1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active Infected?

Discussion in 'Malware and Virus Removal Archive' started by llsshopping, 2010/05/08.

  1. 2010/05/18
    llsshopping

    llsshopping Inactive Thread Starter

    Joined:
    2009/12/22
    Messages:
    92
    Likes Received:
    0
    Thanks. I will take a look. Other than that, what, if anything, should I do next?,
     
  2. 2010/05/18
    crunchie

    crunchie Inactive

    Joined:
    2010/01/12
    Messages:
    982
    Likes Received:
    5
    If that does not fix it, you may have to do a repair of the operation system installation.
    Let me know how you go.
     

  3. to hide this advert.

  4. 2010/05/18
    llsshopping

    llsshopping Inactive Thread Starter

    Joined:
    2009/12/22
    Messages:
    92
    Likes Received:
    0
    Will do. How about any virus/malware issues? Do you see anything I should be concerned about?

    Thanks
     
  5. 2010/05/18
    crunchie

    crunchie Inactive

    Joined:
    2010/01/12
    Messages:
    982
    Likes Received:
    5
    Nothing has stood out in the logs ou have posted and Eset finds it clear. You can try a Kaspersky online scan if you wish?

    • Click START then RUN
    • Now type Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

      ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.
     
  6. 2010/05/19
    llsshopping

    llsshopping Inactive Thread Starter

    Joined:
    2009/12/22
    Messages:
    92
    Likes Received:
    0
    I ran Kaspersky again and it found a threat. Here is the log. Although the infected file is different, the threat is the same, Infected: Trojan-Dropper.Win32.Delf.feq 1. What can I do about this?

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Wednesday, May 19, 2010
    Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Wednesday, May 19, 2010 00:28:03
    Records in database: 4129822
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    Y:\
    Z:\

    Scan statistics:
    Objects scanned: 291205
    Threats found: 3
    Infected objects found: 5
    Suspicious objects found: 0
    Scan duration: 12:03:52


    File name / Threat / Threats count
    C:\Documents and Settings\Lance\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.20 2
    C:\Documents and Settings\Lance\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: not-a-virus:RemoteAdmin.Win32.RAdmin.21 2
    F:\System Volume Information\_restore{D485EE5B-6029-44DA-9697-9274931CC937}\RP3\A0001175.exe Infected: Trojan-Dropper.Win32.Delf.feq 1

    Selected area has been scanned.
     
  7. 2010/05/19
    crunchie

    crunchie Inactive

    Joined:
    2010/01/12
    Messages:
    982
    Likes Received:
    5
    Two are from emails and the other could have been picked up from a particular website that you frequent.

    Update malwarebytes and run it again (full scan) and see if it picks up the Delf entry.
    If it doesn't, you will have to disable ans re-enable system restore.
    The other two should be deleted manually.
     
  8. 2010/05/21
    llsshopping

    llsshopping Inactive Thread Starter

    Joined:
    2009/12/22
    Messages:
    92
    Likes Received:
    0
    The two from the emails are fine. As for the third, not sure where it could be coming from, but if it is not picked up, I should disable, delete, re-enable?

    Thanks again.
     
  9. 2010/05/21
    crunchie

    crunchie Inactive

    Joined:
    2010/01/12
    Messages:
    982
    Likes Received:
    5
    Correct :). Except it's just Disable and re-enable.
     
  10. 2010/05/21
    llsshopping

    llsshopping Inactive Thread Starter

    Joined:
    2009/12/22
    Messages:
    92
    Likes Received:
    0
    Malwarebytes found nothing. Should I delete the file?
     
    Last edited: 2010/05/21
  11. 2010/05/22
    crunchie

    crunchie Inactive

    Joined:
    2010/01/12
    Messages:
    982
    Likes Received:
    5
    Should do. PC going ok?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.