Vince86
Jul 24 2008, 12:26 AM
Hi, i just recently scanned my computer with AVG Free 8.0 and it found a trojan horse generic10.BHES. But it was listed as a C:\documents and settings\vincent lee\application data\adobe\acrobat\7.0\updater\adberdr709_en_US.exe. I think it may be a false positive? can a normal file be infected? it was cleaned and quarantined but should i post a hijack log as well? I am using windows xp. thanks
if i were to upload it to a website that checks files, do i restore the file from my virus vault? would it be safe? how do i go about restoring it and sending it? thanks!
Budapest
Jul 24 2008, 12:42 AM
It probably is a false positive. If you still have access to the file you can upload it at
Jotti for analysis.
Vince86
Jul 24 2008, 12:59 AM
i cant restore it, when i upload it, it says it 0 bytes.. but this could be that i just updated my acrobat reader to a newer version right after the infection.
Vince86
Jul 24 2008, 02:11 AM
now it detected another trojan same one but in a system volume restore file a0007391.exe, from the looks of it on a search, many people get infected here. I am goign to post a log.
TMacK
Jul 24 2008, 02:32 AM
Now that you have a HJT log posted in the HijackThis Logs and Malware Removal forum, I'm going to close this Topic.
You shouldn't make any changes to your system, while your HJT log is posted, as that could change the results of the posted log, making it difficult to properly clean your system.
At this point, the HJT Team should be the only members that you take advice from, until they have verified your log as clean.
If you have any questions, don't hesitate to send me a PM.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.