Infected Files NOT Deleted or Quarantined

G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

I need to know why McAfee isn't deleting these infected files. Here is the
log:

3/14/2005 1:00 AM Scan Started NT AUTHORITY\SYSTEM Scan All Fixed Disks
3/14/2005 2:08 AM Infected NT AUTHORITY\SYSTEM
C:\RECYCLER\S-1-5-21-1390067357-1500820517-839522115-1003\Dc374.IE5\MDPERUH0\View-Movie-001[1].exe Adware-DFC (Program) (Removable)
3/14/2005 2:09 AM Infected NT AUTHORITY\SYSTEM C:\System Volume
Information\_restore{080DA6B3-5930-40A7-9BCB-203708CFF7DC}\RP372\A0020780.exe Adware-DFC (Program) (Removable)
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Scan Summary (Regular
Scanning)
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Boot sectors scanned : 1
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Boot sectors infected : 0
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Boot sectors cleaned : 0
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files scanned :
246110
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files infected : 2
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files cleaned : 0
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files deleted : 0
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files moved : 0
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Scan Summary (Memory
Scanning)
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files scanned :
34
3/14/2005 2:18 AM Scan Summary NT AUTHORITY\SYSTEM Files infected : 0
3/14/2005 2:18 AM Scan Complete NT AUTHORITY\SYSTEM Scan All Fixed Disks
 

Malke

Distinguished
Apr 6, 2004
3,000
0
20,780
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

suzbluii wrote:

> I need to know why McAfee isn't deleting these infected files. Here
> is the log:
>
> 3/14/2005 1:00 AM Scan Started NT AUTHORITY\SYSTEM Scan All Fixed
> Disks
> 3/14/2005 2:08 AM Infected NT AUTHORITY\SYSTEM
> C
\RECYCLER\S-1-5-21-1390067357-1500820517-839522115-1003\Dc374.IE5\MDPERUH0\View-Movie-00
[1].exe
> Adware-DFC (Program) (Removable)
> 3/14/2005 2:09 AM Infected NT AUTHORITY\SYSTEM C:\System Volume
>
Information\_restore{080DA6B3-5930-40A7-9BCB-203708CFF7DC}\RP372\A0020780.exe
> Adware-DFC (Program) (Removable)

Because the malware is in a System Restore point. Once you know your
computer is 100% clean, go to Disk Cleanup (Start>Run cleanmgr [enter])
and click on the More Options tab. You'll be able to delete all but the
most recent System Restore point there.

Malke
--
MS MVP - Windows Shell/User
www.elephantboycomputers.com
In Memoriam - MVP Alex Nichol
The world is diminished without him.