Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

_c00EEE18.dat

Status
Not open for further replies.

depawl

Technical User
Dec 13, 2004
38
Hello:
This computer is a Dell Dimension 4200 running XP Pro SP2, Symantec Antivirus Client. This is located in a small office, I am an IT consultant for them. There are security concerns at this location and I am only given access to computers at certain times of day for limited periods of time. No computers are allowed to be removed from the office, therefore I am unable to run the complete recommended spyware cleaning.
Symantec antivirus detects a Trojan at c:\Windows\System32\_c00EEEE18.dat. Symantec says it can't do anything with it, access is denied. Googling for this file gives no results. Neither does a search on Symantec's website.
I cannot delete, rename, or move this file in normal, Safe mode, nor command prompt.
I was able to delete it using Pocket Killbox.
So far things seem ok, but I'm concerned that removing this one file is too easy and that there must still be some remnants of the infection left.
Any suggestions?
Thanks.
 
I'd get rid of that file first, and see if Symantec finds anything further on the next scan. If it doesn't, then you're making progress.

After that, you could try something like an on-line scan:-


You said, "...I am unable to run the complete recommended spyware cleaning.". I presume this relates to the limited time you're allowed on the machine? I think you need to make the person in charge aware that one of their precious machines has possibly contracted something at best undesirable, and at worst possibly breaching their security! Deep scans take time...

ROGER - G0AOZ.
 
I ran TrendMicro Housecall and it came back clean. Hopefully things are allright now.
thanks for the advise
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top