What do these mean??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by scully91, Dec 27, 2004.

  1. scully91

    scully91 Private First Class

    I have just gone through the motions of the very interesting and useful thread here http://forums.majorgeeks.com/showthread.php?t=35407 and then towards the end of the text i decided to download www.ravantivirus.com/scan.
    Not surprisingly all the other applications had shown there to be no viruses or spyware but this is what the rav-antivirus showed up.

    C:\ProgramFiles\pup.exe is infected with Trojan.Revop.C
    C:\$Vault$.AVG\00000015.FIL.OLD is infected with Exploit.ADODB.Stream.F
    C:\Windows\Hosts is infected with Trojan.StartPage.IG

    Where have these come from that Adaware and Spybot and a few other missed??? Are they really bad? If they need removing how would i go about it?
    They sound serious to me :)
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ad-Aware & Spybot are not truly virus/trojan scanners (although they do pick some up). They are spyware/adware scanners. Rav is an antivirus scanner.

    - C:\ProgramFiles\pup.exe should be deleteable. You may need to boot into safe mode to delete it.
    - C:\$Vault$.AVG\00000015.FIL.OLD - this seems more like a false positive to me. Seems like RAV is picking up AVG's virus vault. You could just empty your virus vault.
    - For the last item with C:\Windows\Hosts . I would like to see the contents of this file.

    What OS do you have?
     
  3. scully91

    scully91 Private First Class

    I am using XP.
    How do i delete the first one?
    The AVG Vault has been emptied but its still showing it (maybe i need to empty the recylce bin too??
    Third one thats all it says so how do i get the contents??

    2 more have appeared
    C:\Windows\RegSvr.exe infected with Trojan.PWS.Sagic.1.5
    and
    C:\Windows\System.exe suspect Behaves Like: Win32.Av-Killer

    Thanks in advance for your help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said, boot to safe mode and delete the file! Use Windows Explorer (click Start then select Explore).

    Is your system update to date with Windows updates? Is your virus application up to date?


    Make sure you have HijackThis 1.99 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  5. scully91

    scully91 Private First Class

    Right i thin thats pup.exe gone.
     

    Attached Files:

  6. scully91

    scully91 Private First Class

    Yes, everything i possess is right up to date.
     
  7. scully91

    scully91 Private First Class

    Ooops, where has that man gone who was going to read my hijack this log ??? Can anyone else help please?
     
  8. scully91

    scully91 Private First Class

    Sorry but better bring this to the top in case anyone has forgotten to read my hijack this log
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't live here! Remember this is all done for free! We are only here when we can be here.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You HJT log is clean!

    Is the below related to your ISP?
    O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/

    If these two file still exist, delete them from safe mode
    C:\Windows\RegSvr.exe
    C:\Windows\System.exe

    Are you still having problems?
     
  11. scully91

    scully91 Private First Class

    Sorry if i seemed impatient. That wasnt the case at all. Of course your help is greatly appreciated.
    There is no problem with the running of my pc but when it says that i have Trojan horse viruses then surely they need to be removed!!

    I will run bitdefender again but if i get rid of c:\windows\system.exe then it dont wanna open any web pages.
    c:\windows\regsvr says it cant be deleted as the disk is protected or something.
    The AVG one i have got rid of as it was just in the vault and im not sure what to do about the c:\windows\hosts.
    Will run it again now and be back in an hour when its finished and see what it says.
    The Wanadoo one is ok.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't understand your statement
    Why wouldn't you want to open any web pages after deleting system.exe?

    Both system.exe, regsvr.exe, and c:\windows\hosts must be deleted!
    Did you boot in safe mode to delete the files?
    Did you right click on the file and change the file attributes so that it is not a Read Only file (uncheck the box if checked)? Then try deleting it! If that still does not work, you need to take ownership of the file. See the following link which will explain how to do that for folders and for files: http://support.microsoft.com/?kbid=308421

    After taking ownership, try to delete it.

    Note a valid hosts file for Win XP belongs in c:\windows\system32\driver\etc , so the one you have in c:\windows is not needed or valid. That is why I say delete it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds