G
Guest
To start...everytime I run my AVG system scan (Updated) the results shows
File-"ntoskrnl.exe" Result/Infection- " change".
Also... I have through "SearchF&F"- two Lsass.exe. One is
"Lsass.exe/System32". The other is "Lsass.exe/System32dllcache".
Also in a recent "SearchF&F" of Lsass there was "LSASS.EXE-28237D89.pf"
(Whatever a pf file is)
I opened it in Notepad and it was half encripted. The last half was readable.
It was...in part...
"A R D D I S K V O L U M E 8 \ W I N D O W S \ S Y S T E M 3 2 \ S O R T T
B L S . N L S \ D E V I C E \ H A R D D I S K V O L U M E 8 \ W I N D O W S
\ S Y S T E M 3 2 \ A D V A P I 3 2 . D L L \ D E V I C E \ H A R D D I S K
V O L U M E 8 \ W I N D O W S \ S Y S T E M 3 2 \ R P C R T 4 . D L L \ D E
V I C E \ H A R D D I S K V O L U M E 8 \ W I N D O W S \ S Y S T E M 3 2 \ L
S ".....etc.
I moved this to a folder on a back drive. It does not show up in any
Searches on my OS drive,anymore, and has had no efect in restarting the PC
haveing it removed.
Any Ideas?
File-"ntoskrnl.exe" Result/Infection- " change".
Also... I have through "SearchF&F"- two Lsass.exe. One is
"Lsass.exe/System32". The other is "Lsass.exe/System32dllcache".
Also in a recent "SearchF&F" of Lsass there was "LSASS.EXE-28237D89.pf"
(Whatever a pf file is)
I opened it in Notepad and it was half encripted. The last half was readable.
It was...in part...
"A R D D I S K V O L U M E 8 \ W I N D O W S \ S Y S T E M 3 2 \ S O R T T
B L S . N L S \ D E V I C E \ H A R D D I S K V O L U M E 8 \ W I N D O W S
\ S Y S T E M 3 2 \ A D V A P I 3 2 . D L L \ D E V I C E \ H A R D D I S K
V O L U M E 8 \ W I N D O W S \ S Y S T E M 3 2 \ R P C R T 4 . D L L \ D E
V I C E \ H A R D D I S K V O L U M E 8 \ W I N D O W S \ S Y S T E M 3 2 \ L
S ".....etc.
I moved this to a folder on a back drive. It does not show up in any
Searches on my OS drive,anymore, and has had no efect in restarting the PC
haveing it removed.
Any Ideas?