Ever since Avira detected that trojan, I have been running all of my different programs nonstop. And every single scan has been coming up clean.
Until Friday. I ran a scan with Superantispyware and along with some cookies, it found this:
Trojan.Agent/Gen-Sirefef
C:\WINDOWS\$HF_MIG$\KB2592799\SP3QFE\AFD.SYS
I could not find out much information on the trojan, but when I brought up the file, it seemed like it was a legitimate Microsoft Windows file from a previous update.
But this is where it gets weird. I always run under a limited Windows account unless it is absolutely necessary to be an administrator. When I ran Superantispyware under my administrator account, the scan came up clean. Went back over to my limited account and was once again giving the same detection. Tried again with the administrator account. Clean.
Ran another scan on Saturday and the results were:
Trojan.Agent/Gen-Sirefef
C:\WINDOWS\$HF_MIG$\KB2592799\SP3QFE\AFD.SYS
C:\WINDOWS\SYSTEM32\DLLCACHE\AFD.SYS
Trojan.Agent/Gen-Orsam
C:\WINDOWS\SYSTEM32\DLLCACHE\NETBT.SYS
Once again, all seem to be legitimate files. Once again, a clean scan under the adminstrator.
Ran another scan later on and was only given one detection:
Trojan.Agent/Gen-Sirefef
C:\WINDOWS\$HF_MIG$\KB2592799\SP3QFE\AFD.SYS
The rest of the weekend, I decided to run a ton of different scans. These were the results:
Avira: clean
Malwarebytes: clean
Spybot: clean
A-2: clean
Blacklight Rootkit Eliminator: clean
TDSSKiller: clean
Eset Online Scanner: clean
Panda Online Scanner: clean
F-Secure Online Scanner: one cookie
Trend Micro Online Scanner: clean
I have no idea what to do. SAS is the only one detecting this trojan and the files seem legitimate, so I don't want to delete them. But I am very uneasy with the detections because I don't know if they are really infected or if they are just false positives. I sent SAS a message about it, but have yet to receive a response. It would be nice if someone could help me the hell out!
Also, I looked more into that trojan Avira had initially found:
[0] Archive type: GZ
--> object
[1] Archive type: MIME
--> Post_Label_1443US.zip
[2] Archive type: ZIP
--> Post_Label.exe
[DETECTION] Is the TR/Dldr.Dofoil.29 Trojan
I think I have a pretty good idea where it came from. Christmas night, I had received an email from DHL telling me I had not been available to pick up a package or something. I knew right off the bat from the subject line that it was a scam, so I didn't open it and immediately deleted it. So how on earth did I get infected if I did not even open it, let alone download anything from it?
ETA: Ran another SAS scan under my limited account after updating the software. Clean.
No comments:
Post a Comment