Hi Ron - I think it might be useful to run A2 (that was my original recommendation, you may remember). Here's its current detection profile for the free version:
Number of Signatures: Trojans 80524 Dialer 27877 Worms 5064 Spyware 4166 Traces 26997
As you can see it's differently oriented than is a virus scanner. You can download the free version here:
formatting link
It shouldn't take nearly as long as SysClean, although it will take a bit. :) Run it from Safe mode w/Internet Access (in order to update) (or update and then boot to Safe mode) or, even better, from a Clean Boot taking into account the following. If it finds anything, clean, reboot and then run it again. After everything is clean in Safe mode or Clean Boot, re-run it after a normal boot still showing hidden files:
From my Blog:
Show hidden files and run all of the following removal tools from Safe mode or a "Clean Boot" when possible, logged on as an Administrator. BEFORE running these tools, be sure to clear all Temp files and your Temporary Internet Files (TIF)(including offline content.) Reboot and test if the malware is fixed after using each tool.
HOW TO Enable Hidden Files
formatting link
Clean Boot - General Win2k/XP procedure, but see below for links for other OS's (This for Win2k w/msconfig - you can obtain msconfig for Win2k here:
formatting link
):
- StartRun enter msconfig.
- On the General tab, click Selective Startup, and then clear the 'Process System.ini File', 'Process Win.ini File', and 'Load Startup Items' check boxes. Leave the 'boot.ini' boxes however they are currently set.
- In the Services tab, check the "Hide All Microsoft Services" checkbox, and then click the "Disable All" button. If you use a third party firewall then re-check (enable) it. For example, if you use Zone Alarm, re-check the True Vector Internet Monitor service (and you may also want to re-check (enable) the zlclient on the Startup tab.) Equivalent services exist for other third party firewalls. An alternative to this for XP users is to enable at this time the XP native firewall (Internet Connection Firewall - ICF). Be sure to turn it back off when you re-enable your non-MS services and Startup tab programs and restore your normal msconfig configuration after cleaning your machine.
- Click OK and then reboot.
For additional information about how to clean boot your operating system, click the following article links to view the articles in the Microsoft Knowledge Base:
310353 How to Perform a Clean Boot in Windows XP
formatting link
How to Perform Clean-Boot Troubleshooting for Windows 2000
formatting link
How to Perform a Clean Boot in Windows Millennium Edition
formatting link
How to Perform Clean-Boot Troubleshooting for Windows 98
formatting link
How to Perform a Clean Boot in Windows 95
formatting link
I did a little research about this Trojan, Downloader.Generic.ML, but couldn't find any information under that name from _any_ of my available resources (including Grisoft, BTW), nor about your aberrant c:\\null file. I would wonder if this is any sort of possible byproduct of some legitimate software heuristically detected by a (recent?) AVG update.
Anyhow, try A2 and post back, please.