Is xp - vista.exe a Trojan?

My anti-virus has identified xp - vista.exe as a Trojan, but I can't find information about this file online.

Any ideas would be appreciated.

Thank you, Palcouk and Vinay.

I have now used various malware programs and changed my antivirus software.  I also used the Scanner for Ms.

The suspicious program is no longer there so he was detected and eliminated.

I especially appreciate knowing the Scanner from Ms.   The analysis lasted more than 12 hours, but it detected the virus having by any other program.  It's a little disconcerting that it is not more widely known among users like me.

Thank you.

Cathy

Tags: Windows

Similar Questions

  • Why Microsoft Security Essentials not detect and prevent installation "Vista Anti-Spyware" Trojan?

    I had the ' Vista Anti-Spyware ' Trojan horse to visit a web site. Why Microsoft Security Essentials does not detect the Trojan horse? He diverted Security Essentials and rendered inoperative.

    Hello

    you will need to ask this question about MSE in the Microsoft Security Essentials Forums the link below

    http://answers.Microsoft.com/en-us/protect

    Here's how to remove this Malware

    Read this information

    Vista anti-virus 2011, Vista Total Security 2011, Win 7 Home Security and include some of the names by a rogue new name change randomly to settle on the victim's computer.  When this particular rogue is installed, it will install as a variety of names in different programs, with each having their own graphical user interface according to the version of Windows running on the computer. Whatever the name, however, they are all the same exact program with just a different name and skin on this subject. This rogue goes by many names in different programs, of which I have listed below depending on the version of Windows that is installed on:

    Windows XP rogue names
    Names of Windows Vista Rogue
    Windows 7 fake names
    XP Antivirus Vista anti-virus Win 7 antivirus
    XP Antivirus 2011 Vista anti-virus 2011 Win 7 anti-virus 2011
    XP Anti-Spyware Vista Anti-Spyware Win 7 AntiSpyware
    XP Antispyware 2011 Vista Antispyware 2011 Win 7 antispyware 2011
    XP Home Security Vista Home Security Win 7 Home Security
    XP Security 2011 Home Vista Security 2011 Home Win 7 Security 2011 Home
    XP Total Security Vista Total Security Win 7 Security Total
    XP Security 2011 Total Vista Total Security 2011 Win 7 Security 2011 Total
    XP security Vista security Win 7 Security
    XP security 2011 Vista Security 2011 Win 7 Security 2011
    XP Internet Security Vista Internet Security Win 7 Internet Security
    XP Internet Security 2011 Vista Internet Security 2011 Win 7 Internet Security 2011

    Follow the EXACT below removal instructions

    http://www.bleepingcomputer.com/virus-removal/remove-win-7-Internet-Security-2011

  • MBAM db 1820: F/P Wextract.exe as Trojan.Vundo

    c:\windows\system32\wextract.exe (Win32 Cabinet Self-Extractor, by Microsoft) is to be mistakenly detected as Trojan.Vundo.   do * NOT * remove it.

    I was about to report it, but I see that many others have beaten me to the MBAM forum:

    http://www.Malwarebytes.org/forums/index.php?showtopic=12131&PID=61652&mode=threaded&start=#entry61652

    http://www.Malwarebytes.org/forums/index.php?showtopic=11639

    http://www.Malwarebytes.org/forums/index.php?showtopic=12129

    taken longer than usual... we used to "instant" MBAM patches...

    but it's been fixed with database version 1821

  • Satellite A300 - w c:\windows\system32\rpcnet.dll and rpcnet.exe recognized as Trojans

    Hello

    while I was scene analysis antivirus on the laptop Satellite A300-15 b, my software recognized w c:\windows\system32\rpcnet.dll and rpcnet.exe as Trojans and deleted. These files are essential?
    How can I get back them? If someone of you cannot answer, I'd appreciate any help.

    Hemoth

    What anti-virus software are you using and have you updated to the latest list of detection of virus/trojan?
    To retrieve these files, you can use the windows repair console, which can be entered by pressing the F8 key before the windows operating system starts.
    Will take you to a list where you repair or somehow mode called option.

    If this does not work, you can try using recovery media.

  • A single file in my Adobe Reader file detected as trojan? (AcroRd32Info.exe)

    Hey everybody,

    I have a question malware for you guys. A few days ago I let a scan of viruses/malware/etc on my PC (via a program called ClamWin anti-virus), who detected a file as a Trojan horse. Here is the line from Scan report:

    C:\Program Adobe 8.0\Reader\AcroRd32Info.exe: Win.Trojan.Agent - 629666 FOUND


    So it confuses me a little. As you can imagine, I'm not really versed in this topic; but it is even possible that a file of a large company like Adobe could be seriously infected? I mean, it obviously seems to be part of Adobe Reader. Or this file maybe just sneak into this folder and start claiming that it belongs there? Or is there perhaps another reason why it has been detected as a Trojan horse, perhaps a kind of "misunderstanding"?

    In conclusion, should I worry that there really is a horse of Trojan on my PC? In this case, it would be wiser to reinstall my OS and wipe the entire hard drive?

    Thank you!

    First of all, it is a rather old version of the player you have installed... It is not compatible with any modern operating system. You should consider upgrading to the latest version, XI player.

    If you have installed the application directly from Adobe so you can be certain, it contains no malware and there is a file of this name in the original installation of the drive, but it is always possible that an external application infested it. Or it could be a false positive... Maybe ask your AV software manufacturers, or try using another to check a second time.

  • Vista - Error Code: 80072 (cannot install Windows updates or Defender)

    I have Vista Home Premium version 6.0 (build 6002 SP2)

    Avast antivirus free version running. No anti-malware running. No 3rd party firewall

    I got the bill113.exe virus/Trojan horse which has not been detected by the AVG Antivirus that I was running. I think I removed the bill113, and I delete AVG, downloaded Avast, ran so deleted spybot Search and Destroy. Since then-, I am getting error 80072 0n updated.

    You can sugest a fix/reset?

    Thank you very much

    If the computer is already infected, no anti-virus/anti-spyware application installed or working properly.

    You have a lot more work to do.

    NB: If you had no installed anti-virus application or subscription has expired * when the machine was first infected * and/or your subscription has expired since and/or the machine is not kept fully corrected in Windows Update, don't waste your time with any of the following: Format & reinstall Windows.  A repair install won't help!

    Microsoft PCSafety provides users at home (only) with free assistance in dealing with infections by malicious software such as viruses, adware and spyware (including unwanted software).
    https://support.Microsoft.com/OAS/default.aspx?&PRID=7552&St=1

    Also available via the homepage of Support of consumer safety: https://consumersecuritysupport.microsoft.com/

    Otherwise...

    1. see if you can download/run the MSRT tool manually: http://www.microsoft.com/security/malwareremove/default.mspx

    NB: Run the FULL scan, not analysis FAST!  You may need to download the MSRT on an uninfected machine and then transfer the MRT. EXE to the infected machine and rename it to SCAN. EXE before running it.

    2A. WinXP-online Windows Live Safety Center scanner 'Protection' (only!) in Mode safe mode with networking, if necessary:http://onecare.live.com/site/en-us/center/howsafe.htm

    2B. Vista or Win7-online this scanner instead: http://onecare.live.com/site/en-us/center/whatsnew.htm

    3. now post the logs required in a forum appropriate for support by an expert in the field. DON'T SKIP THIS STEP!

    I can recommend the assistance of experts available in these forums: http://spywarehammer.com/simplemachinesforum/index.php?board=10.0, http://www.spywarewarrior.com/viewforum.php?f=5, http://www.dslreports.com/forum/cleanup, http://www.bluetack.co.uk/forums/index.phpand http://aumha.net/viewforum.php?f=30

    If these procedures look too complex - and there is no shame in admitting this isn't your cup of tea - take the machine to a local, good reputation and stand-alone computer (that is, not BigBoxStoreUSA or Geek Squad) repair facility.

    ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • Firefox.exe suddenly only 2 k (and IE 1 KB) & flagged up as a malware

    January 13 (2015), I was surprised to find my anti-virus (Pure 3.0 at the time) Kaspersky software tracking upward of what follows as a malware (trojan):

    Firefox.exe C:\Program Files\Mozilla Firefox\firefox.exe HOUR: Trojan.WinLNK.StartPage.gena
    Iexplore.exe C:\Program may Explorer\iexplore.exe TIME: Trojan.WinLNK.StartPage.gena
    eBay Sidebar for Sidebar C:\Users\David\Desktop\eBay Firefox.lnk for Firefox.lnk HOUR: Trojan.WinLNK.StartPage.gena

    I followed the instructions to the quarantine and re - start. No problem. After re-booting, I couldn't access Firefox and discovered that he had indeed been quarantined - with IE (which I use rarely) and eBay Sidebar for Firefox (which I have not used for a long time). On the restoration of these, they are still identified as malware. Further investigation revealed that firefox.exe was only 2 KB - and that is only 1 KB.

    Kaspersky was advised to switch to total security, that I did and it has continued to identify the files as malware. Full virus controls, including safe mode, is not revealed. Run a suite of recommended anti-malware programs don't have pick up a limited number of bits and pieces (and I deleted) that Kaspersky has not, although my research on the net pointing everything be the kind of things that produce advertisements on browsers... not something that would erase or rename programs (I don't see bad ads though, perhaps because of my settings in Firefox Kaspersky and NoScript).

    Kaspersky feels firefox.exe has been altered (on 2 k, it is certainly not right) - Although that corrupt is another question. All other files \Mozilla Firefox seem to be there, and I have no problem with other software or files on my PC (just those three). Again the same thing happened to IE at the same time. That is a hard drive failing very little likely indeed - but it makes me suspicious that there was * something * deliberately made that Kaspersky did not pick up. However, it would be unusual for decent antivirus software like Kaspersky miss something. In addition, the same question must occur widely around the same time, because if everyone around the world lost their browsers he would have made the news - not to mention advertising malware that corrupts the two browsers being rather doomed to failure!

    Either way, the desktop shortcuts have been replaced by the Windows icon by default for programs that do not have a shortcut to measure. And by clicking on what was the shortcut of Firefox opens a DOS window, which closes immediately; IE does the same thing but a "16-bit MS-DOS Subsystem" error box appears (these are the days!) with:
    C:\Users\Public\Desktop\Internet client.lnk
    NTVDM CPU has encountered an invalid statement.
    CS: 123f IP:012d OP: 8f 9f af 6th ba choose 'Close' to terminate the application.
    [By clicking on 'Close' or 'ignore' both close BACK - and that's it.] [No virus or something similar is picked up and four anti-malware programs, I am using now show that my system is clean.

    So my questions are:
    (1) any thoughts on what happened?
    (2) I need to get Firefox working again. Can I simply copy firefox.exe from another machine and replace the existing 2 k firefox.exe and everything should be good, as it was before... or it is not as simple as that? (I understand that Firefox keeps preferences, etc., in separate files).

    Thanks in advance for your comments.

    Dave

    Sorry, you had this problem

    It my be possible and work if you replace the firefox.exe problem

    However that could cause problems and the solution would be to download and install Firefox again by an official site, and by using a pure install involving the removal of the existing program files. (Care to leave the files and folders from one Firefox profile. In fact, it would be interesting, as a precaution suspenders belts ; Locate and save first)

    As to what happened, you gave a well-reasoned and intelligent summary, but after the event, it's going to is almost impossible to define. Sometimes the AV brand and/or & false positives especially temporarily if not totally updated.

    Clean reinstall it

    Some Firefox problems can be solved by performing a clean reinstall. This means that you remove Firefox program files, and then reinstall Firefox. Please follow these steps:

    Note: You can print these steps or consult them in another browser.

    1. Download the latest version of Firefox from mozilla.org office (or choose the download for your operating system and language on this page) and save the file to install it on your computer.
    2. Once the download is complete, close all Firefox Windows (or open the Firefox menu

      Click the close button

      ).

    3. Remove the Firefox installation folder, which is located in one of these locations, by default:
      • Windows:

        • C:\Program Files\Mozilla Firefox
        • C:\Program Files (x 86) \Mozilla Firefox
      • Mac: Delete Firefox in the Applications folder.
      • Linux: If you have installed Firefox with the distribution-based package manager, you must use the same way to uninstall: see Install Firefox on Linux. If you have downloaded and installed the binary package from the Firefox download page, simply remove the folder firefox in your home directory.
    4. Now, go ahead and reinstall Firefox:
      1. Double-click on the downloaded Setup file and go through the steps in the installation wizard.
      2. Once the wizard is completed, click to open Firefox directly after clicking the Finish button.

    More information on the resettlement of Firefox can be found here.

    WARNING: Do not use an uninstaller to third parties as part of this process. This could permanently delete your Firefox profile data, including but not limited to, extensions, cache, cookies, bookmarks, personal settings and passwords saved. They can be retrieved easily unless they have been backed up on an external device!

  • I think that Trojan attacted to my pc.

    Ave.exe and avp.exe a Trojan horse? I think that problems on my computer. How do I remove them?

    My Windows XP computer and protect it with antivirus software.

    Lately, I found the changes with the settings on my pc and is also slow.

    Can anyone help?

    Hello

    Read this information about this Malware.

    http://www.prevx.com/filenames/2108630271898590013-X1/Ave.exe.html

    http://www.prevx.com/filenames/2098712039678712637-X1/AVP.exe.html

    Scan of Malware in Safe Mode with network.

    http://www.bleepingcomputer.com/tutorials/how-to-start-Windows-in-safe-mode/#winxo

    Windows XP

    Using the F8 method:

    1. Restart your computer.
    2. When the machine starts first, yet once it will list usually some equipment that is installed on your machine, amount of memory, hard drives installed etc. At this point you should tap the F8 key repeatedly until you are presented with a menu of Advanced Options in Windows XP.
    3. Select the Safe Mode with networking option using the arrow keys.
    4. Then press enter on your keyboard to start safe mode.
    5. Make all the necessary tasks and when finished restart to start in normal mode.

    Once in Safe Mode with network, download and run RKill.

    RKill does NOT remove the malware; It stops the Malware process that gives you a chance to remove it with your security programs.

    http://www.bleepingcomputer.com/download/rkill/

    Then, download, install, update and scan your system with the free version of Malwarebytes AntiMalware in Mode safe mode with networking:

    http://www.Malwarebytes.org/products/malwarebytes_free

    See you soon.

  • I'm having a lot of problems. Several Trojan horses, the program does not, etc.

    I have a "Inline hook ntkrnlpa.exe" rootkit, Trojan Crypt.ASHD (deleted), (deleted) Trojan horse, several more Generic28.BCBO a Trojan horse detected by AVG & quarantined, Windows Media Player opens at random & says now playing hcp_asx, I can't launch TDSSkiller, redirect random link on the internet. Help, please!

    I have a "Inline hook ntkrnlpa.exe" rootkit, Trojan Crypt.ASHD (deleted), (deleted) Trojan horse, several more Generic28.BCBO a Trojan horse detected by AVG & quarantined, Windows Media Player opens at random & says now playing hcp_asx, I can't launch TDSSkiller, redirect random link on the internet. Help, please!

    Get your installation media, product keys, backup, etc. all together.

    Low level formatting (writing zero or zeros) the hard drive.

    Your installation media to restore the system to factory settings.  (Clean install).

    Continue to use your computer - but get best antivirus (eSet NOD32 AntiVirus - I suggest you not the sequel) and an anti-malware application (I suggest MalwareBytes AntiMalware).

    Why this extreme?  In the end - it's what's going to happen anyway if you ever want to be fully confident in this machine again.

  • Vista cannot locate drivers for my new LifeCam

    Original title: problems with the LifeCam VX-800 and Vista

    I have a LifeCam VX-800, he just bought. Plugged in, and Vista is unable to locate the proper drivers. It is http://support.microsoft.com/kb/929087, but when I click on the page it suggests looking for the drivers, there is no drivers for this webacam. Can someone please? Have tried reinstalling the drivers; does not work!

    Is there anywhere else that I can get the drivers, because they are not on this site? And how is this plug and play product?

    Thank you very much

    OK, maybe you can try this - go to this page:

    http://www.Microsoft.com/hardware/en-us/downloads

    and click on "WebCams" and choose LiveCam VX-1000 instead of VX - 800. Select your Vista operating system and try to download and install "LifeCam 3.2 32-bit and 64-bit Windows Vista (exe)".

    Note - before installing the driver, unplug your WebCam and Plug after installation.

    (I'm sorry, I have somehow forgotten your answer)

    LC

  • You want to update to Vista 32 bit OS - need advice. Don't want to make a mistake.

    Update Vista 32 bit operating system. Currently have a problem.   You want to run a 64-bit OS.  Have a HP Pavilion a6430fPC.  Thought Windows 7.  Can I switch from Vista OS 32 bit to Windows 7 64 - bit OS without problem.  If I currently have on my Vista and upgrade Trojan horse, I still have the Trojan horse.  Don't know if it of my problem and do not want to upgrade my problem also.  Thanks for any input.

    Can I switch from Vista OS 32 bit to Windows 7 64 - bit OS without problem.

    You must do a clean install. Upgrade from 32 bit to 64 bit is not supported:

    The upgrade fromWindows Vista to Windows 7

    What happens if I can't choose the upgrade option? Some versions of Windows cannot be upgraded with the installation disc you are trying to use. For example, you cannot move from a 32-bit version of Windows to a 64-bit version , or a higher edition of Windows like Windows Vista Ultimate Edition, upgrade to a lower edition, such as Windows 7 Edition Home Premium. If this is the case, you will need to use the custom during installation option.

    Best regards
    André
    "A programmer is just a tool that converts the caffeine in code" Deputy CLIP - http://www.winvistaside.de/

  • Security updates Microsoft fails to error 80070005

    original title: Microsoft security updates

    32-bit Vista had a Trojan horse. He wouldn't let me go to a logon screen. Ran in Safe Mode and don't have a restored system. I ran the Norton Internet Security and Microsoft Malicious software tool scans for resolve.
    However, there is a red X on the network in the taskbar icon even if I can get online. Also when you try to update Windows I get error 80070005.
    "Windows could not search for new updates. An error occurred when the new updates for your computer. Error (s) found: Code 80070005. Final check of updates: never (not true). "Updates have been installed: 16/08/2011 at 07:49.
    I had every option, including running FIX, reset msconfig.exe even stop and start services.

    Not sure if the red X on the network is connected or not as I can access the internet.

    I really want to get this computer out of my hair and back to the owner. Please someone out there needs to know what I can do to solve this problem.

    Are you 100% the computer is clean?

    Error 80070005

    Error code 0 x 80070005 is also described as ACCESS DENIED (you may not to install updates).

    Please check that you are logged into an account with administrative privileges.

    Please follow these instructions if you encounter this error code during checking or install updates via Windows Udpate.  What follows applies only to Windows Vista.

    1. Download AccessChk (Sysinternals).  This tool allows you to assess the level of access of some users or groups of resources, including files, directories, registry keys, global objects and Windows services.  Here is the link to download the tool: http://technet.microsoft.com/en-us/sysinternals/bb664922.aspx
    2. Save the file on your desktop zip and extract the file:
      -Right-click on the file and select extract all...
      -Click Next when prompted for the Destination.

      Therefore, you should see a folder called AccessChk on your desktop.

    3. Open the folder AccessChk

    4. Hold the SHIFT key and right-click in the window.  Select "open here command prompt.

    5. A command prompt window should open a similar message:
      C:\Users\\Desktop\accesschk >

    6. Type the following command and press ENTER:
      "" AccessChk.exe "nt service TrustedInstaller" s - n k ' hklm\software\Microsoft\Windows\CurrentVersion\Component Based Servicing "> accesskchk.txt
      Tip: You should be able to copy and paste the command into the command prompt.

    7. Close the command prompt window.  Open the Accesschk folder on your desktop (if it has been closed).

    8. Double-click Accesschk.txt (text file), it should open Notepad.

    9. Copy and paste your results with a new question in the forum of Windows Update.  (Make sure that you write 0x80070005 in the subject).

    Reference1

    If this is not enough: -.

    1. If please download the subinacl.msi from the following link and save the patch to installation on the desktop:
       
      http://www.Microsoft.com/downloads/details.aspx?FamilyId=e8ba3e56-d8fe-4A91-93Cf-ed6985e3927b&displaylang=en#AffinityDownloads
      SubInACL (SubInACL.exe)
      SubInACL is a command line tool that allows administrators to get the security information on files, registry keys, and services, and the transfer of information from one user to another, from local or global group to and from a domain to a domain.

    2. Please, go to the desktop and double-click on the downloaded file.

  • Please select the C:\Windows\System32 folder as the Destination folder during installation. Later, we will use this tool to reset the permissions on the current computer settings.

  • Click the "Start" button in the "Search" bar, type: "Notepad" (without the quotes) and press ENTER.

  • Copy the following commands, and then paste them into the opened Notepad window:
     
    off @echo
     
    Subinacl /subkeyreg HKEY_LOCAL_MACHINE/Grant = administrators = f
    Subinacl /subkeyreg HKEY_CURRENT_USER/Grant = administrators = f
    Subinacl /subkeyreg HKEY_CLASSES_ROOT/Grant = administrators = f

  • Subinacl % lecteur_systeme % /subdirectories / Grant = administrators = f
    Subinacl /subkeyreg HKEY_LOCAL_MACHINE/Grant = system = f
    Subinacl /subkeyreg HKEY_CURRENT_USER/Grant = system = f
    Subinacl /subkeyreg HKEY_CLASSES_ROOT/Grant = system = f
    Subinacl % lecteur_systeme % /subdirectories / Grant = system = f
     
    @Echo =========================
    Completed @Echo.
    @Echo =========================
    @pause
  • After you paste the above commands, please close the Notepad window. Choose "Save" when you are prompted to save the file. Type "reset.bat" as the file name and choose "Desktop" in the Panel on the left as the save location.
  • View the desktop and right click the reset.bat file, then choose "Run as Administrator".
  • You will see a window of type BACK treatment.
     
    NOTE: It may take several minutes, please be patient. When it is finished, you will be prompted with the message: "finished, press any key to continue."
  • Reference2

    This problem may be caused by third-party security programs such as firewalls and antivirus software. You can disable or remove to check the issue.

    Notes are answers Microsoft support engineers
    Support for Windows Vista technical and troubleshooting problems
    Microsoft Help and Support

  • Compaq Presario SR1913WM: Win10 install on Compaq Presario SR1913WM default

    No method of installing Windows 10 has worked on my Compaq Presario SR1913WM.

    My first favorite/attempt method was a clean install Win10 32 bit ISO burned to a DVD-R (installation method because the USB ports on the SR1913WM are not recognized by any Win10 [this is why I attach a PS/2 keyboard to install]):

    With installation (aka clean) "Custom", I get the error
    "We have found all the disks. "For a storage driver, click on load a driver.
    but when I then selects a full DVD - R record of all drivers 'Vista' EXE files for the SR1913WM, (which I thought would have been a better choice than the only other option, XP drivers) I get the error message "no device drivers were found. Make sure that the installation media contains the correct drivers, and then click OK. "(If yes or not I check 'Hide drivers that are not compatible with the hardware on this computer.) »).

    (Is there a way to get the real driver INF of the EXE file?  Their execution didn't extract all files [whichI could find, in all cases], and the old trick of "change the zip extension" did not work either.)

    With the installation of "Keep applications and personal files", he told me to run the installation from inside 8.1, however that also results in an error if the DVD-R or popup of Microsoft to upgrade on the Win10 * offered * (I hear it, it's a good sign) in the BONES, specifically, either:
    1. "the drive where Windows is installed is locked. Unlock the drive, and then try again. »
    (If I opt for "Keep my files") or,
    2. "there was a problem of reset your PC."
    (If I opt for "Remove all")

    Any help, * please *?  Or is this PC stuck on 8.1?

    Compaq Presario SR1913WM care

    (I think my option to Win10 free upgrade expires in 21 days.)

    I'm sorry that your recent attempts to install W10 have not succeeded.

    You can't say that you don't give it your best shot!

    You have to do is say ' I wonder if... "You have tried all the tricks in the book.

  • After the startup error message: C:Docume~1\owner\Locals~1\Temp\dwm.exe__how I can fix it.

    I ran Malwarebytes Anti-Malware and the following came and I deleted everything that came.  Then, I get the error that I mentioned:

    Malwarebytes' Anti-Malware 1.46
    www.Malwarebytes.org

    Database version: 4725

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    30/09/2010 21:36:15
    MBAM-log-2010-09-30 (36-21-15) .txt

    Scan type: quick scan
    Objects scanned: 170298
    Time elapsed: 1 hour (s), 32 minute (s), 59 second (s)

    Memory processes infected: 3
    Memory Modules infected: 0
    Registry keys infected: 0
    Registry values infected: 1
    The infected registry data: 1
    Folders infected: 0
    Files infected: 6

    Process memory infected:
    C:\Documents and Data\Microsoft\svchost.exe Data (Trojan.Downloader.Gen)-> unloaded successfully process.
    C:\Documents and Settings\Temp\dwm.exe owner (Trojan.Downloader.Gen)-> unloaded successfully process.
    C:\Documents and Data\Microsoft\Windows\shell.exe Data (Trojan.Shell)-> unloaded successfully process.

    Memory infected:
    (No malicious items detected)

    Infected registry keys:
    (No malicious items detected)

    The registry is infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost (Trojan.Downloader.Gen)-> quarantined and deleted successfully.

    Infected registry data items:
    HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell)-> Bad: (explorer.exe, C:\Documents and Data Data\Microsoft\Windows\shell.exe) good: (Explorer.exe)-> quarantined and deleted successfully.

    Infected files:
    (No malicious items detected)

    Infected files:
    C:\Documents and Data\Microsoft\svchost.exe Data (Trojan.Downloader.Gen)-> quarantined and deleted successfully.
    C:\Documents and Settings\Temp\dwm.exe owner (Trojan.Downloader.Gen)-> quarantined and deleted successfully.
    C:\Documents and Settings\Temp\1EF.exe owner (Trojan.Downloader.Gen)-> quarantined and deleted successfully.
    C:\Documents and Settings\Temp\24D.exe owner (Trojan.Downloader.Gen)-> quarantined and deleted successfully.
    C:\Documents and owner Settings\Temporary Internet Files\Content.IE5\SCGCF3IX\update[1].exe (Spyware.Passwords.XGen)-> quarantined and deleted successfully.
    C:\Documents and Data\Microsoft\Windows\shell.exe Data (Trojan.Shell)-> quarantined and deleted successfully.

    What can I do about it.  I have windows XP, I got this HP pavilion 555e computer 6 years.  I'm still working, but I don't like the error messages.  Please let me know also where I can learn more about the errors of registry and files.

    try to click on start > run > msconfig

    then under the Startup tab, you will find entries that refer to the programs that are set to start automatically when windows starts.

    You can probably find one of the references corresponding to this faulty .exe and you can turn it off.

    by disabling, attempt to launch the inoculated program will stop and the error warning should also.

    DB·´¯'·.. ¸ > DatabaseBen, Retired Professional - Analyst - Database Developer's - accounting - former veteran of the Armed Forces - @Hotmail.com 'share nirvana mann' - dbZen ~ ~ ~ >

  • Suspicious.Cloud.9 identified by Norton

    I responded to notification of habitual available updated on my desk, and after installed update beating Norton Pavilion adobereaderupdatesetup.exe as "suspicious.cloud.9" - why what is happening and how it affect my computer?

    I also had a Norton warning on adobeflashplayerpluginupdatesetup.exe of Trojan.ADH.2 and this SOUNDS SCARY BAD.

    Should I uninstall all of my Adobe products?  I need to be able to access the pdf and need to drive to do it, I don't?

    I'm not very knowledgeable in this area and need help please!

    No, because these updates are fake, created by the infected applications you already have on your computer.

    Trust only updates that you receive from in the applications themselves, or, better yet, you yourself directly downloaded from the Web site of companies that have created these applications (Adobe, Microsoft, Firefox, etc.).

Maybe you are looking for