Page 1 of 1

Possible malware infestation

PostPosted: Thu Jan 10, 2013 6:36 pm
by OJY
I just routinely completed a malware scan, and Avast reported the following:

Spoiler
D:\Windows\System32\DriverStore\FileRepository\nete1e32.inf_66d199d8\e1e6032.sys
Severity: high
Status: Threat: Win32:Malware-gen

I tried the 'move to chest' thingy, but I got the following error report:

Spoiler
Error: Virus chest server is not running, RPC communication failed. (2147422219)

Malwarebytes and Spybot - Search & Destroy both reported my PC clean, so I wanted to make sure if it really is malware or a false report by Avast before I accidentally start deleting important stuff. I tried to google it, but couldn't find anything I understood. Anyone here who knows what I'm dealing with?

I know the best advice is to nuke it from orbit and reinstall Windows, but I'm hoping this can be solved a little easier than that (I don't have a backup of my harddisk... Please don't hit me DEFRON!)

Possible malware infestation

PostPosted: Fri Jan 11, 2013 2:35 am
by Emma
Try running the program in Safe Mode, that way the malware may not load and stop the process to remove itself.

Also, try System Restore if the above does not work.

However, no AV or malware scan can be fully done in normal PC operation, Safe Mode is usually required for the nasty ones.

Possible malware infestation

PostPosted: Thu Jan 10, 2013 10:39 pm
by Mariana
Hmm, so it is actually malware? I was hoping it'd turn out to be a false positive. :(

I forgot about using Safe Mode, I'll try that then.

edit: I went googling around a little more and found this:

e1e6032.sys is located in C:/Windows/System32 folder. It is a legitimate Windows file which cannot be seen in Windows explorer. e1e6032.sys is an important executive file in Windows operating system.
http://www.spywareremovaltoolkit.com/exe-errors/e1e6032.sys.html Does that mean I am dealing with a false positive after all? I am confused.

Possible malware infestation

PostPosted: Thu Jan 10, 2013 8:32 pm
by Chrissie Pillinger
Isn't that an intel network file or something? Check to see if it's been signed by intel. If it has it's probably a false positive. But as CCNA says re-boot in safe mode and run the scan again.