defpig99
Joined: 16 Sep 2008 |
Posts: 0 |
Location: nyc |
|
 |
Posted: Tue Sep 16, 2008 7:20 pm |
|
 |
 |
 |
 |
My laptop (windows xp) seemed to be running slower then usual so i ran a scan. i scanned my hard drive and got the below report. Now what do i do? Any help will be very appreciated to this rookie. Thanks
C:\Documents and Settings\Lou\Desktop\Unused Desktop Shortcuts\SmitfraudFix\Process.exe: Trojan.Killproc-1 FOUND
C:\Documents and Settings\Lou\Desktop\Unused Desktop Shortcuts\SmitfraudFix\restart.exe: Trojan.Shutdowner FOUND
C:\IBMWORK\Q822603\822603SV.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822603\822603TR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822603\822603US.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827AR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827BR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827CS.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827CT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827CZ.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827DK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827FI.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827FR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827GK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827GR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827HB.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827HU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827IT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827JP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827KR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827NL.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827NO.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827PL.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827PO.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827RU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827SP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827SV.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827TR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q822827\822827US.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642AR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642BR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642CS.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642CT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642CZ.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642DK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642FI.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642FR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642GK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642GR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642HB.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642HU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642IT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642JP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642KR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642NL.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642NO.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642PL.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642PO.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642RU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642SP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642SV.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642TR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823642\823642US.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837AR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837BR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837CS.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837CT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837CZ.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837DK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837FI.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837FR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837GK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837GR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837HB.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837HU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837IT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837JP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837KR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837NL.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837NO.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837PL.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837PO.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837RU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837SP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837SV.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837TR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q823837\823837US.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025AR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025BR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025CS.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025CT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025CZ.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025DK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025FI.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025FR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025GK.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025GR.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025HB.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025HU.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025IT.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025JP.EXE: W32.Parite.B FOUND
C:\IBMWORK\Q824025\824025KR.EXE: W32.Parite.B FOUND
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe: Adware.Downloader-7 FOUND
C:\WINDOWS\system\script.ini: Trojan.IRCBot-96 FOUND
C:\WINDOWS\system\sup.bat: Trojan.BAT.Small-6 FOUND
C:\WINDOWS\system\sup.reg: Trojan.WinREG.Zapchast FOUND
C:\WINDOWS\system32\Process.exe: Trojan.Killproc-1 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 421050
Engine version: 0.93.1
Scanned directories: 11398
Scanned files: 103519
Infected files: 97
Data scanned: 26133.63 MB
Time: 27997.281 sec (466 m 37 s)
--------------------------------------
Completed
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Tue Sep 16, 2008 8:45 pm |
|
 |
 |
 |
 |
You should always try to verify a file is infected before you do anything. A "good" program will occasionally trigger a false alert, and false positives happen from time-to-time with all antivirus programs.
In this case, most of the infections are due to one virus. You don't ordinarily see that many infections of one virus. Upload a copy of one of the Parite-infected files (identified on your scan report) to Jotti at https://virusscan.jotti.org/ on the web and get a free scan with 19 antivirus programs (including Clam). If more than a couple of other antivirus programs say the file is infected, it is probably a real infection and not a false positive. You might also want to verify/upload each of the other files (one-at-a-time), although it looks to me like they are real infections. Another scanning service is VirusTotal at https://www.virustotal.com/ on the web.
If you find an infection is real, change ClamWin's general preferences to Move To Quarantine Folder and re-scan. Each infected file found by ClamWin will then be moved to the quarantine folder, and you can delete it from there. The location of the folder will be noted below the Move To Quarantine Folder block under preferences.
Afterwards, be sure to re-set ClamWin's general preferences to Report Only. You have three choices to treat an infection (Report, Remove, or Quarantine), and Report is the best choice. If you choose Quarantine, you might quarantine an important Windows system file that has a false positive, and you would lose access to Windows (it happened to me once). If you choose Remove, the file will be removed by ClamWin as soon as it is found.
Regards,
|
|
Theoracle117
Joined: 18 Sep 2008 |
Posts: 0 |
Location: san diego |
|
 |
Posted: Fri Sep 19, 2008 12:12 am |
|
 |
 |
 |
 |
WHOAH!
Thats alot of infected files
usually when you have that many infections, you will see...
1- computer slows down ALOT
2- wierd antiviruses automatically installed on your desktop
3- getting alot of alerts from other unknown or fake antiviruses.
|
|