1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Kapersky online scanner found threats.

Discussion in 'Malware and Virus Removal Archive' started by Vicki, 2009/01/06.

  1. 2009/01/06
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    [Resolved] Kapersky online scanner found threats.

    Hello all!

    I really had no reason to suspect any infections, but thought I'd try the Kapersky online scanner just out of curiousity. Imagine my surprise to say it found some!:eek:

    I currently use AVG, Spybot S&D, Spyware Blaster, and Ad-aware programs. Keep everything up-to-date and do scans at least weekly if not more.

    So how do I rid myself of the threats that this scanner has found?

    Here is the text/log of what the online scanner found:


    KASPERSKY ONLINE SCANNER 7 REPORT
    Monday, January 5, 2009
    Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Monday, January 05, 2009 12:40:14
    Records in database: 1563644


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area My Computer
    A:\
    C:\
    D:\
    E:\

    Scan statistics
    Files scanned 90733
    Threat name 2
    Infected objects 4
    Suspicious objects 0
    Duration of the scan 03:22:46

    File name Threat name Threats count
    C:\Documents and Settings\amd\.housecall6.6\Quarantine\in123093233345432[1].mov.bac_a03736 Infected: Exploit.Multi.Qtp.d 1

    C:\RECYCLER\NPROTECT\00647052.wmf Infected: Exploit.Win32.IMG-WMF.u 1

    C:\RECYCLER\NPROTECT\00647053.wmf Infected: Exploit.Win32.IMG-WMF.u 1

    C:\RECYCLER\NPROTECT\00647054.wmf Infected: Exploit.Win32.IMG-WMF.u 1

    The selected area was scanned.


    Please keep in mind I'm not too terribly computer savvy....will need step-by-step, hold-my-hand type of instructions!:eek:

    Thanks in advance for any advice or assistance you may provide!

    Regards,
    Vicki
     
    Last edited: 2009/01/06
  2. 2009/01/06
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Hi Vicki
    At some time you ran an online scan at Housecall - a nasty was found and placed in quarantine, where it is harmless. Empty the quarantine folder.
    You are running Norton and have the Protected Recycle Bin feature enabled - NPROTECT.

    Right click on the Recycle Bin icon - should be a menu item to empty the Norton Protected Recycle Bin.
     

  3. to hide this advert.

  4. 2009/01/06
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    Need more help

    Thank you Pete for your quick reply to my question about the "infections ". However, I still need some assistance before I tackle this.

    How/where would I find that folder to empty it?


    Didn't realize I had this? I think this computer may have had Norton's AV at one time and I uninstalled it? But that was quite some time ago! I did check the recycle bin icon (right clicked) but these are the only lists that it shows:

    1. open
    2. explore
    3. Scan using Spybot-Search & Destroy
    4. empty recyle bin
    5. create shortcut
    6. properties

    No mention of the Norton Proctected Recycle Bin? Would this be easy to locate to empty?

    Thanks again for your assistance!

    Vicki
     
  5. 2009/01/06
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    the location is shown in the report ......

    C:\Documents and Settings\amd\.housecall6.6\Quarantine\in123093233345432[1].mov.bac_a03736 Infected: Exploit.Multi.Qtp.d 1

    You may need to enable 'Show hidden files and folders' under Tools > Folder Options > View.
    OK, read this .....

    How to remove the NPROTECT folder after deletion of System Works
     
  6. 2009/01/08
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    Thank you Pete for your assistance with this. I was able to locate the housecall quarentined folder and deleted that.

    I read the article from the link you provided, but I must admit I was totally lost and confused by it (there's where my computer illiteracy comes in:eek:). Would there be any harm in just ignoring/leaving those NProtect files alone? I'd certainly hate to try and remove them not knowing exactly what I'm doing and end up messing up my computer to the point of no return!


    Vicki
     
  7. 2009/01/10
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    If you follow these two lines no harm should come to your computer and the files gone, which is to be preferred .....

    1. Click on the 'Start' button and select the 'Run..' option

    2. Copy and paste the following text and click the 'OK' button

    rmdir /s \\?\C:\RECYCLER\NPROTECT


    The NPROTECT folder and its contents will now have been deleted from your system.

    To check go, in Windows Explorer .....

    Tools > Folder Options > View and check 'Show hidden files and folders' and uncheck 'Hide protected operating system files' - agree to the warning dialogue - YES

    In your C:\ drive the folder Recycler will now be visible - double click on it to open. There should not be a Nprotect folder present.

    Go back through Tols > Folder Options > View and check 'Do not show hidden files and folders' and check 'Hide protected operating system files' and OK out.
     
  8. 2009/01/10
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    Error message?

    Thank you Pete for explaining the steps in how to eliminate the NProtect folder. However, when trying to run that command (after doing the copy/paste) I receive an error message(?) stating that "Windows cannot find 'rmdir'....... "

    Is there something wrong/missing on my computer that's not allowing me to do this??:eek:

    Thanks again for your assistance!

    Vicki
     
  9. 2009/01/10
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    No - there is a step missing from that article I posted - should have checked more closely .....

    Start > Run > cmd > Enter

    This brings up a black Command window with the flashing cursor at the end of .....

    C:\Documents and Settings\Your username> _

    type cd\ and hit the Enter key, This takes you to the C:\> prompt followed by the flashing cursor

    Copy the command ....

    rmdir /s \\?\C:\RECYCLER\NPROTECT

    and right click in the Command Window > Paste

    The command string is entered followed by ....

    Are you sure (y/n) - hit the y key followed by the Enter key

    You should receive a message that the removal has been successful

    Close the Command Window
     

    Attached Files:

  10. 2009/01/10
    Vicki

    Vicki Well-Known Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    413
    Likes Received:
    8
    Thank you again Pete for helping me with this. I was relieved to know that there wasn't a problem with my computer :)

    I followed your instructions, but after I chose the "y ", I never received any message stating the removal was successful? It just went back to the C:> prompt.

    I did go back and check to see if the NProtect folder was still there....nope, it's gone! :D

    But in the "recycler" folder there is a file with a big long string of a letter & numbers (S-1-5-21-85235.....there are many more numbers, but you get the idea). Don't remember if I saw that there previously (but I wasn't paying very close attention, just looking for the NProtect file that we were trying to eliminate.) Should this be of any concern?

    Thanks again for your attention to this. I really do appreciate your help!

    Vicki
     
  11. 2009/01/11
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Well done Vicki :cool:
    That's fine - the Command window only reports failure of a command. I rarely have the need to use it and was mistaken re. confirmation
    No - that is the Recycle Bin file and should be there :)
     

    Attached Files:

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.