Symanec Protection Suites

 View Only
Expand all | Collapse all

SAM 10;1;6 trogans keep infecting my System Volume_restore and chrome

  • 1.  SAM 10;1;6 trogans keep infecting my System Volume_restore and chrome

    Posted Jun 25, 2011 09:36 PM

     

    Risk History log any help?? Just installed all new updates for ie8 and ff5.

     

     

     

     

     

     

    Action

     

     

    Count

    Filename

     

     

    Risk Type

    Original Location Computer User Status Current Location Primary Action Secondary Action Logged By Action Description Date
    Cleaned by deletion 1 overlay.xul File C:\Documents and Settings\Deanie\Local Settings\Application Data\{E4F62AE3-555E-4034-9355-B3D1DB7D55FA}\chrome\content\ DMCLAPTOP DMCLAPTOP\Deanie Infected C:\Documents and Settings\Deanie\Local Settings\Application Data\{E4F62AE3-555E-4034-9355-B3D1DB7D55FA}\chrome\content\ Clean security risk Quarantine Auto-Protect scan   6/24/2011 23:28
    Quarantined 2 A0087099.dll File C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1020\ DMCLAPTOP DMCLAPTOP\SYSTEM Infected Quarantine Clean security risk Quarantine Auto-Protect scan The file was quarantined successfully. 6/21/2011 15:33
    Cleaned by deletion 2 overlay.xul File C:\Documents and Settings\Deanie\Local Settings\Application Data\{32F47977-6C8C-449D-9825-7ADA7E80725B}\chrome\content\ DMCLAPTOP DMCLAPTOP\Deanie Infected C:\Documents and Settings\Deanie\Local Settings\Application Data\{32F47977-6C8C-449D-9825-7ADA7E80725B}\chrome\content\ Clean security risk Quarantine Auto-Protect scan   6/18/2011 9:53
    Reboot Processing 2 Unavailable File Unavailable DMCLAPTOP SYSTEM Infected Unavailable Delete Leave alone (log only) Reboot Processing Performing Post-Reboot Risk Processing. 6/16/2011 12:29
    Left alone 1 msfnwobg.dll File C:\WINDOWS\ DMCLAPTOP SYSTEM Left alone C:\WINDOWS\ Clean security risk Quarantine Auto-Protect scan The file was left unchanged. 6/16/2011 12:22
    Quarantined 4 msfnwobg.dll File C:\WINDOWS\ DMCLAPTOP SYSTEM Infected Quarantine Clean security risk Quarantine Auto-Protect scan The file was quarantined successfully. 6/16/2011 12:22
    Reboot Required - Quarantined 4 msfnwobg.dll File C:\WINDOWS\ DMCLAPTOP DMCLAPTOP\SYSTEM Infected Quarantine Reboot Required - Clean security risk Reboot Required - Quarantine Auto-Protect scan The file was quarantined successfully. 6/16/2011 12:20


  • 2.  RE: SAM 10;1;6 trogans keep infecting my System Volume_restore and chrome

    Posted Jun 27, 2011 11:40 AM

    What AV product and Version are you running?

    Try disabling System Restore. Make sure you have the latest Certified or Rapid Release definitions, and then running a ful scan in Safe-mode.

    http://www.symantec.com/business/theme.jsp?themeid=full-system-scan

    If that fails to do the trick, try the PE removal tool.

    Removal Tool