• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Please Help With Virus Problem

FireStormGS

[H]ard|Gawd
Joined
Jul 24, 2001
Messages
1,425
I just got back to school and while browsing the internet the other day I noticed a window put up and disappear quickly. I wasn't on a sketchy site at all either, I think I was browsing here or it might have been penny arcade. Shortly after I ran a full scan in NOD32 and it found a few files that it deleted in the windows folder, but it's also finding files that are infected in odd locations. I've got my third full scan running right now 2 days later and it found an infected file in my System Volume Information folder on my secondary hard drive. The only option it gives me when it finds a file is to leave it, all the other options were grayed out. And windows won't let me go into the folder to manually delete the files.

This is one of the files it found, D:\System Volume Information\_restore{98D90B21-681D-4D74-9CF8-DCDA604F6197}\RP52\A0011652.exe »NSIS »switch.exe - a variant of Win32/TrojanDownloader.IstBar trojan

If I cant get into the folder and NOD32 wont delete it, how am I supposed to clean my system? I've also ran adaware to try and catch anything else that might have cropped up. Is there any other programs you guys suggest running?

Right now I think that it might have been my housemates laptop that virused my computer through the network, but theres no way to know for sure. I asked him and he said he hadnt updated his antivirus software in a year. So he's since formated his computer, it needed it anyways.

I have another housemate running a mac but I really don't think it could have come from her.
 
Disable the system restore, that will do the trick. I don't think virus scanners can clean anything that is in the system restore section. I find the system restore useless anyways, viruses like to hide there.
 
Sorry yea, I forgot to mention that I've had system restore turned off since I last formatted. So I don't understand how that folder is even there either.
 
I ran HijckThis, I can't see anything that is out of the ordinary though. It might be worth noting that there were three errors while the scan program started, something about registry modifications.

Code:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CoolMon 2\CM2Alpha.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\APC PowerChute Personal Edition\apcsystray.exe
C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
C:\Program Files\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Ansys Inc\Shared Files\Licensing\intel\ansyslmd.exe
C:\MATLAB701\webserver\bin\win32\matlabserver.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Installs\Downloading\utorrent.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Eset\nod32.exe
C:\Documents and Settings\Alex\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Coolmon2] "C:\Program Files\CoolMon 2\CM2Alpha.exe" "C:\Program Files\CoolMon 2\alex20_light.cml"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: APC UPS Status.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {495DEA80-49C2-4891-94CD-C2016615D16F} (ProductView Control) - http://216.235.87.77/spx/servlet/websearch/pvcadview.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122065307671
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{20A4AF63-D75F-40D0-8062-F2E4607EBA8B}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{20A4AF63-D75F-40D0-8062-F2E4607EBA8B}: NameServer = 192.168.1.1
O18 - Protocol: msnim - 0 - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ANSYS FLEXlm license manager - Macrovision Corporation - C:\PROGRA~1\ANSYSI~1\SHARED~1\LICENS~1\Intel\lmgrd.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: C-DillaCdaC11BA - Unknown owner - C:\WINDOWS\system32\drivers\CDAC11BA.EXE (file missing)
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB701\webserver\bin\win32\matlabserver.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
 
Hello,

Are you certain you disabled System Restore on the second disk volume? Perhaps it was disabled on drive C: but it still monitoring drive D:. If so, that could explain why there are still restore point on the drive. Here is a VBS script you can use to disable the system restore service, which should, in turn, remove all restore points from all disk volumes.

  • strComputer = "."
    Set objWMIService = GetObject("winmgmts:\\" & strComputer & "\root\default")
    Set objItem = objWMIService.Get("SystemRestore")
    errResults = objItem.Disable("")
Copy and paste it into your favorite text editor, save it with a .VBS extension and run it. After it is done, the System Restore tab should disappear from the System Properties (filename: SYSDM.CPL) applet in the Control Panel.

You may need to reboot for the change to take effect.

After you are done, you can re-enable the System Restore service with the following script:

  • strComputer = "."
    Set objWMIService = GetObject("winmgmts:\\" & strComputer & "\root\default")
    Set objItem = objWMIService.Get("SystemRestore")
    errResults = objItem.Enable("")
If the restore point it still present on drive D:, you may wish to contact your anti-virus software vendor's technical support department and see if they can provide assistance in removing the file.

Regards,

Aryeh Goretsky
 
I'm sure it is turned off on both drives, but I ran your script anyways. BTW, I think the space on the third line needs to be removed as it was giving me errors before i did that.

Is it possible for a mac to be infecting my computer through the network? I'm wondering if it is even possible before trying to get the third house mate to check through their computer. I've never used a mac before so wouldn't really know where to begin anyways. Because I'm still getting internet explorer windows popping up every so often as well as tabs appearing in firefox to some winvirus protection program.
 
I think I might have finally removed the virus from the system volume information folder. I booted into safe mode, browsed to the system volume folder > properties > security tab and added my local user account. I then deleted the restore folder because it should have never been there in the first place anyways. And then I removed my user from the security list again. I'm surprised no one was able to mention this, or knew about it. All I got from browsing the internet was to try and run a scan in safe mode, but that didn't work.

Now I get to play the waiting game and see if any more pop ups appear...

Damned viruses... :mad: :mad:
 
Back
Top