ope this would help.
Virus Description:
the virus only infect exe files. but it would infect your antivirus software and userinit.exe which
would be run as you logon. the DL.exe keep downloading the virus from "utenti.lycos.it" which could be see if you open
the dl.exe or userinit.exe with ultraedit32 and search for "lycos.it". The virus would attach the dl.exe to some important
windows exe files like userinit.exe, regedit.exe, iexplore.exe, rundll32.exe(it is run when you use the windows add/remove programs).
So it come back quickly.
Want to know more:
The description of McAfee of this Virus:
»vil.nai.com/vil/content/v_134857.htm
Somehow difference is that I didn't find the GAELICUM.EXE nor the CBACK.exe on my laptop.
A virus analysis:
»
www.nod32.com/msgs/tengaa.htm
Remove instruction:
1.kill excess process in the windows task manager, which means leave the the svchost.exe there, end the other process you could kill.
Those process showing two name there, the one with about 4~6k memory should be the virus dl.exe.
2.after killing the excess process, you should be able to access to internat temporary. Download the Malware remove tools
from Microsoft quickly:
»
www.microsoft.com/downloads/deta···ylang=en
run it and it should find the w32/Gael virus, thousands of files infected, repaired them.
Some of the exe files may be removed here, so far I only got two of my program files missing.
after that, would be asked to restart, before you restart, do these things:
a. del any values in the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
b. del anything in the windows/prefatch and set the folder to read only
c. open your administrative tools/services, stop any excess services related to your installed programs, which are usually with a short description, and set them or manual or disabled.
d. DISCONNECT your computer from internat, unplug the cable and stop wireless network. This make sure virus won't come back from internat again.
when the virus is there, although it seem that you could not access to internat through internat explore, the virus could still access the virus server.
3.Now after restart your computer, open your task manager quickly, if any excess process is there,like the userinit.exe, cftmon.exe,wscntfy.exe,kill them quickly.
4.Do a quick check with the Malware remove tools from microsoft, should be not files infected. Don't run any excess programs, they may still be infected.
5.Bring up the windows add/remove programs and remove your antivirus software and reinstalled it, make sure you install from cd and the installation files are not infected, while doing this,
keep tracking the process with the task manager, any process(except svchost.exe) appear with two,should kill the one with about 4~6k memory quickly.
if you are asked to restart after remove program, make sure step 2.a, 2.b, 2.c, 2.d are done. after restart, do a quick check with malware remove tool
6.restart after you reinstall you antivirus software, if the antivirus software is working, job is almost done. Make sure step 4 is done. If the antivirus software is still not working, go back to step 1, make sure you are disconnected from internat from step3 to step6.
if this still doesn't work, leave me a message.
7.Now you could plug in your cable, do the antivirus update first, after restart, do the full scan, you should still find some virus on your computer,
kill them or repair them. Now it is done.