Author Topic: SYSTEM file infected  (Read 2800 times)

0 Members and 1 Guest are viewing this topic.

cholmes

  • Guest
SYSTEM file infected
« on: October 15, 2012, 08:13:42 PM »
Hey Guys,

I ran a full system scan the other day and got two hits :(;

C:\System32\config\SYSTEM
C:\System32\config\RegBack\SYSTEM

Both infected with Win32:Agent [tjn]

They both also showed up in a boot time scan.

Since then I have scanned with SuperAnti Spyware, Malware, Windows Malicious Software Removal tool, and even Clam Anti Virus just to be sure, and they all showed the system was clean. As well as sfc.exe to make sure it wasnt corrupt and giving me a hit because of that.

The File is a system file and is used in the environment so obviously i cant just delete it, and I dont know if it is a false positive or not. Any suggestions?

Running Windows 7 Professional x64

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SYSTEM file infected
« Reply #1 on: October 15, 2012, 08:50:19 PM »
Quote
The File is a system file and is used in the environment so obviously i cant just delete it, and I dont know if it is a false positive or not. Any suggestions?
upload to www.virustotal.com and test with 40+ malware scanners......if scanned before, click rescan
post the scan link here for us to see

alternative
jotti.org
metascan-online.com

cholmes

  • Guest
« Last Edit: October 16, 2012, 12:02:01 AM by cholmes »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: SYSTEM file infected
« Reply #3 on: October 15, 2012, 11:39:29 PM »
much easier if you just copy the url to the scan result and post that  ;)

cholmes

  • Guest
Re: SYSTEM file infected
« Reply #4 on: October 16, 2012, 12:02:48 AM »
much easier if you just copy the url to the scan result and post that  ;)

... ya figured that as soon as i hit post... its been modified.

cholmes

  • Guest
Re: SYSTEM file infected
« Reply #5 on: October 17, 2012, 10:36:40 PM »
Any ideas Pondus?

cholmes

  • Guest
Re: SYSTEM file infected
« Reply #6 on: October 20, 2012, 09:13:33 PM »
the fun keeps coming, I ran a scan in safe mode and got nothing. same scan after reboot and i get the same 2 hits

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: SYSTEM file infected
« Reply #7 on: October 20, 2012, 09:19:25 PM »
You can report a possible FP here: http://www.avast.com/contact-form.php?loadStyles
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0