BetaONE will rise again!


Reply
  #1  
Old 24th Jan 04, 12:50 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
This was found by an online symantec security check and I swear I cannot find the files on my computer and nav does not detect it. What to do??

D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004950.exe is infected with Trojan Horse
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004951.exe is infected with Trojan Horse
__________________
Reply With Quote
  #2  
Old 24th Jan 04, 12:54 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
Found it in the registry under Search assistant/ACMru. Wtf?
__________________
Reply With Quote
  #3  
Old 24th Jan 04, 01:31 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
Ok fixed the registry but another scan gave me this again:

Virus Status: Infected!
Your computer is infected with at least one known virus or Trojan horse.




Warning! The scan detected a virus that is active in your computer's memory.
The scan ended to prevent further infection.



D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004950.exe is infected with Trojan Horse
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004951.exe is infected with Trojan Horse
__________________
Reply With Quote
  #4  
Old 24th Jan 04, 01:41 AM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Disable system restore on all drivers and restart windows and re-enable system restore.

Problem soloved. That is if the scanner is telling the truth.
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #5  
Old 24th Jan 04, 02:20 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
Scanning again now. Last scan after reboot gave me this before enabling system restore.

Virus Status: Infected!
Your computer is infected with at least one known virus or Trojan horse.

No viruses were detected in memory

D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004950.exe is infected with Trojan Horse
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004951.exe is infected with Trojan Horse
__________________
Reply With Quote
  #6  
Old 24th Jan 04, 02:37 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
I still get the virus warning on the scan again
__________________
Reply With Quote
  #7  
Old 24th Jan 04, 02:46 AM
DoG's Avatar
DoG DoG is offline
Administrator
 
Join Date: Nov 2001
Posts: 2,996
DoG will become famous soon enoughDoG will become famous soon enough
Send a message via ICQ to DoG Send a message via MSN to DoG Send a message via Yahoo to DoG
You will have to delete the infected files manually from this folder:
Code:
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\
Make sure that the options to view hidden and system files is checked in folder options.

If windows says you are not authorised to access those folders then turn off simple file and folder sharing, assign youself access to the folders and then delete the files.
__________________

Reply With Quote
  #8  
Old 24th Jan 04, 02:55 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
So far I cant find the folder. Its like it doesnt exist but I found stuff in the registry about it. This is too wierd and yes hidden files are enabled
__________________
Reply With Quote
  #9  
Old 24th Jan 04, 03:06 AM
SlickVic78's Avatar
SlickVic78 SlickVic78 is offline
Senior Member
 
Join Date: Sep 2001
Location: New York, USA
Posts: 515
SlickVic78 is an unknown quantity at this point
war59312 should be right... The infected file was captured within a snapshot most likely from System Restore... In order for you to removed the virus, you need to turn off System Restore for that drive (D: in your case), then restart the computer. Next turn back on System Restore and then run another virus scan on your system to see if it comes back up. The _Restore is associated with your System Restore snapshots.

James55, you are saying that after turning off System Restore on your D: drive, and then rebooting the system did not remove all of you past Restore Points? that is very interesting... If that is the case, then I would say to do what DoG suggested which is to continue to have System Restore off for your D: drive and then going in and manually remove the Restore Point directory that contains the virus, which is RP56. Once that is done, you should be able to turn back on System Restore for your D: drive.

-SlickVic78
__________________
  • Pentium 4 3.20GHz Processor
  • 1 Gig DDR 400MHz RAM
  • 100 Gig 7200 RPM Western Digital HDD
  • 80 Gig 7200 RPM Western Digital HDD
  • Lite-On LTR-52327S CD-RW Burner
  • Lite-On SOHW-1633S DVD Burner
  • ATI Radeon 9700 Pro
  • Sound Blaster Audigy
  • Microsoft Windows XP Pro SP-2
Reply With Quote
  #10  
Old 24th Jan 04, 04:36 AM
James55's Avatar
James55 James55 is offline
Senior Member
 
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
James55 is on a distinguished road
Still working on it. I did a scan with the recue disk and nothing found. Nav did not find it. Could it be that the online scan was screwed up?
__________________
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
unzipping question? SIRCOOKS Software Support 2 2nd Nov 04 03:00 PM
When posting a question User Needs Software Support 0 1st Nov 04 04:31 AM
For Dell and AMD, a tantalizing question NewsBot NeoWin News 0 26th Oct 04 03:30 PM
XP 64bit question volpe1564 Hardware Support 3 25th Mar 02 04:53 PM
Pentium Processor Question??? mayostudent Hardware Support 5 1st Oct 01 04:56 PM


All times are GMT +1. The time now is 12:55 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.