I have a password locked RAR archive with media files from the internet (if you know what I mean...) and was wondering if it is at all possible that a virus may be laid dormant in there and a virus scanner wouldn't be able to reach it because of its protectiveness.
Can I do some extra scans to see any active malware, rootkits, etc? I never keep my computer up-to-date so are there any programs that allow to upgrade drivers, programs such as java or mouse drivers that are vulnerable?
I still feel uncertain and have detected irremovable registry values as well as internetexplorer temporary files picked up by Sophos Anti-Rootkit :
\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Servers\2453DF02-B063-47F5-B61C-63341A983BB8
\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{FB2952FE-77CF-4BBD-B3EB-6967D3AC5553}
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Cont.IE5\OXUBNI1X\cation=site_below_header;dcopt=st;campaign=;page=category;kw=blinkx;pid=16;sz=728x90, 728x91;;source=site;t=;tile=1;ord=4627831643768924
(It detected 600+ of these, but did not recommend remove, but i did anyways.)
Here's a list of viruses that were detected and in quarantine in my malwarebytes from October 30-31st, 2011:
c:\Users\********\AppData\Local\Temp\thpm164059252196957788.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.
c:\programdata\javatraynotifier.dll (Trojan.SHarpro.PGen) -> Quarantined and deleted successfully.
c:\Users\********\local settings\application data\exploreradmin.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
c:\Users\********\AppData\Local\exploreradmin.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
c:\Users\********\AppData\Local\ATI\atiupdate\atiupdt32.dll (Trojan.SHarpro.PGen) -> Quarantined and deleted successfully.
c:\Users\********\AppData\Local\Temp\thpm4807319687908550185.tmp (Exploit.Drop.3) -> Quarantined and deleted successfully.
c:\programdata\googleservicetray.dll (Trojan.SHarpro.PGen) -> Quarantined and deleted successfully.
c:\Users\********\local settings\application data\tcpipsys32.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
c:\Users\********\AppData\Local\tcpipsys32.dll (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
c:\Users\********\AppData\Local\ArcSoft\arcsoftupdate\arcsoftup.dll (Trojan.SHarpro.PGen) -> Quarantined and deleted successfully.
Memory Modules Infected:
c:\programdata\googleservicetray.dll (Trojan.SHarpro.PGen) -> Delete on reboot.
c:\Users\********\AppData\Local\ArcSoft\arcsoftupdate\arcsoftup.dll (Trojan.SHarpro.PGen) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{107B4FAA-FF1D-48A4-B2C4-72C742183DF8} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{107B4FAA-FF1D-48A4-B2C4-72C742183DF8} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\GoogleServiceTray (Trojan.SHarpro.PGen) -> Value: GoogleServiceTray -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Winamp Update (Trojan.SHarpro.PGen) -> Value: Winamp Update -> Quarantined and deleted successfully.
Memory Modules Infected:
c:\programdata\javatraynotifier.dll (Trojan.SHarpro.PGen) -> Delete on reboot.
c:\Users\********\AppData\Local\ATI\atiupdate\atiupdt32.dll (Trojan.SHarpro.PGen) -> Delete on reboot.
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{107B4FAA-FF1D-48A4-B2C4-72C742183DF8} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{107B4FAA-FF1D-48A4-B2C4-72C742183DF8} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{107B4FAA-FF1D-48A4-B2C4-72C742183DF8} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{107B4FAA-FF1D-48A4-B2C4-72C742183DF8} (Trojan.SHarpro.Gen) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\JavaTrayNotifier (Trojan.SHarpro.PGen) -> Value: JavaTrayNotifier -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Intel Update (Trojan.SHarpro.PGen) -> Value: Intel Update -> Quarantined and deleted successfully.
This post has been edited by BeenInfected: 09 November 2011 - 12:21 PM

Help
This topic is locked

Back to top








