Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Symantec suddenly starting to find unnamed trojan horses

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Symantec suddenly starting to find unnamed trojan horses

Unread postby lithiumus » December 21st, 2009, 11:48 am

I went through my Archive folders and simply deleted everything (why take a chance)... I emptied the deleted folders, compacted it and verified that the archive folder size is now 0.

I'm performing another Kaspersky scan now. Below are the entries from the Symantec Risk log. I can't access the "System Volume Information" directories...

Code: Select all
Risk	Action	Filename	Original Location	Logged By	Date
Trojan Horse	Quarantined	GetPopupInfo.exe.e68908.tmp	C:\For Burn\Adobe Illustrator CS3\Program Data\4000002800003i\	Auto-Protect scan	2009-12-09 0:48
Trojan Horse	Quarantined	GetPopupInfo.exe.e68908.tmp	C:\For Burn\Adobe Illustrator CS3\Program Data\4000002800003i\	Auto-Protect scan	2009-12-09 0:47
Trojan Horse	Quarantined	GetPopupInfo.exe.e68908.tmp	C:\For Burn\Adobe Illustrator CS3\Program Data\4000002800003i\	Auto-Protect scan	2009-12-09 0:47
Trojan Horse	Quarantined	GetPopupInfo.exe.e68908.tmp	C:\For Burn\Adobe Illustrator CS3\Program Data\4000002800003i\	Auto-Protect scan	2009-12-09 0:47
Trojan Horse	Quarantined	GetPopupInfo.exe.e68908.tmp	C:\For Burn\Adobe Illustrator CS3\Program Data\4000002800003i\	Auto-Protect scan	2009-12-09 0:47
Trojan Horse	Quarantined	GetPopupInfo.exe.5b4dcc.tmp	C:\For Burn\Adobe Illustrator CS3\Program Data\4000002800003i\	Auto-Protect scan	2009-12-09 0:45
Trojan Horse	Quarantined	A0021314.exe	C:\System Volume Information\_restore{FF4B3B50-83E3-4A5F-B273-B341A337A52E}\RP250\	Auto-Protect scan	2009-12-08 1:12
Trojan Horse	Quarantined	surcodedvd.exe	C:\Program Files\Minnetonka Audio Software\SurCode DVD DTS\	Auto-Protect scan	2009-12-07 20:37
Trojan Horse	Partial	surcodedvd.exe	c:\program files\minnetonka audio software\surcode dvd dts\	Defwatch Scan	2009-12-07 9:30
Trojan Horse	Quarantined	A0019756.exe	C:\System Volume Information\_restore{FF4B3B50-83E3-4A5F-B273-B341A337A52E}\RP229\	Scheduled scan	2009-11-18 1:08
Trojan Horse	Quarantined	A0018122.exe	C:\System Volume Information\_restore{FF4B3B50-83E3-4A5F-B273-B341A337A52E}\RP212\	Scheduled scan	2009-11-04 10:42
Trojan Horse	Quarantined	A0016443.exe	C:\System Volume Information\_restore{FF4B3B50-83E3-4A5F-B273-B341A337A52E}\RP204\	Scheduled scan	2009-10-28 1:10
Trojan Horse	Quarantined	TeamViewer_Setup.exe	C:\Documents and Settings\glau\My Documents\Personal\Software\	Scheduled scan	2009-10-28 1:04
Trojan Horse	Quarantined	TeamViewer_Setup.exe	C:\Documents and Settings\glau\Desktop\Software\Installed\	Scheduled scan	2009-10-28 1:02
Trojan Horse	Quarantined	A0016178.exe	C:\System Volume Information\_restore{FF4B3B50-83E3-4A5F-B273-B341A337A52E}\RP199\	Auto-Protect scan	2009-10-23 0:43
lithiumus
Active Member
 
Posts: 12
Joined: December 8th, 2009, 8:57 am
Advertisement
Register to Remove

Re: Symantec suddenly starting to find unnamed trojan horses

Unread postby deltalima » December 21st, 2009, 6:00 pm

Hi lithiumus,

The "System Volume Information" directories are special hidden system folders where the files and other data required to perform System Restore and cannot be accessed via Windows Explorer.

I will give you some instructions (once we have decided that your system is clean) to clear out this folder to ensure nothing remains in there.

ESET online scannner

  • Please go Here then click on: Image
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  • Select the option YES, I accept the Terms of Use then click on: Image
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Image
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Symantec suddenly starting to find unnamed trojan horses

Unread postby Carolyn » December 25th, 2009, 3:58 pm

Due to a lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
Carolyn
MRU Emeritus
MRU Emeritus
 
Posts: 4701
Joined: April 18th, 2007, 9:36 am
Location: Maine

Previous

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 136 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware