Virus quarantined

C

Claire Brucker

I just had a virus quarantined along with several cookies.
Is that as good as having it removed? Webroot just quarantines things.
 
1

1PW

I just had a virus quarantined along with several cookies.

What is the full and exact name that Webroot calls the virus?
Is that as good as having it removed?

Yes. If it's a false positive, you then have the opportunity to return
the file from where it came.

Webroot just quarantines things.

Exactly what is the full & complete name of the Webroot product in use?

Also, upload the suspected virus file to:

<http://www.virustotal.com/>

After you have received an analysis of the file, please post an
"executive summary" of their report here as a follow-up to your thread.

Pete
 
C

Claire Brucker

The virus was Mal/Behav-116. Quarantined by Webroot AntiVirus with
AntiSpyware
 
N

nass

Claire
If you have share on this machine and you got this through the shares, then
it is best if you run a through scan on this machine.

TROJ_AGENT.WNQ
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.WNQ&VSect=T

Trojan.Tooso.E - Removal
http://www.symantec.com/security_response/writeup.jsp?docid=2005-030411-1006-99&tabid=3

Unexplained computer behaviour may be caused by deceptive software
http://support.microsoft.com/kb/827315

Go through these Cleaning steps:
- First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
install the free trial of Windows Live OneCare
http://onecare.live.com/standard/en-gb/default.htm

http://www.microsoft.com/mscorp/safety/technologies/onecare/default.mspx

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html


- If you still having trouble Download the Hijackthis and send the report to
one of
many
forums for analysis and troubleshooting or you can send it to me on my email
provided at the bottom:
When all else fails, HijackThis v2.0.2
(http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php)

Can you please send me a copy at (e-mail address removed) ,
remove the obvious to email me.

HTH.
nass
 
C

Claire Brucker

I consider the case closed. Webroot quarantined the virus I had and that's
enought for me.

nass said:
Claire
If you have share on this machine and you got this through the shares,
then
it is best if you run a through scan on this machine.

TROJ_AGENT.WNQ
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.WNQ&VSect=T

Trojan.Tooso.E - Removal
http://www.symantec.com/security_response/writeup.jsp?docid=2005-030411-1006-99&tabid=3

Unexplained computer behaviour may be caused by deceptive software
http://support.microsoft.com/kb/827315

Go through these Cleaning steps:
- First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
install the free trial of Windows Live OneCare
http://onecare.live.com/standard/en-gb/default.htm

http://www.microsoft.com/mscorp/safety/technologies/onecare/default.mspx

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html


- If you still having trouble Download the Hijackthis and send the report
to
one of
many
forums for analysis and troubleshooting or you can send it to me on my
email
provided at the bottom:
When all else fails, HijackThis v2.0.2
(http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php)

Can you please send me a copy at (e-mail address removed) ,
remove the obvious to email me.

HTH.
nass
---
http://www.nasstec.co.uk

Claire Brucker said:
The virus was Mal/Behav-116. Quarantined by Webroot AntiVirus with
AntiSpyware
 
N

nass

If you wish, but it doesn't hurt if you scanned using the live onecare
scanner the least to check for any badies!!!
HTH,
nass
---
http://www.nasstec.co.uk



Claire Brucker said:
I consider the case closed. Webroot quarantined the virus I had and that's
enought for me.

nass said:
Claire
If you have share on this machine and you got this through the shares,
then
it is best if you run a through scan on this machine.

TROJ_AGENT.WNQ
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.WNQ&VSect=T

Trojan.Tooso.E - Removal
http://www.symantec.com/security_response/writeup.jsp?docid=2005-030411-1006-99&tabid=3

Unexplained computer behaviour may be caused by deceptive software
http://support.microsoft.com/kb/827315

Go through these Cleaning steps:
- First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
install the free trial of Windows Live OneCare
http://onecare.live.com/standard/en-gb/default.htm

http://www.microsoft.com/mscorp/safety/technologies/onecare/default.mspx

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html


- If you still having trouble Download the Hijackthis and send the report
to
one of
many
forums for analysis and troubleshooting or you can send it to me on my
email
provided at the bottom:
When all else fails, HijackThis v2.0.2
(http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php)

Can you please send me a copy at (e-mail address removed) ,
remove the obvious to email me.

HTH.
nass
---
http://www.nasstec.co.uk

Claire Brucker said:
The virus was Mal/Behav-116. Quarantined by Webroot AntiVirus with
AntiSpyware

On 03/23/2009 09:42 AM, Claire Brucker sent:
I just had a virus quarantined along with several cookies.

What is the full and exact name that Webroot calls the virus?

Is that as good as having it removed?

Yes. If it's a false positive, you then have the opportunity to return
the file from where it came.

Webroot just quarantines things.

Exactly what is the full & complete name of the Webroot product in use?

Also, upload the suspected virus file to:

<http://www.virustotal.com/>

After you have received an analysis of the file, please post an
"executive summary" of their report here as a follow-up to your thread.

Pete
 
1

1PW

I consider the case closed. Webroot quarantined the virus I had and that's
enough for me.

Hello Claire:

The only trouble with your position is that the malware may have
contaminated an otherwise good file that your system really needs.
Then, the correct action would be to not only purge the quarantine, but
also replace the file with a known good clean one.

Pete
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top