Unable To Delete Infected Files

I'm unable to remove bad cookies and a possible virus. No action possible for the cookies. The virus is possible to move to quarantine, but it reappears on the next scans.


I've uploaded a copy of the possible virus at Rapidshare: http://rapidshare.com/files/315259576/CLSTR3.rar.html (password "infected")

Comments

  • Hello Aarrestad,


    The sample that you have sent us did not help us very much. In order to be able to help you please run a Deep System Scan and then provide us the scan log for analysis . Here is what you have to do :


    1. Before running the scan please make sure that you have the latest virus definitions downloaded via the Update module: open BitDefender and click the "Settings" button in the upper right side of the interface; Switch UI to "Novice Mode"; Click "OK"; Choose the "Update Now" task;


    2. After the update process completes successfully you can proceed to running the scan task: select the "Scan Now" task;


    3. When the scan ends, click the "View Log" button at the bottom right of the scan window; A browser window will open displaying the scan report; Save this file on a location of your choice, upload the report on http://www.sendspace.com/ then post here the download link.


    We are looking forward to your reply.


    Thank you.

  • Hello Aarrestad,


    This sittuation requires further investigation. We would like you to go to the next link and run the BDSI and the Gmer tools as described in the article . After you obtain these reports , you will need to upload them here then reply with the download links . My colleagues from the Virus Analysis team will analyze these files and we will contact you back with further instructions after the analysis is complete .


    Thank you .

  • Hello Aarrestad,


    Please try the steps bellow and let us know what happens :


    1. Disable the BitDefender real-time protection and/or any other active security solution(s) that you are using;


    2. Clean up your browser cache;


    3. Clean up your browser cookies;


    4. Enable the BitDefender real-time protection .


    ~ Below you will find complete instructions in terms of how to perform the above actions. ~


    [how to DISABLE THE REAL-TIME PROTECTION on BitDefender 2010]


    In order to disable the real-time protection please open BitDefender, click the "Settings" button in the upper right side of the interface, Switch UI to "Advanced Mode", Click "OK"; Go to "Antivirus" > "Shield" and click on "Real-time protection is enabled", select the time interval that suites your troubleshooting needs and click "OK" (the message will change to "Real-time protection is disabled"). The real-time protection should be enabled after performing the troubleshooting procedure.


    [how to CLEAN UP YOUR BROWSER CACHE]


    Deleting the files can take up to a couple of minutes, depending on the cache size and the system speed; during this time the browser or the operating system might seem blocked.


    - To clear the Microsoft Internet Explorer 7 cache:


    Open "Internet Explorer" > "Tools" menu > "Delete Browsing History..." > "Delete files" button > "OK" button;


    - To clear the Mozilla Firefox cache:


    Open "Firefox" > "Tools" menu > "Clear Private Data..." > select "Cache" checkbox > "Clear Private Data Now" button;


    In case you have another browser please let us know .


    [how to CLEAN UP YOUR BROWSER COOKIES]


    Cookies are files created by websites that store information in your computer; this files could be used in malicious purposes.


    Clearing the web browser cookies differs for each browser:


    - Clearing the cookies Internet Explorer 7:


    Open "Internet Explorer" > "Tools" menu > "Delete Browsing History..." > "Delete cookies..." button > "OK" button;


    - Clearing the cookies in Mozilla Firefox:


    Open "Firefox" > "Tools" menu > "Clear Private Data..." > select "Cookies" checkbox > "Clear Private Data Now" button;


    If the situation persists or you require further assistance please do not hesitate to contact us.


    Thank you.