Unsolved

This post is more than 5 years old

3 Posts

5133

March 20th, 2008 23:00

Virus Alert: Generic9.acnh (dgnetc.dll)

Hi everybody,

 

I was helping a client clean up his laptop last night and while scanning his Dell laptop using AVG it detected the above virus located in the above file under Windows/system32

 

When I press Heal, it reboots. I can put it in the vault, but it still pops-up.

 

I've been researching the Generic9.xxxx and Generic6.xxxx viruses on several forums and the consensus seems to include booting into Safe Mode and then scanning with AVG to kill it. Is that the case here or does anyone know something else about this specific virus?

 

We are using XP Pro, IE 7, Firefox, AVG 7.5 Free, Windows Firewall and Ad-Aware Free with all possible updates included.

 

Thanks in advance for your help.

 

Dan,

San Francisco, CA

 

Message Edited by dbmay75 on 03-20-2008 05:49 PM
Message Edited by dbmay75 on 03-20-2008 05:49 PM

2.9K Posts

March 20th, 2008 23:00

If you've researched this problem and the recommendation is to scan in safe mode, have you done that? That would be a logical first step!

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

March 21st, 2008 12:00

please confirm the presence of the letter 'c' at the end of the file name:   is it really dgnetc ?  or is it simply dgnet (without the 'c') ?

 

dgnet.dll (without the 'c') is a legitimate Microsoft file.   in fact, i have two copies of it (on my xp pro system), one located in windows\system32 , the other located in \i386

 

the 'generic' detection... generally indicative of a heuristic 'hit'... is often prone to being a false positive.

 

[you can try temporarily turning heuristic anlysis off:

click on the avg control center

resident shield

properties

UNcheck the box marked Use Heuristic Analysis]

 

i don't know if avg will even allow you to access the file, but if you can

you might be able to upload a copy of the file to one, or both, of the following sites, to have them analyze it for you:

 

jotti's virusscan  

 

virustotal.com

 

if they say it's clean, you should be okay.

 

p.s.  if you temporarily turned-off heuristics in order to access/upload the file, be sure to turn heuristic back on when you're done.

3 Posts

March 21st, 2008 15:00

Hi,

 

Yes, it's dgnetc.dll

 

Thanks for the AVG tip on the false positive. I will check those once I access his laptop again. While the client had McAfee running in the systray, it had expired and he also admitted to frequently visiting porn sites so I expected something like this to happen.

 

My main concern is the fact that the laptop reboots if we try to heal the virus. Whether or not it's clean, it needs to be removed so I'll try the Safe Mode scan at that point.

 

What's your thoughts on the Comodo Firewall?  Is it annoying like ZoneAlarm or quiet like Windows?  This client is not tech-savy and I would hate to explain how to deal with the constant ZA pop-ups, etc.

 

Thanks again,

Dan

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

March 21st, 2008 16:00

with the 'c', i have no idea what the file is.... but a "gut"/"hunch" says it could be a virus, trying to "pass itself off" as the legitimate microsoft file (no 'c').

 

if you can access that file (avg may not let you), the jotti and/or virustotal online scanners would still be the way to go:   each one accesses a large database of virus companies (including symantec/norton and mcaffee) and displays the results of each.   should avg be the sole product asserting it's an infection, then odds are it's a false positive.  but if others likewise find problems with the file, that's another story.

 

as for comodo (vs. zonealarm), there are at least two points [and probably more] that need to be considered... effectiveness of the product, and ease-of-use.

 

it seems you're concerned about the latter:  ease of use.   comodo goes through a "learning" process... when first installed, it can inquire about any attempt to access the internet.  you have to "teach" it... telling it to remember your answers... and after a "short" while, you tend to see fewer popups from it.

however, any time a particular program is updated, changing its "cryptographic signature", comodo will advise you as such [just in case it was spyware tampering with a program, rather than an actual update].   so yes, your client will need to interact somewhat with comodo.

 

the current version, 3.x, seems to require more input on the part of the user.   the previous version, 2.4.x, is still fully supported, and more "user friendly".   if you opt for comodo for your client, i would suggest the 2.4 rather than the 3.0

 

in terms of effectiveness, commodo is getting raving reviews, while zone alarm --- in particular, the free version --- is getting massacred.

Message Edited by ky331 on 03-21-2008 01:20 PM

3 Posts

March 21st, 2008 17:00

Yes, I believe your gut hunch is a good one...anything that shuts down the OS in defense of being eliminated is grounds for a virus in my humble opinion.

 

Thanks for the Comodo feedback.  I myself use only Windows FW, and haven't encountered any attacks after almost a year (I also don't intentionally enter porn sites, lol) but I knew there had to be something as thorough as ZA, but not as obtrusive while surfing and without having to purchase a full fledged security suite.

 

I will report back here after verifying the .dll with jotti/virustotal and doing a Safe Mode scan with AVG.

 

Lastly, which free Anti-Spyware program(s) do you find to be the best these days?  I use Ad-Aware free and I splurge on Spyware Doctor as I found Webroot to be less than satisfying.

 

Have a great Easter weekend!

 

Dan 

 

 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

March 21st, 2008 17:00

one other point on firewalls... nowadays, many people are connected via routers, which typically include their own hardware (generally "NAT" -- Network Address Translation) firewall.  it's okay to combine such a hardware firewall, together with ONE software firewall (Windows, ZoneAlarm, Comodo, etc).   While Windows FW by itself leaves much to be desired, when used in conjuction with a router firewall, the combination is formidable.

 

i was a long time user of Ad-Aware SE.   but i've been very disappointed with their 2007 "upgrade"... and no longer recommend it. 

 

my anti-spyware recommendations are somewhat dependent on the user's operating system.   You mentioned XP at the start of this thread... 

 

for Windows XP (especially for people still using I.E.6):

 

resident protection:   Windows Defender along with Spybot's TeaTimer (yes, I use/run both).

[Note:  Windows Defender and SpyBot each include a "rudimentary" on-demand scanner]

additional on-demand scanners:  SuperAntiSpyware (SAS) and MalwareBytes AntiMalware (MBAM)

immunization via Spybot [optionally including HOSTS file immunization], as well as  SpywareBlaster.

use of Spybot's SDHelper BHO.

pseudo-protection:   WinPatrol.

 

==============================================================================

 

Here are the program links:

 

Windows Defender  [Windows XP Service Pack 2; or Windows Server 2003 Service Pack 1 (or higher); and I believe it's automatically included as part of Vista]
SpyBot Search & Destroy 1.5  [Windows 98/ME/NT/2000/XP/2003/Vista ; some functions need administrator rights]
[While others (including Joe53) may differ on its optimal usage,
I myself use SpyBot for ALL of the following under Windows 98/ME/XP (with IE6) ---
but suggest using only its on-demand scanner under Vista (with UAC) & IE7 (with anti-phishing):
1) Immunization (optionally including HOSTS file protection),
2) SDHelper (Browser Helper Object for Internet Explorer), 
3) TeaTimer (realtime protection), and 
4) on-demand scanner / removal ;
for more details on these various features, see my post here:

 

SuperAntiSpyware (FREE Edition for Home Users) [Windows 98, 98SE, ME, 2000, Vista, 2003 and XP Home/Pro]
MalwareBytes AntiMalware (Scanner/Remover is FREE) [Windows 2000, XP, Vista]
SpywareBlaster [for all versions of Windows --- but some people believe it's not necessary for Vista]

Note:  for my personal  taste/usage, I have "tweaked" one setting in SpywareBlaster: 

under restricted sites, i have UNchecked the one marked

DoubleClick(2) doubleclick.net

simply because it seemed that just about EVERY site i use was "guilty" of invoking this, and i got tired of continually getting security warnings about it.   that's my choice... other users can decide for themselves.

 

WinPatrol [Windows 98 through Windows Vista]: 

 

No Events found!

Top