tcb3210
Joined: 20 Sep 2007 |
Posts: 0 |
|
|
 |
Posted: Thu Sep 20, 2007 3:52 pm |
|
 |
 |
 |
 |
After I scan my computer,It shows that there are 9 files infected:
C:\WINDOWS\system32\dllcache\NOTEPAD.EXE: Trojan.Dropper-1206 FOUND
C:\WINDOWS\system32\notepad.exe: Trojan.Dropper-1206 FOUND
C:\WINDOWS\notepad.exe: Trojan.Dropper-1206 FOUND
C:\Documents and Settings\welcome\Local Settings\Application Data\Mozilla\Firefox\Profiles\ochvjnzm.default\Cache\_CACHE_002_: JS.Psyme-7 FOUND
C:\Documents and Settings\welcome\Local Settings\Application Data\Mozilla\Firefox\Profiles\ochvjnzm.default\Cache\_CACHE_003_: Trojan.Downloader.Istbar-207 FOUND
C:\Documents and Settings\welcome\Local Settings\Application Data\Mozilla\Firefox\Profiles\ochvjnzm.default\Cache\79D8733Ad01: Exploit.Iframe-1 FOUND
C:\Program Files\Freesoft\tools\内存回收专家.exe: W32.Zloyfly FOUND
C:\System Volume Information\_restore75C08FAA-7B2E-429B-87D8-64B32E23ACAF\RP22\A0004589.exe: Trojan.Dropper-1656 FOUND
C:\System Volume Information\_restore75C08FAA-7B2E-429B-87D8-64B32E23ACAF\RP37\A0012978.exe: Trojan.Dropper-1206 FOUND
I try to delete the files ,but it notices me that some are system files ,I can't delete the file .Then what should I do with the files infected?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Fri Sep 21, 2007 1:40 am |
|
 |
 |
 |
 |
Malware is becoming hard to get rid of once it infects you. A good antispyware program can remove some tough trojans. If you aren't using one, you might try downloading a trial copy of one of the better antispywares. Configure it for maxiimum security. I also think you need something better than LavaSoft or Spyware Search & Destroy. If that doesn't work...
Use your previous ClamWin scan logs to find your last clean scan and see if you can use System Restore to restore the system files back to a time before you got the infections.
You should be able to manually delete the malware in your Firefox cache.
If you turn off System Restore, you should lose the Trojan Droppers in there. Don't turn on System Restore until all malware is gone.
Next to the last suggestion: boot into Safe Mode and see if you can delete the files.
Last suggestion: Ask for help from the forum on "Am I Infected? What To Do?"
Good Luck,
|
|
tcb3210
Joined: 20 Sep 2007 |
Posts: 0 |
|
|
 |
Posted: Fri Sep 21, 2007 3:29 pm |
|
 |
 |
 |
 |
thank you !
I will have a try.
|
|
tcb3210
Joined: 20 Sep 2007 |
Posts: 0 |
|
|
 |
Posted: Fri Sep 21, 2007 3:45 pm |
|
 |
 |
 |
 |
another question,when i run the clamwin free antivirus on my friends computer ,it notice me the same result of mine ,while i run the kaspersky anti-virus personal version ,no malware is detected.it makes me fussed . what need i to do?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Fri Sep 21, 2007 10:02 pm |
|
 |
 |
 |
 |
Kaspersky generally has better detection capability than ClamWin, although once in a while ClamWin may find something that Kaspersky doesn't.
I always upload a copy of any file that my antivirus finds to VirusTotal at https://www.virustotal.com/ on the Web or to Jotti at https://virusscan.jotti.org/ on the Web. Both of these services will scan your file for free with multiple antivirus programs--including Clam/ClamWin and Kaspersky. If If Clam/ClamWin is the only one that finds a virus/malware, it is probably a false positive, but if more than one antivirus finds a virus/malware, then it is probably a real virus.
Regards,
|
|