PDA

View Full Version : Is an *.exe in spybot\recovery\nurech3.zip



JD the DJ
2009-05-29, 08:16
OS: Windows XP SP3
Windows Firewall

The PC in question was infected with several viruses.
Used Spybot, MBAM, SuperAntiSpyware and online scans.
However now, in Normal Mode, IE8, Firefox 3 and Google Chrome cannot display webpages. But they can in safe Mode.
But, a program called "Registry Explorer" can browse the web (but with limitations).
I can ping websites using IP address or common name.
Does not matter whether the firewall is on or off.

While trying to figure out how to get the browsers to access the web, I discovered an *.exe file in "C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Nurech3.zip"

Is that supposed to be there? Because the Modified On Date is within the same 5 minutes that other infected files have.

Yodama
2009-05-29, 09:10
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\
is the location where Spybot S&D puts the backups of the files it removes. These backups are password protected so that these files cannot get extracted and executed by mistake.

If normal usage of your web browsers is only possible in Windows safe mode it is very likely that the computer is still not completely cleaned. You can go to our malware removal forums for help or send an email to detections@spybot.info with a reference to this thread and a full Spybot S&D report file.
To create a full report file do a scan, then right click the scan results screen and select to save the full report to your desktop.