Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 15th, 2012, 08:32 PM
bgoodman4's Avatar
bgoodman4 bgoodman4 is offline
Very Frequent Poster
 
Join Date: Jan 2009
Posts: 2,002
Default Suggestions how to deal with this please

I am not knowledgeable in this area but know enough to know I don't know enough, thats why I am posting this here.

I ran an ESET scan and it did not identify these files as a problem but Zemana AntiMalware did. I asked Zemana to quarantine the first file and delete the 2nd. As you can see the delete failed. Any suggestions as to how to proceed now would be most appreciated.

PS: I just re-ran Zemana AntiMalware and both files showed up again so the 1st one, which should have been quarantined, was not. Thats 2 issues to deal with then rather than 1.
Attached Images
 
__________________
"Chance fights ever on the side of the prudent"
...Euripedes

Last edited by bgoodman4 : February 15th, 2012 at 08:41 PM.
  #2  
Old February 16th, 2012, 09:43 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Suggestions how to deal with this please

Well, win32k.sys is protected so it can't delete it. Maybe that's all it means?
__________________
  #3  
Old February 16th, 2012, 09:56 AM
bgoodman4's Avatar
bgoodman4 bgoodman4 is offline
Very Frequent Poster
 
Join Date: Jan 2009
Posts: 2,002
Default Re: Suggestions how to deal with this please

Thank you for your comment. Does this mean I should not worry about this item?
__________________
"Chance fights ever on the side of the prudent"
...Euripedes
  #4  
Old February 16th, 2012, 08:55 PM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,387
Default Re: Suggestions how to deal with this please

I would run a few more scans to determine if its a FP. Try a kaspersky and/or Dr web boot disk. Then after that update MBAM, kaspersky TDSS killer and Emsisoft kit and run them in safe mode. After that run hitman pro once on the desktop. This should find something. If not then you can try GMER and see if you find something odd.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #5  
Old February 16th, 2012, 11:59 PM
bgoodman4's Avatar
bgoodman4 bgoodman4 is offline
Very Frequent Poster
 
Join Date: Jan 2009
Posts: 2,002
Default Re: Suggestions how to deal with this please

Thank you, I will try these.
__________________
"Chance fights ever on the side of the prudent"
...Euripedes
  #6  
Old February 17th, 2012, 01:32 PM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,387
Default Re: Suggestions how to deal with this please

Let us know how things turn out.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #7  
Old February 19th, 2012, 04:42 PM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,127
Default Re: Suggestions how to deal with this please

Quote:
Originally Posted by bgoodman4
I am not knowledgeable in this area but know enough to know I don't know enough, thats why I am posting this here.

I ran an ESET scan and it did not identify these files as a problem but Zemana AntiMalware did. I asked Zemana to quarantine the first file and delete the 2nd. As you can see the delete failed. Any suggestions as to how to proceed now would be most appreciated.

PS: I just re-ran Zemana AntiMalware and both files showed up again so the 1st one, which should have been quarantined, was not. Thats 2 issues to deal with then rather than 1.

Try to choose "replace" instead of "delete". Reboot the system, and run the scan again.
__________________
Linux Mint 13 MATE x64
  #8  
Old February 19th, 2012, 04:50 PM
Escalader's Avatar
Escalader Escalader is offline
Massive Poster
 
Join Date: Dec 2005
Location: Land of the Mooses
Posts: 3,661
Default Re: Suggestions how to deal with this please

Quote:
Originally Posted by bgoodman4
I am not knowledgeable in this area but know enough to know I don't know enough, thats why I am posting this here.

I ran an ESET scan and it did not identify these files as a problem but Zemana AntiMalware did. I asked Zemana to quarantine the first file and delete the 2nd. As you can see the delete failed. Any suggestions as to how to proceed now would be most appreciated.

PS: I just re-ran Zemana AntiMalware and both files showed up again so the 1st one, which should have been quarantined, was not. Thats 2 issues to deal with then rather than 1.

With the cavete that I am not an expert on Zemma I'd bet 99.999999 % it is a false positive on the part of the product.
Eset is solid and did not confirm so forget it and move on with life.
__________________
Escalader
i7 8 GB RAM Notebook, 1TB External Drive
Sandboxie, Nod32, OP FW Pro, KeyScrambler, MVPS HOSTS File
IE 9 Hardened Active X,SmartScreen,Tracking Protection
Paragon Backup and Imaging
  #9  
Old February 21st, 2012, 03:28 PM
bgoodman4's Avatar
bgoodman4 bgoodman4 is offline
Very Frequent Poster
 
Join Date: Jan 2009
Posts: 2,002
Default Re: Suggestions how to deal with this please

I tried a number of suggestions and none found any problem with the files so I will take Escaladers advice and not worry about it. Thanks for all suggestions and comments, most appreciated.
__________________
"Chance fights ever on the side of the prudent"
...Euripedes
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:48 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums