Hey Everyone,
Thanks in advance for your help. Basically, the scanner on the Standard Shield found this, which was confirmed with a thorough scan that found 2 additional items.
I snooped around the site to try and figure out what the heck to do. I’ve already run Ad-Aware, Spybot, MBAM, and SAS. SpywareBlaster is up and running. Nothing abnormal was found. I also ran CCleaner.
I made a “Suspect” folder on C:\ and excluded it from the scanner as previously posted. I then opened up the program, clicked on the Chest and highlighted the infected file. I then went to “Extract” and moved it to C:\Suspect, where there’s now a .pdf file in there.
-Was that done correctly? I will send this to the virus website shortly.
-Shall I delete C:\Suspect after I send the file?
I ran a boot scan, which just found the same stuff. Except, that it wouldn’t let me Move, Delete, Repair, or place it in the Chest.
Here’s what’s reported from the Warning.log (I’ve removed my name, if that’s ok):
9/18/2008 8:34:42 PM 1221784482 SYSTEM 868 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\WINDOWS\INSTALLER{27625A79-D272-41EF-844B-6EAC87D4A51E}\ICON3F55B0C912.PDF” file.
9/19/2008 12:55:25 AM 1221800125 NAME REMOVED 5736 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\Program Files\Common Files\Wise Installation Wizard\WIS27625A79D27241EF844B6EAC87D4A51E_8_0_0_754.MSI\Icon.Icon3F55B0C912.pdf” file.
9/19/2008 7:11:10 AM 1221822670 NAME REMOVED 5736 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\System Volume Information_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP32\A0013297.MSI\Icon.Icon3F55B0C912.pdf” file.
9/19/2008 8:06:27 AM 1221825987 NAME REMOVED 5736 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\WINDOWS\Installer\e4bdb4.msi\Icon.Icon3F55B0C912.pdf” file.
Don’t know if this is a false-positive or not.
Again, thanks for your consideration.