quarantine error

Discussion in 'Returnil releases' started by winwolf, Jul 14, 2011.

Thread Status:
Not open for further replies.
  1. winwolf

    winwolf Registered Member

    Joined:
    Mar 2, 2011
    Posts:
    9
    Hi,

    Returnil AV just ran a scan and found two malicious files, but issued an error when I tried to repair. Does this mean the file is fixed or not? It's still located in the listed directory, c:\WINDOWS\SYSWOW64.


    Date: 12:48:55 PM
    Malware Type: Security risk
    Malware Id: W32/MalwareF.AFFCM
    Detection Accuracy: Exactly identified
    Location:\DEVICE\HARDDISKVOLUME1\WINDOWS\SYSWOW64\PGPSC.DLL
    First accessed by:\DEVICE\HARDDISKVOLUME1\PROGRAM FILES (X86)\RETURNIL\RVS3\RVSMON.EXE
    Detected by:Quick Scan in Standard Mode on 12:48:54 PM started at 12:48:48 PM
    Quarantine Status:Error while moving into Quarantine.
    Quarantine Error:350 (The operation completed successfully. )
    Restore Analysis:Done.
    Restore File:N/A
     
  2. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    Please send us the following reports from the problem computer (support [dash] tech [at] returnil [dot] com):

    RVS 2010:

    * "C:\Windows\rvs3.log"
    * "C:\Windows\rvs3-inst.log"

    RSS 2011:

    The rvs3.log and rvs3.inst.log files in the following folder:

    Win XP: C:\Documents and Settings\all users\application data\returnil\rvs3\log

    Vista/Win7: C:\ProgramData\Returnil\RVS3\log

    All versions:

    * MSINFO32 report: Click START > RUN or Search depending on version of Windows > Type MSINFO32. On the System Information screen click FILE > Export and then save the file where you can find it to attach to your support e-mail.

    Mike
     
  3. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    We have the logs and the lead has been updated. I will reply as soon as I get a reply from them on the possible cause of the issue. Also, check the support reply for an additional question about getting samples of the files detected so the research team can take a look at them as well.

    Thanks
    Mike
     
  4. winwolf

    winwolf Registered Member

    Joined:
    Mar 2, 2011
    Posts:
    9
    I just responded to the additional question. Thanks for the prompt responses!
     
Thread Status:
Not open for further replies.