Possible malware infestation

Post » Thu Jan 10, 2013 6:36 pm

I just routinely completed a malware scan, and Avast reported the following:

Spoiler
D:\Windows\System32\DriverStore\FileRepository\nete1e32.inf_66d199d8\e1e6032.sys
Severity: high
Status: Threat: Win32:Malware-gen

I tried the 'move to chest' thingy, but I got the following error report:

Spoiler
Error: Virus chest server is not running, RPC communication failed. (2147422219)

Malwarebytes and Spybot - Search & Destroy both reported my PC clean, so I wanted to make sure if it really is malware or a false report by Avast before I accidentally start deleting important stuff. I tried to google it, but couldn't find anything I understood. Anyone here who knows what I'm dealing with?

I know the best advice is to nuke it from orbit and reinstall Windows, but I'm hoping this can be solved a little easier than that (I don't have a backup of my harddisk... Please don't hit me DEFRON!)
User avatar
OJY
 
Posts: 3462
Joined: Wed May 30, 2007 3:11 pm

Post » Fri Jan 11, 2013 2:35 am

Try running the program in Safe Mode, that way the malware may not load and stop the process to remove itself.

Also, try System Restore if the above does not work.

However, no AV or malware scan can be fully done in normal PC operation, Safe Mode is usually required for the nasty ones.
User avatar
Emma
 
Posts: 3287
Joined: Mon Aug 28, 2006 12:51 am

Post » Thu Jan 10, 2013 10:39 pm

Hmm, so it is actually malware? I was hoping it'd turn out to be a false positive. :(

I forgot about using Safe Mode, I'll try that then.

edit: I went googling around a little more and found this:

e1e6032.sys is located in C:/Windows/System32 folder. It is a legitimate Windows file which cannot be seen in Windows explorer. e1e6032.sys is an important executive file in Windows operating system.
http://www.spywareremovaltoolkit.com/exe-errors/e1e6032.sys.html Does that mean I am dealing with a false positive after all? I am confused.
User avatar
Mariana
 
Posts: 3426
Joined: Mon Jun 12, 2006 9:39 pm

Post » Thu Jan 10, 2013 8:32 pm

Isn't that an intel network file or something? Check to see if it's been signed by intel. If it has it's probably a false positive. But as CCNA says re-boot in safe mode and run the scan again.
User avatar
Chrissie Pillinger
 
Posts: 3464
Joined: Fri Jun 16, 2006 3:26 am


Return to Othor Games