Virus Win32:Malware-Gen, How can i get rid of it?????

Hi Mr. Oldman

I’ve done what you asked me to do. but, it automatics rebooted after it done. And I don’t see any combofix.log. Maybe this one I found in windows\temp (T30DebugLogFile.txt) but, it nothing in there (0 KB)

Hi

The log should be at C:\Combofix.txt

If you can’t find the log there we will use another tool to have a look at that folder.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

[*]Double-click SystemLook.exe to run it.
[*]Copy the content of the following codebox into the main textfield
[*]Do not copy the word CODE , please note the script starts with the :

:file
C:\WINDOWS\tepie\install.48143.exe
:dir
C:\WINDOWS\tepie

[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post the combofix log if you found it or the SystemLook log.

Thanks

Thanks for the replied, Mr. Oldman

Yes, I believed that I found combofix.txt in c:\comboFix

Hi domdom63,

Combofix dosen’t seem to have completed. Let’s try again with a new copy.

Please delete the copy you have and download a new one. Don’t run it, we run it with a command.

Download a new copy from one of these links and save it directly to your desktop.

It must be on your desktop, not in a folder on your desktop.

Link 1
Link 2

Please follow all previous instructions regarding security programs.

Don’t be alarmed if your desktop disappears during the fix. It will reappear. Don’t mouse click or do anything else while the tool is tunning.

Open a new Notepad session
[*]Click the Start button, click run
[*]in the run box type notepad
[*]click ok
[*]In the notepad, Click “Format” and be certain that Word Wrap is not checked.

[*]Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

KillAll::

File::
C:\WINDOWS\tepie\install.48143.exe

Folder::
C:\WINDOWS\tepie



In the notepad
[*]Click File, Save as…, and set the Save in to your Desktop
[*]In the filename box, type (including quotation marks) as the filename: “CFScript.txt”
[*]Click save

Next, click your start button, click run.

In the run box, copy and paste the following bolded line (it’s one long line), then click OK.

“%userprofile%\desktop\combofix.exe” “%userprofile%\desktop\combofix.exe\CFScript.txt”

Please post back with the combofix log.

Mr. Oldman,

I’ve tried that but, when I enter
“%userprofile%\desktop\combofix.exe” “%userprofile%\desktop\combofix.exe\CFScript.txt”
The comboFix.exe started
After a few minutues I have this messages

ERROR - Script format is incorrect
Rich Text Formats (RTF) are unacceptable !!
Please save CFScript commands as a textfile, using notepad.exe

… But I did exactly what you told me to do

Hi

Are you using notepad? The message would see to be consistant with using wordpad.

yes, i used notepad.exe

Oh, never mind Mr. Oldman,
I redo the text file and draged it to combofix’s icon and it does the works. And here is the log.txt file for you.

Thank you

Oh no,

My computer is crashed. It keeps reboot. I have to put the recover disk to install the window now. Ím using my laptop to reply to you :frowning:

Hi,

What were you doing when it crashed?

I turned off before to bed
The next morning it was been up all night with booting windows still on

Hi

You shut the computer down completely and it attempted to restart?

Before you do anything drastic like reinstalling windows, is your disk a full copy of XP?