Virus. Is this file important ?

Discussion in 'malware problems & news' started by SonyaM32, Dec 23, 2004.

Thread Status:
Not open for further replies.
  1. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    My ewido just found an infected file, that says it's uncleanable, and is asking me if I want to delete the whole archive. Here is the name of the file. I will wait till I get an answer before I delete it. Thanx Sonya
    C:\WINDOWS\system32\mac80ex.idf
     
  2. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    there is some info here


    you can go to the file (C:\WINDOWS\system32\mac80ex.idf) in your c drive and open the file and see if either of these files are in there. Don't delete this file (C:\WINDOWS\system32\mac80ex.idf )

    The compressed file adv.exe within C:\WINDOWS\system32\mac80ex.idf is a Adware threat.

    The compressed file bargains.exe within C:\WINDOWS\system32\mac80ex.idf is a Adware threat
     
    Last edited: Dec 23, 2004
  3. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    Ok ill try my best to understand here, so bear with me. If I go to see if either of the 2 files are there, do I delete them ? I still have the pop up asking me if I want to delete the whole archive. Can I just delete it.? As long as it does not hurt my pc in any way ?
     
  4. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    don't delete the whole file, open the file and see if either or both of the other files are in there. If they are there delete them but not the C:\WINDOWS\system32\mac80ex.idf file

    bigc
     
  5. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    Thank you for your help ! Merry xmas ! :D
     
  6. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    Merry christmas to you also and good luck. If you would, let me know if you get them out of the file.

    bigc
     
  7. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    I could not open the file, it was a " open with ", type file. So now it is in quarentine. So I can get it out if needed, I hope. Unless you know how I can open it. Thanx :D :D :D :D :D
     
  8. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    you can open it with notepad
     
  9. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    If either of those files are in the notepad, do I delete them ferom there ?I'm sorry, I just don't know alot about all this :) :)
     
  10. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    highlite them if they are there and then delete, just be careful if you delete something you want to keep from notepad it is gone. After deleting close everything, reboot, and rescan with ewido.
     
  11. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    OK, I am trying to get them to restore from quarentine . I am highlighting the files and then clicking restore, and they will not. This is my first time using the ewido, so I don't hardly know anything about it .
     
  12. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    well since you have the file already in quarantine, just leave it there and use your computer normally and see if everything seems to work alright without the file that is in quarantine. if it does work ok and everything works as it should for a week or so then you can probably delete the quarantined file. But I would give it at least a week to make sure nothing shows up

    bigc

    P.S.
    I don't use ewido so I can't be much help with it.
     
  13. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    OK, THANX so much for your help ! :D
     
  14. Verdann

    Verdann Guest

    Something that I found in the file that helped me find everything in it, is at the end of every path are the letters UT. just did a find on them and found every path in the file, eventually. Got rid of the one's I needed to and no more problems. for now.
     
  15. bajinaido

    bajinaido Guest

    did you delete it in notepad? I see the file in notepad, however it is mixed with a bunch of other nonsense so I'm a little worried about deleting anything.
     
  16. SonyaM32

    SonyaM32 Registered Member

    Joined:
    Dec 23, 2004
    Posts:
    718
    Hi bajinaido, what I ended up doing is deleting the whole thing. I just let the ewido clean the file. I have been ok since. Thanx :D
     
  17. Proverbs 9:10

    Proverbs 9:10 Registered Member

    Joined:
    Jan 20, 2005
    Posts:
    4
    Re: Virus...was having a similar problem...now have others

    Followed the link by bigc73542 to search for specific items. When I searched for exdl.exe for example the notepad found two hits. I went to the hit spots and deleted only the "exdl.exe" (was not in quotes). Should I have deleted the part immediately before it which included ...system32/ reference?

    After completing this task, I saved it. Now, I am currently getting a message from "messenger service". "Message from SYSTEM to USER on 1/20/05." There is a bunch of warning information with a suggestion to get help at www.ErrorFixer.com. Is this a legitimate warning from my computer, perhaps based on what I deleted in notepad? Or, is this an attempt by others to get at my computer?

    Can you please help? o_O I really don't know if I need to follow this link or if I should run fast and furious. Thank you.
     
  18. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    That is one thing I don't do is delete from notepad. I delete from the file or from the registry. sometimes it is a little confusing the way that note pad presents things. besides I can back up the registry before I delete anything from there.

    bigc
     
  19. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    57,802
    Location:
    Texas
  20. Proverbs 9:10

    Proverbs 9:10 Registered Member

    Joined:
    Jan 20, 2005
    Posts:
    4
    Now that I realize it was wise to steer clear, is there anyway to delete this pop up message from ? "messenger service"? If I need to do this in another forum, please let me know. Thank you.
     
  21. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    57,802
    Location:
    Texas
  22. Please,make sure there is nothing in my computer.like a virus
     
  23. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Is this a question or a reply?
     
Loading...
Thread Status:
Not open for further replies.