by Methious » Sun Dec 23, 2007 11:11 pm
I just got done with a PC AVG antivirus/spyware, Geede.exe slipped right past both, and so did xpx? ( ? being a special character ) root kit. I been using Avg AV and Windows Defender so I checked my system32 directory and fortunately I'm clean. If you find Geede.exe or Geede.dll in system32 (and there are a bunch of other lettered names it uses) it's a bad one. Even in safe mode you can't delete the .dll, and after reboot the .exe is back. Edit Geede out of the registry and the machine hangs at "windows is loading" forever. AVG root kit did detect and try to remove it but to many files were infected.
Common names GEEBB.EXE,GEBYV.EXE,DDABY.EXE,SSTTU.EXE,PMKJH.EXE,AWTST.EXE,GEBCA.EXE,DDCYY.EXE,SSTTQ.EXE,DDAYX.EXE,AWVTR.EXE,GEEDE.EXE,MLLMJ.EXE,
MLJJI.EXE,MLLJG.EXE,MLJGF.EXE,AWTSS.EXE,VTURR.EXE,SSQPQ.EXE,SSQRQ.EXE,PMKJI.EXE,PMNNO.EXE,GEBYA.EXE,JKHFF.EXE,DDCCD.EXE,DDAYA.EXE,
VTURS.EXE,MLLMK.EXE,AWTQP.EXE,DDCCY.EXE,SSQPM.EXE.
Summary : Trojan.Downloader-ConHook.Process
Description : Conhook/Vundo-related downloader component
Here's the scary part, he got it from a 3dmark06 he downloaded from some game site. Thought I'd pass the info. By the time I got the machine he had over a hundred infections (he downloaded it yesterday), had to reload his rig.
