 |
I too got the message re: Trojan Horse Generic11.BEOG which infected the setup.exe file in Adobe Reader 9. I moved it to the Virus Vault. Does anyone know what to do about this? Should I simply delete it from the Virus Vault? Will it affect the usability of Adobe Reader? Any insight on this would be appreciated.
|
|
|
|
Oct 19 2008, 08:39 PM
Post
#8
|
|
|
Forum Deity ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 1,619 Joined: 27-November 06 Member No.: 775 |
It is not a virus, it is a false positive by AVG.
|
|
|
|
Oct 21 2008, 12:12 AM
Post
#9
|
|
![]() New Member ![]() Group: Members Posts: 27 Joined: 5-October 08 Member No.: 4,320 |
I found same "problem" this morning...Yesterday at the same time the scan was done none of those "infections"were there. In mean time Avg did update and "infections" were there. I have send files as well for check up. I went on google to find "virus" but there was nothing except your post! I also have these in vault: C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0010583.exe and this one : C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0000038.exe and same as yours: C:\Program Files\Adobe\Reader9.0\Setup Files{AC76BA86-7AD7-1033-7B44-A90000000001\Setup.exe if i do get some answers i will keep your posted and please do the same! Tnx Hi brannka, I did a second scan and came up with similar System Volume Information\_restore entries. Tigger93(moderator) has posted that it is a false positive. I have requested info as to whether we restore all quarantined items or not No response from AVG, not expecting to see one either. Thank god for MBAM and this forum--awesome Will keep you posted |
|
|
|
Oct 21 2008, 12:28 AM
Post
#10
|
|
![]() New Member ![]() Group: Members Posts: 27 Joined: 5-October 08 Member No.: 4,320 |
It is not a virus, it is a false positive by AVG. Thanks Tigger93 So now do i restore it? Also what do the entries below mean? Restore them all?? FYI, a second scan showed two entries similar to brannka's post below: I found same "problem" this morning...Yesterday at the same time the scan was done none of those "infections"were there. In mean time Avg did update and "infections" were there. I have send files as well for check up. I went on google to find "virus" but there was nothing except your post! I also have these in vault: C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0010583.exe and this one : C:\System Volume Information\_restore-{3F4EE1B5-F71E-43F-9187-0D3999ADCB4E}\RP42\A0000038.exe |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 29th July 2010 - 10:30 PM () |