Network server antivirus problem.

  1. #11
    jinx123 is offline Full Member

    Re: Network server antivirus problem.

    The person in that building worsning the situation there. he says he just disable symantec auto protect. I tried what u said

    name is: Trojan horse

    path of files:

    infected file: c:\windows\vmm32i.dll
    browser cache:Unknwon redemiationaction operands
    Registry:Hkey_local_machine\software\microsoft\win dows\currentversion\ run: vmm32driver


    here is the report of the scan
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 2:01:19 PM 4/10/2007

    + Scan result:



    C:\Documents and Settings\athif-eccd\Cookies\athif-eccd@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\athif-eccd\Cookies\athif-eccd@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\athif-eccd\Cookies\athif-eccd@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned.
    C:\Documents and Settings\athif-eccd\Cookies\athif-eccd@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\athif-eccd\Cookies\athif-eccd@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.


    ::Report end

    I scanned in normal mode. after restarting it still appears. when I went home I started scan in safe mode. when I came in morning the user of the pc already restarted in normal windows. he said there was no infection found and in normal mode it stopped appearing. but for the second pc I scanned in normal windows only. but after restarting it still shows. When I came next day it was ok no more msg appears. i don't what happened but it dissapears some how after the pc is shutdown and turned on or restarted twice after the scan. the problem is solved but I cudn't understand much
    Attached Images
    • File Type: bmp 1.bmp (855.0 KB, 6 views)
    Last edited by jinx123; 11-04-2007 at 05:51 AM.


  2. #12
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    POtentially, there may re-infection file copies in TEMP files. Have you cleaned out the TEMP files recently:

    Clean out TEMPORARY FILES procedures:
    To clean your temp folder, recycle bin, etc..please download this free tool:

    CCleaner http://www.ccleaner.com/downloadbuilds.asp

    Install Options:
    • Don't install any Toolbars, or other programs, should it ask you!
    • Just uncheck the option of installing the Yahoo toolbar.

    It will put a shortcut on your Desktop.

    Do not run CCleaner until requested later.




    Run CCleaner in SAFE MODE (reboot tapping the F8 key after the beep).

    Select the ‘Options’ BUTTON option (top LEFT), ‘Advanced’ BUTTON, and then UNCHECK the ‘Only delete files in Windows Temp Folders older than 48 hours’ (often, the latest download traffic is likely to be the bearer of bad content).

    Select the ‘Cleaner’ BUTTON option (top LEFT), if not already selected. Use the ’Windows’ TAB up front by default.
    • Uncheck ‘Cookies’ option (advisable)
    • Optionally, Uncheck ‘Recently Typed URLs’ option (potentially still useful)
    • Click the ‘Analyse’ button.
    • Thereafter, click ‘Run Cleaner’ after you have reviewed what it proposes to clean.


    If there are still issues, please post a hijackthis log in case there is an active downloader or other malware involved with this - follow instructions, here:

    http://www.d-a-l.com/help/showthread.php?t=32403

+ Reply to Thread
Page 2 of 2 FirstFirst 1 2