Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 09-05-2011, 04:44 PM   #1
Member (6 bit)
 
squeakyknees's Avatar
 
Join Date: Mar 2006
Location: Ontario,Canada
Posts: 47
Send a message via Skype™ to squeakyknees
trojan in Acer recovery software

I recently bought an Acer 5250 BZ479 laptop I immediately made the recovery discs and installed Security Essentials (The McAfee trial wouldn't activate)
It acted strangely so I reloaded via the recovery discs. Same results. I installed Spybot and the scan came up clean twice. I finally reloaded it from the recovery partition. This time I tried Panda's free edition from the cloud. It came up with a trojan, Deldir.A It was found in C:\Windows\System32\OEM\CLEANUP.CMD and C:\Windows\System32\OEM\CLEANUP_MLP.CMD I had to manually remove the two files as there doesn't appear to be a fix yet.
Today I saw on Code Wars show that pcs being made in China were being sent here with trojans insertesd in the OEM software. This computer was made in China so be aware of this issue in Acer laptops. I didn't find the trojan anywhere in my desktop which I built myself.

MCP MCDST CompTIA IT Tech
squeakyknees is offline   Reply With Quote
Old 09-05-2011, 07:11 PM   #2
Moderator
Staff
Premium Member
 
jdeb's Avatar
 
Join Date: Nov 2008
Location: Detroit, MI
Posts: 5,223
Create a Microsoft System Sweeper disc from a clean computer. Boot this disc in the infected computer to clean. It is available in 64bit or 32bit, match to your OS.

Microsoft Standalone System Sweeper Beta | Microsoft Connect
jdeb is offline   Reply With Quote
Old 09-05-2011, 09:06 PM   #3
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,189
Are you sure it isn't a legitimate file?
glc is offline   Reply With Quote
Old 09-05-2011, 10:02 PM   #4
Moderator
Staff
Premium Member
 
jdeb's Avatar
 
Join Date: Nov 2008
Location: Detroit, MI
Posts: 5,223
Right. The cleanup cmd is a file used by the manufacture that installed the operating system.

Better to be safe than sorry. I do not think there is an issue. In my opinion, most new laptops act flaky until you get rid of the bloated software and completely remove the trial software. I use decrapifier and CCleaner.
jdeb is offline   Reply With Quote
Old 09-06-2011, 07:54 AM   #5
Member (6 bit)
 
squeakyknees's Avatar
 
Join Date: Mar 2006
Location: Ontario,Canada
Posts: 47
Send a message via Skype™ to squeakyknees
The trojan file discovered was Deldir.A within those files, not the cleanup cmd themselves
squeakyknees is offline   Reply With Quote
Old 09-06-2011, 08:16 AM   #6
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,189
The majorgeeks.com forums say that this is a false detection by Panda.
glc is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 03:12 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1