S
Steve Pope
Hi Folks.
On an XP machine, I mistyped a website URL in Explorer causing
an event caught by Malwarebyte's realtime protection. There
seemed to be no damage, but as a precaution I went through a
brief clean-up process including an immediate power-down and running
"System Restore" with a restore point a few days in the past.
Subsequent to the System Restore, there were certain instabilities,
which I have now cleaned up, and they are mostly explainable as
side effects of the System Restore and/or the abrupt power-down, but
there is one oddity I cannot explain:
I had previously saved a copy of Kaspersky tdsskiller.exe in a directory
(not a standard Windows directory, one of my own directories), and
it is now gone!
Is it possible that a malware would have searched for and deleted
tdsskiller.exe? Well, I know it's technically possible; so my real
question is: are there any reports of any malware actually doing this?
The system seems okay: Windows update and antivirus updates still work,
scans are clean including Avast, Malwarebytes, F-Secure Easyclean
and tdsskiller, I do not see any website redirection, I do not see
wrong IP's in netstat, the hosts file had not been written to.
Any thoughts?
Thanks
Steve
On an XP machine, I mistyped a website URL in Explorer causing
an event caught by Malwarebyte's realtime protection. There
seemed to be no damage, but as a precaution I went through a
brief clean-up process including an immediate power-down and running
"System Restore" with a restore point a few days in the past.
Subsequent to the System Restore, there were certain instabilities,
which I have now cleaned up, and they are mostly explainable as
side effects of the System Restore and/or the abrupt power-down, but
there is one oddity I cannot explain:
I had previously saved a copy of Kaspersky tdsskiller.exe in a directory
(not a standard Windows directory, one of my own directories), and
it is now gone!
Is it possible that a malware would have searched for and deleted
tdsskiller.exe? Well, I know it's technically possible; so my real
question is: are there any reports of any malware actually doing this?
The system seems okay: Windows update and antivirus updates still work,
scans are clean including Avast, Malwarebytes, F-Secure Easyclean
and tdsskiller, I do not see any website redirection, I do not see
wrong IP's in netstat, the hosts file had not been written to.
Any thoughts?
Thanks
Steve