swen virus

Discussion in 'Software' started by ~Pyrate~, Dec 13, 2005.

  1. ~Pyrate~

    ~Pyrate~ MajorGeek

    I just did a scan with avast, and it found the swen virus. While it didn't delete it, I manually deleted the files it was contained in. That is, it was contained in some 3-4 year old outlook express email backups(.dbx file, marked as deleted emails). THIS was the best information I could find about the virus. I've been through that and I did see the following registry keys:
    I don't think there is anything out of the ordinary with those strings, and I'm not confident enough to just delete those. Although, I have seen this virus on my computer in the past in the same folder and avast did delete it before and that is what concerns me.

    I'm not seeing any side effects or symptoms of this virus, as my computer has been running very stable but I would like to know if there is any sure fire way of making sure it is not doing any harm, however slight, to my system.
     
  2. Mada_Milty

    Mada_Milty MajorGeek

    You could always backup your registry before trying any changes.
     
  3. Adrynalyne

    Adrynalyne Guest

    Well, something is not right.

    All of my keys, on a new install of XP, have a data value of "%1" %*.

    Whats up with the extra windir info? That wasn't done by XP.
     
  4. Adrynalyne

    Adrynalyne Guest

    To be more specfic, I'll paste the first one:

    [HKEY_CLASSES_ROOT\batfile\shell\open\command]
    @="\"%1\" %*"
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    As this is a new occurance after an update from Avast to the Defs at of yesterday IIRC, then I would take a second opinion and use an online scan to double check its not a false positive.... some updates to DATs can cause this, you may find that Avast update today or tomorrow again to overcome this if indeed its a false positive.

    But do the online scans, a list of the most popular ones in section 5. http://forums.majorgeeks.com/showthread.php?t=35407
     
  6. ~Pyrate~

    ~Pyrate~ MajorGeek

    Thanks :D I don't have the %windir%, don't know why I didn't notice that.

    I am running the trendmicro scan and it's going to take 1 1/2 hours:eek: So thanks for all your help I can take it from here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds