E 
		
								
				
				
			
		Evi
Avast found Win32.Trojan Gen on a friend's PC along with the following.
C:/Windows/SYSTEM/mxflrfn.exe/[UPX] unable to scan UPX archive is corrupted
C:/Windows/Temp/morphrec.exe/[UPX] unable to scan UPX archive is corrupted
C:/Windows/All users/./RELATED HTM
C:/Windows/ All users/Application Data/./sb Recovery.ini
C:/Windows/ All users/Application Data/sb Recovery.reg
C:/Windows/ All users/Application Data/00227165.urr
C:/Windows/ All users/Application Data/0201469.urr
C:/Windows/ All users/Application Data/wkrparam.lst
C:/Windows/ All users/Application Data/ 00228384.dat
C:/Windows/ All users/Application Data/ 00246769.dat
C:/Windows/ All users/Application Data/ 0024AD.dat
C:/Windows/ All users/Application Data/files.ini
C:/Windows/ All users/Application Data/002272FA.jpg
C:/Windows/ All users/./mail Stamp Btn.html
C:/Windows/ All users/. /SmileyCentral Btn.html
C:/Windows/ All users/. /Cursor Mania Btn.html
C:/Windows/ All users/. /My stationery Btn.Html
C:/Windows/ All users/. /My SignatureInsert Btn.html
C:/Windows/ All users/. /My Signature Preview Btn.html
C:/Windows/ All users/. /Fun Budl con Btn.html
C:/Windows/ All users/Application Data/00b685B.dat
C:/Windows/ All users/Application Data/not allowed
C:/Windows/ All users/Application Data/not allowed
C:/Windows/ All users/Application Data/SbRecovery.ini
C:/Windows/ All users/Application Data/sbRecovery.reg
We sent everythign to the vault and emptied it. We ran SpyBot and Ad-Aware
and deleted everything they found.
But next time we started, there it was again.
These people had a 2nd hand Pc with lots of rubbish on it but want to avoid
a reformat since they don't have the Windows CD
The PC has Windows ME but we did switch off System Restore before running
the cleanup procedure.
Any ideas?
Evi
				
			C:/Windows/SYSTEM/mxflrfn.exe/[UPX] unable to scan UPX archive is corrupted
C:/Windows/Temp/morphrec.exe/[UPX] unable to scan UPX archive is corrupted
C:/Windows/All users/./RELATED HTM
C:/Windows/ All users/Application Data/./sb Recovery.ini
C:/Windows/ All users/Application Data/sb Recovery.reg
C:/Windows/ All users/Application Data/00227165.urr
C:/Windows/ All users/Application Data/0201469.urr
C:/Windows/ All users/Application Data/wkrparam.lst
C:/Windows/ All users/Application Data/ 00228384.dat
C:/Windows/ All users/Application Data/ 00246769.dat
C:/Windows/ All users/Application Data/ 0024AD.dat
C:/Windows/ All users/Application Data/files.ini
C:/Windows/ All users/Application Data/002272FA.jpg
C:/Windows/ All users/./mail Stamp Btn.html
C:/Windows/ All users/. /SmileyCentral Btn.html
C:/Windows/ All users/. /Cursor Mania Btn.html
C:/Windows/ All users/. /My stationery Btn.Html
C:/Windows/ All users/. /My SignatureInsert Btn.html
C:/Windows/ All users/. /My Signature Preview Btn.html
C:/Windows/ All users/. /Fun Budl con Btn.html
C:/Windows/ All users/Application Data/00b685B.dat
C:/Windows/ All users/Application Data/not allowed
C:/Windows/ All users/Application Data/not allowed
C:/Windows/ All users/Application Data/SbRecovery.ini
C:/Windows/ All users/Application Data/sbRecovery.reg
We sent everythign to the vault and emptied it. We ran SpyBot and Ad-Aware
and deleted everything they found.
But next time we started, there it was again.
These people had a 2nd hand Pc with lots of rubbish on it but want to avoid
a reformat since they don't have the Windows CD
The PC has Windows ME but we did switch off System Restore before running
the cleanup procedure.
Any ideas?
Evi
