Also run hijackthis....

Mark

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of FORC5
Sent: Tuesday, January 02, 2007 3:18 PM
To: The Hardware List
Subject: Re: [H] virus bug, help

good idea, will disconnect from Internet and see if it returns.
fp
thanks

At 12:25 PM 1/2/2007, Steve Tomporowski Poked the stick with:
>Search for Trojans.  I got hit with some scumware once where the
>infection was based on a trojan that keeps downloading the scumware
>when it detects that it's been removed.
>
>Steve
>
>On 1/2/07, FORC5 <[EMAIL PROTECTED]> wrote:
>>Have a customer box with adware.purityscan. It basically is shut down and
blocked and not running but the infected file keeps re appearing and I can
not figure out how. Have checked all the usual suspects in the run and
services and win.ini etc.
>>folder that the AV sw finds is in documents and settings/(user)application
data/dobe~1/nopdb.exe
>>
>>the end of that is not visible under explorer but every time I run a av
scan it shows up and gets quarantined. Symantec says to use the purityscan
unintsller but the AV sw says that is infected and seems ridicules to use a
uninstall routine from the infector. Webroot supposedly removed the
infection it is just this stupid file keeps reappearing according to
symantec corporate. tempted to tell sace to ignore on next boot.
>>
>>other then fdisk, any clues ?
>>FWIW this box came in with a bad HD and it was a pain but I finally got it
to ghost, wish I hadn't :'(
>>fp
>>
>>--
>>Tallyho ! ]:8)
>>Taglines below !
>>--
>>What doesn't destroy me makes me stronger.
>>
>>

-- 
Tallyho ! ]:8)
Taglines below !
--
We will find no ancestor before his time.


-- 
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.5.432 / Virus Database: 268.16.3/614 - Release Date: 1/2/2007
2:58 PM
 

-- 
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.5.432 / Virus Database: 268.16.3/614 - Release Date: 1/2/2007
2:58 PM
 

Reply via email to