Перейти к содержимому


Фото
- - - - -

Suspicious Files In Spider Guard


  • Please log in to reply
10 ответов в этой теме

#1 JJC

JJC

    Newbie

  • Posters
  • 6 Сообщений:

Отправлено 06 Ноябрь 2010 - 22:20

What does it mean when suspicious files are listed and locked in Spider Guard? Should something be done, or does Dr. Web take care of this automatically?

Сообщение было изменено JJC: 06 Ноябрь 2010 - 22:20


#2 sergeyko

sergeyko

    Guru

  • Dr.Web Staff
  • 3 928 Сообщений:

Отправлено 06 Ноябрь 2010 - 22:29

What does it mean when suspicious files are listed and locked in Spider Guard? Should something be done, or does Dr. Web take care of this automatically?

Depends on your settings. Anyway it would be good could to send the file to our virlab https://vms.drweb.com/sendvirus/ to make sure.
Sergey Komarov
R&D www.drweb.com

#3 JJC

JJC

    Newbie

  • Posters
  • 6 Сообщений:

Отправлено 07 Ноябрь 2010 - 00:27

What does it mean when suspicious files are listed and locked in Spider Guard? Should something be done, or does Dr. Web take care of this automatically?

Depends on your settings. Anyway it would be good could to send the file to our virlab https://vms.drweb.com/sendvirus/ to make sure.


I have 11 suspicious files currently listed in Spider Guard, and they are all locked. I don't see how to look up these files or send them to you. Is this info available through the logs?

#4 drumut

drumut

    Member

  • Members
  • 325 Сообщений:

Отправлено 07 Ноябрь 2010 - 01:28

I have 11 suspicious files currently listed in Spider Guard, and they are all locked.


Because they are quarantined by dr.web.

I don't see how to look up these files or send them to you. Is this info available through the logs?



Go to spider guard settings and choose actions, under this option you would see what to do with suspicious files. You need to choose ignore in drop down menu temporarily. Then these files would be available to you.

Another option to be sure about these files is sending them to virustotal and post scanning results link here. There is a tutorial here how to do this.
OS : Debian Sid , all i have all i need!

#5 JJC

JJC

    Newbie

  • Posters
  • 6 Сообщений:

Отправлено 07 Ноябрь 2010 - 20:16

After I restarted my computer the suspicious files are no longer listed. I thought they would show up in quarantine, but they did not.

Will these start showing up again during routine operation of Spider Guard?

#6 drumut

drumut

    Member

  • Members
  • 325 Сообщений:

Отправлено 07 Ноябрь 2010 - 20:46

Please see quotes below.

Quarantine displays objects which can accessed by your user account.

To view hidden objects, open the Dr.Web installation folder and run the dwqrui.exe file under a more privileged account, or run Dr.Web under an administrative account.


Also do you use any other security softwares on your computer?

Сообщение было изменено drumut: 07 Ноябрь 2010 - 20:46

OS : Debian Sid , all i have all i need!

#7 JJC

JJC

    Newbie

  • Posters
  • 6 Сообщений:

Отправлено 07 Ноябрь 2010 - 20:52

Also do you use any other security softwares on your computer?


No, I use only Dr. Web. I have disabled Windows Defender. My operating system is Windows Vista 32-bit.

I'll take a look at that folder and see what I can find.

Сообщение было изменено SergM: 08 Ноябрь 2010 - 05:27


#8 JJC

JJC

    Newbie

  • Posters
  • 6 Сообщений:

Отправлено 07 Ноябрь 2010 - 20:59

I checked the folder and reflects what I can see when I go into quarantine. There is one file in quarantine, which has been there for a month or so. I've included an attached file wit the info.

Прикрепленные файлы:

  • Прикрепленный файл  drweb6.JPG   77,73К   33 Скачано раз


#9 drumut

drumut

    Member

  • Members
  • 325 Сообщений:

Отправлено 08 Ноябрь 2010 - 04:15

I recommend you to do a complete scan again. We can't go somewhere from this point. Just do a complete scan then we would talk again about your quarantined files. Because you say there are 11 suspicious files but after directions there is only one. The only way to be sure and to feel comfortable on your side is doing another complete scan.
OS : Debian Sid , all i have all i need!

#10 JJC

JJC

    Newbie

  • Posters
  • 6 Сообщений:

Отправлено 08 Ноябрь 2010 - 05:08

I recommend you to do a complete scan again. We can't go somewhere from this point. Just do a complete scan then we would talk again about your quarantined files. Because you say there are 11 suspicious files but after directions there is only one. The only way to be sure and to feel comfortable on your side is doing another complete scan.



Okay, I'll do a complete scan and report back.

#11 SergM

SergM

    Guru

  • Moderators
  • 9 387 Сообщений:

Отправлено 08 Ноябрь 2010 - 05:39

Look the pic.

Прикрепленные файлы: