suspicious file found....

Hi All,

David so should i just go ahead and delete the file now??

Also Coder i have the same problem. I can’t open any of my drives without right clicking it. Now my Firefox has lost all my bookmarks!!
Did you experience the same thing with “suspicious file found…” ??

Avast hasn’t detected and suspicious file since i changed its name.

David i moved it to chest so how come its still in its original location as well. Wouldn’t it all have moved to chest?

And this pointer thing is driving me nuts!

No problems with my pc prior to this. I’ve had this pc for a while now. ???

Anyone out there experiencing the same thing??

Thanks all and much obliged…

Attached is what i get when attempting to open my c:\ drive by double clicking the mouse. I can open it if i right click it and select “open” but not by double clicking.
So strange…

Yes delete it from the original location but not the copy in the user files section of the chest. You should periodically scan this file in the chest and when avast detects it as infected, you can pat yourself on the back for helping improve detections.

Well so far I have answered why the file remains in the original location twice. But for further clarification this is not the same as avast moving an ‘infected’ file to the chest, you are ‘adding,’ copying a file to the chest so you have to deal with what is in the original location, like I said.

It isn’t surprising that avast doesn’t detect it after you renamed it, that was the whole point of renaming it ‘as I said’ any registry entry or other source is looking to run sys.exe and to all intents and purposes it doesn’t exist (because it has been renamed). So it can’t run, if it isn’t running avast won’t see it as a hidden process.

What pointer thing ???

OK it looks like the sys.exe file has hooked itself into the explorer shell or something like that, so that before you open folders it is running, this allows it to gain control, which we have circumvented by removing the file.

Program & Tutorial - Also useful as a diagnostic tool - FileHippo Download - HiJackThis and post the contents of the HJT log file here. - HJT Information HiJackThis Tutorial.

Download and run HJT and post the contents of the log file (cut and paste or attach the log file) into this topic, you may need to split it over two or more posts depending on how large it is.

LOL Bro, I Lost all of my Fixefox bookmars too, all the addons and themes i added to it and my passwords. It Just Crashed With an Error message Run.dll. FTW.
I’m totally confused.

BTW, Kazmania bro i found how to open the Hard Drives, Just search for this file “Autorun.inf” using search option from the Start Menu. And make sure you search the hidden/files and folders.

You will find a copy of Autorun.inf in all of your drives just delete them and restart. Your drives should work normally now.

These are my results from HT…

Let me know what it means to you experts out there.
Update: i deleted the file and performed a system restore to an earlier date. So far my pc is fine apart from my lost bookmarks in Firefox… guys any ideas??


Ensure you have the latest version of JRE (JAVA Runtime Environment) because older versions can be vulnerable to malware. First remove All Older Versions From Add/Remove Programs.

Then get the latest update from here

Or JRE version 6 update 13

I would also suggest a visit to this site, which scans your system for out of date programs that have patches to close vulnerabilities,

There are some that consider Bonjour unnecessary/unwanted, something that gets installed with some Apple programs.

– How To Uninstall or Remove Bonjour mDNSResponder.exe - This is considered a non-essential, not critical component as related to ITunes. - See
How To Uninstall or Remove Bonjour mDNSResponder.exe
Also see for a tool to automate this process so you don’t have to manually remove as in the above link.

Other than that I don’t see anything obvious.

As for firefox bookmarks, I suggest you back them up (Bookmarks, Organise bookmarks, Export), obviously that may not help you right now, but I thought firefox was meant to back them up somewhere. You might consider this add-on, FEBE (Backup your Firefox data), it saves a lot of stuff.