Hi friends !
I am running McAfee VirusScan Enterprise 8.5i (VSE 8.5i) with Engine version: 5200.2160 and latest DAT version: 5231.0000 as on 15 February 2008. I have installed it with Maximum Protection.
Now when I perform On-Demand Scan my computer, all local drives, registered files, registry, running processes, the antivirus scans them and results that Nothing Found.
Now when I double click / right click /browse C: or D: drive to open them, On-Access Scan Messages Window pops up always. It states this information:
Name: Z5.DLL
In Folder: C:\Documents and Settings\Administrator\Loc
al Settings\Temp
Detected As: PWS-LegMir.gen.k.dll
Detection Type: Trojan
Status: Deleted
Application: C:\0hct8ybw.bat
Now it shows that there was a Trojan PWS-LegMir.gen.k.dll and using the application 0hct8ybw.bat and now it has been deleted. BUT&
When I again close C: and then open it again the same problem comes. Why it pops up again and again when it is deleted.
Then, I went to cmd and then on C: drive, I typed dir /ah to see the hidden files. Except the default hidden files, I found two files : (1) 0hct8ybw.bat and (2) x.com
When I used C:\>del 0hct8ybw.bat and C:\>del x.com then I received the message: Could not find C:\0hct8ybw.bat.
These two files are on D: drive also.
In the registry, these entries are at the following locations:
For C: drive
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
MountPoint
s2 {89607d04-3be5-11d8-a683-8
06d6172696
f}\Shell\A
utoRun\Com
mand
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
MountPoint
s2 {89607d04-3be5-11d8-a683-8
06d6172696
f}\Shell\E
xplore\Com
mand
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
MountPoint
s2 {89607d04-3be5-11d8-a683-8
06d6172696
f}\Shell\O
pen\Comman
d
For D: drive
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
MountPoint
s2\{13d0b8
e6-d99c-11
dc-95a5-80
6d6172696f
}\ShellAut
oRun\Comma
nd
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
MountPoint
s2\{13d0b8
e6-d99c-11
dc-95a5-80
6d6172696f
}\Shell\Ex
plore\Comm
and
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
MountPoint
s2\{13d0b8
e6-d99c-11
dc-95a5-80
6d6172696f
}\Shell\Op
en\Command
Common for C: and D:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\ShellNoRo
om\MuiCach
e
I know that these are the bad entries in Registry. Please tell me what should be the proper entry ?
I also know that every time, I double click C: or D:, the 0hct8ybw.bat batch file runs and On-Access Scan Messages Window Pops up.
So also tell me if somebody knows how to overcome with this problem. If some of you experts are using the same VSE 8.5i, then definitely some of you have faced the same problem.
I am facing this problem in many PCs. Please help me in this regard.
Regards,
Hemant
Start Free Trial