:-
helo.Help.Pls.Avast-warning gives …
filename: C:\86.exe
type: Rootkit:hidden processes
HELLP PLS…
http://img40.imageshack.us/img40/357/86help.jpg
get this warning
:-
helo.Help.Pls.Avast-warning gives …
filename: C:\86.exe
type: Rootkit:hidden processes
HELLP PLS…
http://img40.imageshack.us/img40/357/86help.jpg
get this warning
Ok, seems and infected file. Can’t you send it to Chest?
Are you using Windows XP/Vista?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.
If infected files are found, it’s safer to send them to Chest instead of deleting them.
This way you can further analysis them.
@ Tech
Sending to the chest isn’t an option when it is an anti-rootkit detection.
@ mavisakal
Allow the file to be sent to avast for analysis.
Given the file name and location at the very least it is highly suspicious.
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page.
Oops, you’re right. Sorry.
I’ve had the same warning this morning along with 3 other suspicious files. I’m letting avast! take care of it as I write (I’m using my iMac at the moment). I work in media (film and TV) but don’t know a great deal about viruses. How do these things get on there. Sorry if I sound a bit naïve.
Gracias.
C from Possessive Media
There really are too many means of getting infected to post.
This is now an old piece of information and there are other means of getting infected outside of this.
Hello, There have been two days since last post about this virus and avast did not send a word on response about it.
Please, could you just say what do we have to do? Quarantine? Delete? Reboot? Reformat HD? What?
Many other people must have been infected too. We must stop the spreading of this virus.
What do you know about it? What kind of damages to the machine does it make?
I like using AVAST very much, but this has been quite a desception.
Waiting for a response.
Adaylton
Yes, it has and still no response by the original poster either, to my suggestion to upload to virustotal for confirmation one way or the other.
avast has so far done part of the job in giving a warning of a suspicious file a ‘possible’ piece of malware. So both posters should have a) allowed the sample to be sent to avast and as I suggested confirm the detection one way or another, rather than sit around waiting.
So currently it is a suspicion and not a confirmed detection, so any suggested action can’t really be fully given. If you to have this then you too can help and upload the suspect file to virustotal for confirmation.
Information about file 86.exe :
http://www.prevx.com/filenames/110918394309349326-X1/86.EXE.html
http://www.superantispyware.com/malwarefiles/86.EXE.html
Personally I don’t hold a great deal of store in just file names unless they have the same MD5 as the OPs (original poster) 86.exe, even in the two links they don’t both have an MD5, but the reported file size/s also differ which would mean the files are different.
With such a small file name two characters there could be multiple occurrences of a file of this name but not the same file.
Personally, if we don’t get any feedback from the original poster then we shouldn’t proceed further. Considering the plea for help, we have done that as much as we can, now we need input form the OP.
http://www.prevx.com/filenames/110918394309349326-X1/86.EXE.html
:-\
license activation :-\ wants
http://img17.imageshack.us/img17/3483/adsz1bx.jpg
1 C:\86.exe
type: Rootkit:hidden processes
2
Windows Live Communications Platform"
Error
3
Deepfreeze Error …
:-[ :-[ :-[ :-[
4 format p.c.
program ComboFix also recently solved…
I do not know what work ComboFix decreased in.
http://uploaded.to/file/nxue55
______________________________-
Tech
DavidR
Possessive Media
adaylton
CharleyO
Thank … Çok Teşekür. Ederim
Şuna bir sorun yok düzeldi gibi .
ComboFix
program ne işe yaradıgını bilmiyorum sizce bir sakıncası varmı programın.? ComboFix??