CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Archived Files

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
sheryldotrock

Trooper
Trooper
Premium Member

Joined: Apr 04, 2004
Posts: 29
Location: USA
Premium

PostPosted: Sat Oct 30, 2004 4:54 pm    Post subject: Archived Files
Reply with quote

Hi,
AntiVir keeps telling me that it has made detections in Archived files and that the files will not be deleted or repaired. Is it safe to locate the files and uncheck the "Archive" box? If not, what can I do to rid my computer of these infected files? Thanking you much in advance! I have attached the most recent logfile for help. Thanx again!

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sat Oct 30, 2004 7:10 pm    Post subject:
Reply with quote

Hi sheryldotrock,

You do not need to post the AVPE logfile here. Just copy and paste the paths of those archived files from it so we can see what they are. Do not worry. Those files cannot do anything as long as you do not open them. If they are system files then you will need replacements for them. Do you have your original install CDs?

(I checked one of your past HJT Logs and so I know your OS is Windows ME SP1.)


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
sheryldotrock

Trooper
Trooper
Premium Member

Joined: Apr 04, 2004
Posts: 29
Location: USA
Premium

PostPosted: Thu Nov 04, 2004 12:09 am    Post subject: Archived Files
Reply with quote

Dear Prince_Serendip,

Thank you for your response. I have my original HP Pavillion System Recovery discs and most of the files were in the Windows\Temp folder. Here are the paths:

C:\WINDOWS\TEMP
polmx.cab
ArchiveType: CAB (Microsoft)
--> polmx.exe

C:\WINDOWS\TEMP\THI193D.TMP
twaintec.cab
ArchiveType: CAB (Microsoft)
--> preInsTT.exe
--> polall1m.exe

C:\WINDOWS\TEMP\THI3A95.TMP
twaintec.cab
ArchiveType: CAB (Microsoft)
--> preInsTT.exe
--> polall1m.exe

C:\WINDOWS\TEMP\THI529F.TMP
twaintec.cab
ArchiveType: CAB (Microsoft)
--> preInsTT.exe
--> polall1m.exe

C:\WINDOWS\TEMP\THI1C02.TMP
twaintec.cab
ArchiveType: CAB (Microsoft)
--> preInsTT.exe
--> polall1m.exe

C:\My Documents\downloads
100_72b.exe
--> APPLE\100_32.HQX

C:\Program Files\CoolAgent\6477905\Users\Default\Data.tmp\15a1\1153
infopak.zip

C:\Program Files\ReflexiveArcade\Arcade
Arcade.dat

Thanks again for any help you can offer!

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Thu Nov 04, 2004 4:31 pm    Post subject:
Reply with quote

Hi sheryldotrock,

Judging from the list you will need to get the latest edition of HijackThis and post a log in the HijackThis Forum. Instructions provided below. Post the address of your HJT log here in this thread too.

Here are instructions on how to remove Twain-tec:
http://www.pchell.com/support/twaintec.shtml

Then run HijackThis and post a fresh log in the HijackThis Forum (see below).

HijackThis is a tool we use to detect spywares, adwares, and many other kinds of malicious programs on your computer. It takes an expert or a person with pc security experience (who is on Staff here) to interpret what it finds as it lists the good stuff along with the bad.

Please follow these directions:

From Computer Cops get the Direct-Download of HijackThis. It's zipped.

Save it to your download folder first.
Unzip the download (using a piece of software like Winzip). Create a folder in My Documents and unzip HijackThis into the new folder and run it from there.
Do not run HijackThis from your desktop or a Temp folder as these do not allow HijackThis to save the changes it makes.

Doubleclick on HijackThis.exe from the unzipped archive and press the "Scan" button.

When the scan is finished, the "Scan" button will change into a "Save Log" button. Press this button, and save the log to the same folder as HijackThis.

IMPORTANT NOTE: Most of what HijackThis lists will be harmless or even required, so do NOT fix anything yet.

Go to the Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! Forum and click on "New Topic." Note: This is the only forum where you can post HijackThis Logs at CastleCops!

Copy and paste the contents of your entire HijackThis log into your New Topic post. Please do not post more than one New Topic for your problem. The others will be deleted. If you have been advised to post your HijackThis Log there by a Host/Mod from another forum please post the address for your New Topic here. Thanks.

Open the Log with Wordpad/Notepad (for example), Press Ctrl + A to highlight all, then Press Ctrl + C to copy it. To put it in your post, position the cursor on the page and press Ctrl + V.


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
sheryldotrock

Trooper
Trooper
Premium Member

Joined: Apr 04, 2004
Posts: 29
Location: USA
Premium

PostPosted: Sun Nov 07, 2004 4:16 pm    Post subject: HJT forum thread
Reply with quote

Dear Prince_Serendip,

Here's the thread:

CastleCops Link/p359892-AntiVir_forum_requested_I_post_HJT_log.html#359892

I spotted 3 items that I know should be fixed but all in all, this log looks pretty clean. We'll see.

Thank you again!

Sheryl

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Mon Nov 08, 2004 4:09 pm    Post subject:
Reply with quote

Hi Sheryl,

You are most welcome. I had a look at your post in the HijackThis Forum. You are in very good hands with Marianna helping you. Follow her instructions. Very Happy


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer