Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 9th, 2009, 02:55 AM
xMarkx's Avatar
xMarkx xMarkx is offline
Frequent Poster
 
Join Date: Dec 2008
Posts: 447
Default Infection

Hello,

I have: Windows XP Home Edition SP3, 32-bit computer will all the latest Windows Updates on a Dell Dimension 8400 with ESS v3.

Yesterday, during a scan, it picked up the following:

Object Name: C:\I386\GTDownDE_87.ocx
Reason: Probably a variant of Win32/Adware.Agent application

Today, when I left the computer idle for an hour or two and came back NOD32 found the following:

Object Name: C:\System Volume Information\_restore{random letters and numbers here going on for a while}\RP927\A0106100.ocx

Reason: Probably a variant of Win32/Adware.Agent application

Other Information:

• Real-time file system protection
• C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP927\A0106100.ocx
• Probably a variant of Win32/Adware.Agent application
• Cleaned by deleting - quarantined
• NT AUTHORITY\SYSTEM
Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe. <--- What does this mean?

I haven't a single virus in over a year! I have never had a virus 2 days in a row before... what's going on? I haven't visited any bad websites or downloaded anything bad.

What are these things and how am I getting them? Help! Thanks.
__________________
ESET NOD32 Antivirus v6

Last edited by xMarkx : February 9th, 2009 at 03:37 AM.
  #2  
Old February 9th, 2009, 04:57 AM
PaulB2005 PaulB2005 is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 525
Default Re: Infection

The first one is the virus which ESS removed.

The second is the copy of it Windows made in System Restore when ESS removed it. You are NOT infected by the second one. It's just lying dormant inthe System Restore folders. As long as you don't restore your PC back to a time when you had th virus you are still clean.
__________________
ESET NOD32 Anti Virus 4.2.64.12
AMD 64 X2 4400+
Asus A8N-SLi Deluxe (Bios 1016)
3 Gb RAM
Sony DVD-RAM AW-G170A
Seagate ST3200820AS (200 Gb Main Drive)
  #3  
Old February 9th, 2009, 05:50 AM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Infection

If I remember right they are both something to do with Dell support programs. I would follow the usual steps for getting a False Positive fixed.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #4  
Old February 9th, 2009, 09:39 PM
xMarkx's Avatar
xMarkx xMarkx is offline
Frequent Poster
 
Join Date: Dec 2008
Posts: 447
Default Re: Infection

Quote:
Originally Posted by PaulB2005
The first one is the virus which ESS removed.

The second is the copy of it Windows made in System Restore when ESS removed it. You are NOT infected by the second one. It's just lying dormant inthe System Restore folders. As long as you don't restore your PC back to a time when you had th virus you are still clean.
Hello,

Thank you Paul and Funky for your replies.

What does this mean though:
Event occurred during an attempt to access the file by the application: C:\WINDOWS\System32\svchost.exe.

(This was for the C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP927\A0106100.ocx one)

Regards,
Mark.
__________________
ESET NOD32 Antivirus v6
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:15 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums