Jump to content

Recommended Posts

The SymNoNav issue has been around for quite a while, but still gets detected? It is provided by Symantec for removal of their products. The other false positive 'dellater2.exe' was compiled by me and is a modified assembly of a public utility to add file names to the registry for deletion on reboot. Not sure why this is being detected as the downloader trojan. I have my doubts on the others, but I went ahead and removed as they are not needed.

Files Infected:

c:\Users\Public\Project\sms\Sep\SEP11\SymNoNav\esugdlgcontrol.exe (Malware.Gen) -> Not selected for removal.

c:\Users\Public\Project\sms\Sep\SEP11\SymNoNav\ESUGMSI.exe (Malware.Gen) -> Not selected for removal.

c:\Users\Public\Project\sms\Sep\SEP11\SymNoNav\esugregex.exe (Trojan.Dropper) -> Not selected for removal.

c:\Users\Public\scripts\dellater2.exe (Trojan.Downloader) -> Not selected for removal.

c:\Users\Public\us\dellater2.exe (Trojan.Downloader) -> Not selected for removal.

c:\Users\Public\us\antivirus\virus issue 1-2008\dellater2.exe (Trojan.Downloader) -> Not selected for removal.

c:\Users\Public\us\antivirus\virus issue 1-2008\spybotrem\dellater2.exe (Trojan.Downloader) -> Not selected for removal.

c:\Users\Public\us\DS NTWS\I386\INETSRV\KEYGEN.EXE (Riskware.Tool.CK) -> Not selected for removal.

c:\Users\Public\us\Personal\d501pc552 stuff\temp\sav\esugdrop.exe (Malware.Gen) -> Not selected for removal.

c:\program files\avi converter\abdioconverter\myutil.dll (Spyware.Passwords) -> Not selected for removal.

c:\Users\Paul\AppData\Local\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.