Keni254
Topic Starter
I ran Kapersky virus scan, just to double check my NAV, and among the items in the report were the following:
C:\System Volume Information\_restore{FC410490-7AE3-4CCB-9F1C-204F35B7DF3D}\RP186\A0094740.exe/WISE0021.BIN Infected: Backdoor.Win32.Ruledor.c
C:\System Volume Information\_restore{FC410490-7AE3-4CCB-9F1C-204F35B7DF3D}\RP186\A0094740.exe/WISE0022.BIN Infected: Trojan-Dropper.Win32.Mudrop.o
C:\System Volume Information\_restore{FC410490-7AE3-4CCB-9F1C-204F35B7DF3D}\RP186\A0094740.exe Infected: Trojan-Dropper.Win32.Mudrop.o
What have I got here? Seems to say that a restore point may have been created with active malware. Am I OK as long as I don't restore, and how can I delete this restore point just to be sure?
Also in the report:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy1.zip/msexreg.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy1.zip Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy18.zip/msexreg.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\eXactAdvertisingBargainsBuddy18.zip Suspicious: Password-protected-EXE
I read this as Spybot has already identified and quarantined the BarginsBuddy threat, but it also appears to be in the Spybot recovery file. Same question as above, how can I delete this?