BleepingComputer.com: Logs for Windows Defender Virus

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

Logs for Windows Defender Virus Original Post: Windows Defender Virus - or worse?

#31 User is offline   Dinx 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 26-December 11

Posted 21 January 2012 - 11:55 AM

Well that was a DIFFERENT computer, but this one seems pretty hopeless, too at this point. Thanks for trying . . . .

#32 User is offline   Dinx 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 26-December 11

Posted 21 January 2012 - 02:31 PM

I just posted another reply but think I lost it trying to figure out how to attach my file. After your last reply I just shut down the laptop then rebooted it for the heck of it. It came up FINE - well except for the InitFakeav file that keeps popping up in Symantec. The file is located in c:\users\minotti. If I look there, there are no files by that name but there is an O file with two dots over it. Anyway, if you have a clue what is recreating this file that Symantec keeps "partially" fixing, and how I can remove it, please let me know. I tried attaching an export of the Symantec Risk History so you could see, but I was not permitted.

Dinx

#33 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 22 January 2012 - 08:29 AM

If you did not create that folder and these is nothing good in it delete it. c:\users\minotti <- minotti folder only.

#34 User is offline   Dinx 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 26-December 11

Posted 22 January 2012 - 05:27 PM

This c:\minotti folder appears to have been set up during creation of my user account. At the minotti folder level, there are two other folders - Default and Public. The minotti folder has subfolders for Documents, Contacts, etc. The file named O with two dots over it, is at this level. I tried to delete and first got a message about the recycle bin (I had to download and run MS Fix IT to get the Recycle Bin back on my desktop because it had apparently disappeared at some point.) So now when I try to delete, a popup asks for permission and if I give it, it grinds on a bit then asks for permission again. This cycle went on for a while until I gave up and cancelled. I went into properties for that file and it said I could not look at certain things as I was not the owner, and in the owner field it said the owner name was not available. I tried to change ownership to minotti and that appears to "take", but when I go back into properties again it again says I am not the owner. The entire time this was going on, Symantec was busy finding and doing a partial fix on InitFakeav - when I shut down there were probably a list of 15 entries in the Auto-Protect window, with each entry showing a File Count of 3. I'm wondering if this "O" file is some kind of container where Symantec is putting the Initfakeav files??

#35 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 23 January 2012 - 09:36 AM

Quote

I'm wondering if this "O" file is some kind of container where Symantec is putting the Initfakeav files??


I do not think so. Norton would not use one of your profile to store or quarantine files.
==

Quote

This c:\minotti folder appears to have been set up during creation of my user account.

Can you use that User profile to get to that folder/files and delele the O file?

What we are dealing with is a false positive from Symantec but will not go away until this corrupted file is deleted.

One more thing you can try to delete the bad file is boot to save mode and try to delete if from there.

#36 User is offline   Dinx 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 26-December 11

Posted 25 January 2012 - 07:39 AM

I did try deleting the file as user minotti but it would not let me. However, I WAS able to delete it when I booted up in safe mode. I also emptied the recycle bin. When I rebooted, I checked to see if another had appeared but there is nothing there. I am going to run a full scan to see if Symantec finds anything now . . .

#37 User is offline   Dinx 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 26
  • Joined: 26-December 11

Posted 29 January 2012 - 07:53 PM

It has been several days and I see no evidence of a virus. The only weird thing is that most of my disk space is "used" yet I can't account for it. I will look into what I can do to resolve that. I think I am virus free on this computer - thanks very much for all of your help!

Dinx

#38 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 04 February 2012 - 09:19 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users