![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Nov 2008
Posts: 5
OS: win xp
|
Win32/AutoRun.ABH
Hello,
After I have removed autorun.inf using FLASH DISINFECTOR and after I also used MALWAREBYTES' ANTI-MALWARE SCANS I thought I had cleaned my computer completely. But, except yesterday Nov. 11, I keep getting from ESET NOD32 the following: 12/11/2008 5:25:33 pm Real-time file system protection file C:\System Volume Information\_restore{F229C88F-68CE-41E1-A890-F3D9A8BD1714}\RP54\A0020902.com a variant of Win32/AutoRun.ABH worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\System32\svchost.exe. 12/11/2008 4:12:25 pm Real-time file system protection file C:\System Volume Information\_restore{F229C88F-68CE-41E1-A890-F3D9A8BD1714}\RP54\A0020878.com a variant of Win32/AutoRun.ABH worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\System32\svchost.exe. 10/11/2008 11:36:08 pm Real-time file system protection file C:\System Volume Information\_restore{F229C88F-68CE-41E1-A890-F3D9A8BD1714}\RP54\A0019884.com a variant of Win32/AutoRun.ABH worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\System32\svchost.exe. 10/11/2008 10:22:15 pm Real-time file system protection file C:\System Volume Information\_restore{F229C88F-68CE-41E1-A890-F3D9A8BD1714}\RP54\A0019850.com a variant of Win32/AutoRun.ABH worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\System32\svchost.exe. 10/11/2008 9:22:51 pm Real-time file system protection file C:\System Volume Information\_restore{F229C88F-68CE-41E1-A890-F3D9A8BD1714}\RP54\A0018850.com a variant of Win32/AutoRun.ABH worm cleaned by deleting - quarantined NT AUTHORITY\SYSTEM Event occurred on a file modified by the application: C:\WINDOWS\System32\svchost.exe. another MALWAREBYTES scan produces nothing! Please advise I thank you in advance for your kind attention and help Last edited by paul333; 11-12-2008 at 08:07 AM. |
|
|
| Sponsored Links |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 23,234
OS: N/A
|
Re: Win32/AutoRun.ABH
Do this ....
CLEAR & RESET SYSTEM RESTORE'S CACHE - (System Volume Information folder) Go to Start >> Run - type control sysdm.cpl,,4 & press Enter
NOD wont pick it up anymore after you have reset the cache |
|
|
| Thread Tools | |
|
|