Computer Help Forums

Computer Help Forum > Operating Systems > System Security & Infection Support > three infected files found!!!

Reply
Thread Tools Display Modes

three infected files found!!!

 
 
THQ Newbie
Join Date: Dec 2004
Location: Virginia
Age: 27
Posts: 7

andriarox is on a distinguished road to becoming a computer geek
 
      Dec 27th, 04, 5:50 AM
I scan my computer everyday with the AVG Virus program and for the passed week I keep getting the same Virus list each time and it says "0 files healed" and it won't let me send them to the Virus Vault to be deleted. Here is the list:
"C:\WINDOWS\TEMP\polmx2.cab:\polmx2.exe","Troj an horse Downloader.Agent.AS","Infected, Embedded object"
"C:\WINDOWS\TEMP\polmx3.cab:\polmx3.exe","Troj an horse Downloader.Agent.AS","Infected, Embedded object"
"C:\WINDOWS\TEMP\conscorr.cab:\conscorr.exe","Troj an horse Downloader.Stubby.C","Infected, Embedded object"

What should I do?
 
Reply With Quote
 
 
 
 
ST 38
Join Date: Jul 2004
Location: Honolulu, Hawaii
Age: 22
Posts: 2,218
spike228's Avatar

spike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to behold
 
      Dec 27th, 04, 8:13 AM
scan in safemode and then delete them. if that fails then try search the DIR in safemode and delete it manually.
 

 
Reply With Quote
 
Regular @ THQ
Join Date: Nov 2004
Location: Townville
Age: 43
Posts: 249

Tosca will become a geek soon enoughTosca will become a geek soon enough
 
      Dec 27th, 04, 9:49 AM
I've seen advice on many occasions about searching/deleting/running AV in Safe Mode rather than folowing a normal full boot. I know that Safe Mode loads a limited number of drivers but how else does this mode allow AV functions/deletion of files etc. to be done whilst a normal full boot does not?
 
Reply With Quote
 
Photojournalist
Join Date: Dec 2002
Location: Maine, USA
Age: 28
Posts: 6,601
James's Avatar

James has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mindJames has a brilliant tech mind
 
      Dec 27th, 04, 1:17 PM
Andria, Have you tried delete those files? If you cannot in Windows, boot in Safe Mode w/ Command Prompt.

If you're not familiar with changing directories via command prompt follow these commands:

CD\
CD windows\temp
dir /w
del filename.extension
 

 
Learn about the man behind the screen.

My Zenfolio - Photography
Reply With Quote
 
Regular @ THQ
Join Date: Nov 2004
Location: Townville
Age: 43
Posts: 249

Tosca will become a geek soon enoughTosca will become a geek soon enough
 
      Dec 27th, 04, 2:21 PM
Hi James

I'm familiar with these commands and techniques but WHY is this possible when in Safe Mode but not following a normal full boot? Is it because some drivers are not loaded or other reasons?
 
Reply With Quote
 
Assistant Sensei
Join Date: Aug 2004
Location: VA & NC
Age: 24
Posts: 1,162
D Schrute's Avatar

D Schrute is a splendid one to beholdD Schrute is a splendid one to beholdD Schrute is a splendid one to beholdD Schrute is a splendid one to beholdD Schrute is a splendid one to beholdD Schrute is a splendid one to behold
 
      Dec 27th, 04, 3:04 PM
The files that are infected may be in use during a normal boot whereas booting into safemode only allows for the bare minimum of files to be used.
 

 
"I can travel anywhere, except Cuba, and I will travel to New Zealand and walk the Lord of the Rings trail to Mordor and I will hike Mount Doom." ~Dwight K. Schrute
Reply With Quote
 
Addicted to THQ
Join Date: Apr 2003
Location: Ann Arbor, Mi
Age: 26
Posts: 2,925
Fenis-Wolf's Avatar

Fenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geeknessFenis-Wolf has much to be proud of his / her geekness
 
      Dec 27th, 04, 3:19 PM
Its because the virus is loading those files into memory and marking them as being used by the System. Booting into Safe Mode forces only the most limited, Microsoft approved things to load. Thus allowing the virus scan software to safely remove it.
 
Reply With Quote
 
Regular @ THQ
Join Date: Nov 2004
Location: Townville
Age: 43
Posts: 249

Tosca will become a geek soon enoughTosca will become a geek soon enough
 
      Dec 27th, 04, 5:33 PM
Cool. My belief about minimal drivers etc. was correct - I just didn't know why!


Thanks
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dial Up connection infected Nickweb System Security & Infection Support 16 Mar 1st, 07 10:46 AM
Infected...HJT Log TheOneGreatX System Security & Infection Support 6 Jul 7th, 06 9:48 AM
Trojan RC5.A I'm Infected... DaVo System Security & Infection Support 5 Apr 6th, 04 2:18 PM
Infected Files . . SwitCh System Security & Infection Support 5 Feb 15th, 04 8:01 PM
Files can't be found sammy004 Software Support 9 Nov 20th, 03 3:02 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36