I would greatly appreciate any help/advice on resolving on the following.
On 28Aug 2009 I used Combofix to add the Recovery Console to the Boot Menu of my Toshiba Satellite Pro M70 laptop, which is running on Win XP Pro SP3.
(if necessary, refer to my previous post of 29Aug2009).
After adding the Recovery Console to the Boot Menu, I then uninstalled Combofix, and deleted all the Combofix entries in the Registry, but left 3 folders that are associated with Combofix in the root directory (Combofix, cmdcons & Qoobox).
Today I ran a full scan of the C: partition with SuperAntiSpyware, and it detected Trojan.Agent/Gen in 2 files:
C:\Windows\PEV.EXE
C:\System Volume Information\-Restore{8CEF57C7-733C-4C48-BEA9-6DA51175C09C}\RP220\A0032428.EXE
So far I have not taken any action using SuperAntiSpyware to quarantine &/or remove the 2 files, because scans with MalawareBytes and my CA Antivirus V8.4 software did not detect the Trojan.Agent/Gen, and therefore I don't know whether the SAS detection is just a false positive.
I did a google search for PEV.EXE, and some of the results suggested that PEV.EXE is associated with Combofix.
I checked the properties of the PEV.EXE file, and in the General tab the info given is:
Type of File: Application
Size: 224 KB (229,376 bytes)
Size on Disk: 224 KB (229,376 bytes)
Created: 28Aug2009, 10:50:22
Modified: 23 Aug 2009, 03:09:13 ???
The Time Created (28/08/09, 10:50:22) of the PEV.EX file is similar to the Times Created of the 3 Combofix-related foldrers:
Combofix - created 28/08/09 at 10:54
cmdcons - created 28/08/09 at 10:52
Qoobox - created 28/08/09 at 10:50
This would suggest that the PEV.EXE file is associated with Combofix. Is this correct ?
If yes, why is it being detected as Trojan.Agent/Gen ?
Can I safely delete it ?
Is the A0032428.EXE file also associated with Combofix ?
Thank you
AlanCB


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top









