BleepingComputer.com: Is This A Backdoor Trojan? How To Remove. Gen.peed.emi.384a84a7

Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Is This A Backdoor Trojan? How To Remove. Gen.peed.emi.384a84a7

#1 User is offline   teachtom 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 16
  • Joined: 27-April 07

Posted 11 August 2007 - 04:16 PM

When I last ran My BitDefender Vol10 AV this could not be Disinfected or moved. Please tell me how to remove. I ran SAS, spybot, A-Squared Anti-Malware,and ATF Cleaner but showed to still be there. Thanks for your help. Here is what was on report Generic.Peed.Emi.384A84A7 Teachtom

#2 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,490
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 11 August 2007 - 05:27 PM

There were no results in Google for "Generic.Peed.Emi.384A84A7"
If you can locate the file that Bit Defender says is infected, submit it to Jotti. The link and instructions are below.
http://virusscan.jotti.org/

If you are unable to submit the file to Jotti, run and online virus scan using Kaspersky and let us know what malware if any it finds.
http://www.kaspersky.com/virusscanner

#3 User is offline   TMacK 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 4,672
  • Joined: 18-March 06
  • Gender:Male
  • Location:B.C. Canada

Posted 11 August 2007 - 06:30 PM

Hi teachtom,

One of Agent.AF many aliases is Trojan.Peed.HXN (BitDefender).

The only Spyware removal tool that you haven't tried (that I know of) is Spyware Terminator.
Chaos reigns within.
Reflect, repent, and reboot.
Order shall return.

aaaaaaaa a~Suzie Wagner

#4 User is offline   teachtom 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 16
  • Joined: 27-April 07

Posted 11 August 2007 - 10:47 PM

C:\Documents and Settings\Tom\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Inbox.dbx=>(message 56) Infected: Generic.Peed.Eml.384A84A7
C:\Documents and Settings\Tom\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Inbox.dbx=>(message 56) Disinfection failed
C:\Documents and Settings\Tom\Local Settings\Application Data\Identities\{DFF16927-88E6-4EAA-A097-460B7E65289B}\Microsoft\Outlook Express\Inbox.dbx=>(message 56) Move failed
Here is the virus report from my last scan. I also ran the Kaspersky, but it didn't catch it. Thanks

#5 User is offline   TMacK 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 4,672
  • Joined: 18-March 06
  • Gender:Male
  • Location:B.C. Canada

Posted 12 August 2007 - 12:44 AM

Jotti Virus Scan picked up this Trojan as well.

Did you run Spyware Terminator?

If so, please Post a HijackThis Log in the in the Hijack and Analysis Forum by following the directions in this link; Preparation Guide for use before posting a HijackThis Log .

Please do not post the log in this forum.
Chaos reigns within.
Reflect, repent, and reboot.
Order shall return.

aaaaaaaa a~Suzie Wagner

#6 User is offline   teachtom 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 16
  • Joined: 27-April 07

Posted 12 August 2007 - 09:44 AM

Hi TMacK, I went into safe mode and ran SpyWare Terminator, then ran SAS. Both showed no problems found. I could not get BD AV to load in Safe mode, so I went into desktop and ran it. It showed the same problem as before. Generic.Peed.Emi.384A84A7. What should I do next? Thanks, Tom

#7 User is offline   TMacK 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 4,672
  • Joined: 18-March 06
  • Gender:Male
  • Location:B.C. Canada

Posted 12 August 2007 - 10:06 AM

Hi teachtom,

Follow the instructions in the thread from the BitDefender Forum.
Then run your BitDefender AV Scan.

Please report back the results.
Chaos reigns within.
Reflect, repent, and reboot.
Order shall return.

aaaaaaaa a~Suzie Wagner

#8 User is offline   teachtom 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 16
  • Joined: 27-April 07

Posted 12 August 2007 - 08:33 PM

TMack Thanks for the help . I got my problem fixed at BD Forums. Many thanks. teachtom

#9 User is offline   teachtom 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 16
  • Joined: 27-April 07

Posted 13 August 2007 - 07:05 AM

Please help. I still have this malware. I forgot to update my AV, then when I did and rescanned the gen.Peed was still there. I hope someone has new advice. Thank you.

teachtom

#10 User is offline   TMacK 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 4,672
  • Joined: 18-March 06
  • Gender:Male
  • Location:B.C. Canada

Posted 13 August 2007 - 11:00 AM

I think it's time for the Hijack Team to have a look at this.

Post a HijackThis Log in the in the Hijack and Analysis Forum by following the directions in this link; Preparation Guide for use before posting a HijackThis Log .

Please do not post the log in this forum and be patient for a reply as they are a very busy forum.
Chaos reigns within.
Reflect, repent, and reboot.
Order shall return.

aaaaaaaa a~Suzie Wagner

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users