PDA

View Full Version : use of download directories



JimBodkins
2009-02-15, 19:24
Hi,

First time poster with several comments.

1) Thanks for the software.
2) Yahoo (commercial account) considers your verification email to be spam.

I recently became infected with some trojan that (via a connection with a malware site I suspect) is making my life miserable. I am currently scanning with SSnD 1.6. I didnt this and the system was reported as clean. I rebooted and rescanned with the same results. I then added my entire drive as a download directory (1TB with about 600 megs in use) and rescanned. Two comments.

1) It so far has found seven additional issues Nurech, Smitfraud-C, Virtumonde, FakeAlert-CC, Microsoft.Windows.System, Microsoft.WindowsSecurityCenter.RegisteryTools, Win32.Agent.pz. None of which were found as a result of the 'clean' scan. Which makes a degree of sense.

2) The scan is entering its third day.

What am I to make of the new discoveries? Are they just infected files that may not ever be run? And why is the scan taking so long? Can I make it faster? It is currently reporting 371000/386000 (rough numbers).

Should I cancel the scan and fix the problems found then reboot into safe mode and rescan in some different way?

I have that system (Windows XP with latest SP's) disconnected from the internet. I just ended teatimer, pestpatrol and antivir (none of which caught the infection :( ). I didnt realize this was the preferred configuration during a scan. I am working from an opensuse box used for work (programming).

Thanks again.
Jim

JimBodkins
2009-02-15, 19:52
Sorry, it wouldnt let me edit my post so I am adding some info.

As a note, I did complete scans with pestpatrol, antivir and adaware. None of them took over ~9 hours as I recall.

md usa spybot fan
2009-02-15, 20:32
JimBodkins:

The Spybot's » Advance mode » Settings » Directory feature is only intended to scan a directory (folder) were you store download programs. It is not intended to scan an entire drive. In addition, although I can't find the reference right now, I believe that it has been noted that the Directory feature can produce false positives if you use it to scan entire drives.

JimBodkins
2009-02-15, 21:09
JimBodkins:

The Spybot's » Advance mode » Settings » Directory feature is only intended to scan a directory (folder) were you store download programs. It is not intended to scan an entire drive. In addition, although I can't find the reference right now, I believe that it has been noted that the Directory feature can produce false positives if you use it to scan entire drives.

Then I have a question - how do I scan an entire drive?

Thanks for the reply.

drragostea
2009-02-15, 21:49
Then I have a question - how do I scan an entire drive?
You don't with Spybot-Search&Destroy because it is going to take forever. The single file scanning option (you used it to scan your drives correct?) is meant for single files, not whole drives.

JimBodkins
2009-02-15, 21:51
You don't with Spybot-Search&Destroy because it is going to take forever. The single file scanning option (you used it to scan your drives correct?) is meant for single files, not whole drives.

I see. Thanks for the good info. What would you recommend for entire drive scans. I ask as I respect your opinion.

Thanks again

drragostea
2009-02-15, 23:50
Jim, I'm not saying you can't it's just that you shouldn't because the scanner (single file) can be misunderstood sometimes and used as a scanner for a large drive.

What I would recommend is a anti-virus product or anti-spyware product that does the job. What makes Spybot stand out (unique) is that it does not perform single-file scanning of each file in the whole system because that'll take too long. Spybot scans common places where malware may hide and 'anchor' themselves. After that Spybot 'puts the pieces together' to find the malware itself. (I'm not so good as wording this, so bear with me).

JimBodkins
2009-02-16, 01:37
I plan to continue using SSnD. I was interested in opinions of other tools. Antivir missed all this stuff for example.

Thanks again.

drragostea
2009-02-16, 03:53
Antivir missed all this stuff for example.
How so?

I was interested in opinions of other tools.
Such as? Spybot-Search&Destroy Advanced Mode also offers a few great tools if you're willing to explore.

md usa spybot fan
2009-02-16, 06:29
JimBodkins:


... Antivir missed all this stuff for example.
Also which version of Avira Antivir?
Avira AntiVir personal
Avira AntiVir Premium