PDA

View Full Version : IRC Trojan casicon.exe and imgurla.exe


dfarino
May 1st, 2006, 03:24 PM
:confused:

This is the message I received this morning:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: IRC Trojan
File: C:\System Volume Information\_restore{A3E26B45-117D-4D9B-A992-CC51C6F255C3}\RP266\A0126353.exe
Location: C:\System Volume Information\_restore{A3E26B45-117D-4D9B-A992-CC51C6F255C3}\RP266
Computer: NUYNA
User: SYSTEM
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Monday, May 01, 2006 12:55:40 AM


This is the final step after having received the blue screen of death..

I went into the bios and booted from an additional hard drive I have installed. I did a Virus Scan and found 2 viruses on the original hard drive which were: casicon.exe and imgurla.exe Norton has since quarantined these viruses. I then went back into the bios and reset it to boot from the original hard drive and now my original hard drive boots up..:thrilled: .... So now i did another virus scan and it came up with the above virus which norton is unable to remove. ????

As i go onto internet explorer and try to open more than one window at a time it gives me an error reading the page cannot be displayed...And i need to reboot frequently... Sometimes 5 or 6 times with one task..extrememly annoying..lol (my compter doesnt boot up to quickly either) I should have looked into this when it first started happening (maybe I wouldnt have gotten the blue screen of death).. LOL

My first hard drive is Windows 2000 professional and my second is Windows XP Professional..

If you can help me with this I would be ever so grateful..

Thanks
D-

Spider
May 2nd, 2006, 05:10 AM
Hi dfarino welcome to CyberTechHelp .

Are you able to boot to Safe Mode (http://space.hostrocket.com/safe.mode/safe.mode.html)?

dfarino
May 2nd, 2006, 12:11 PM
First of all thank you for posting a reply..

I really appreciate it..

Yes I am able to boot in safe mode. I did that last night and did a virus scan it ran for 4-5 hours and it says no viruses..

My printer is no longer available which is no big deal i can just reinstall it..
Everything has changed my second hard drive used to be called F: now its called D:

I dont understand..:

:rotflmao:

Thanks for your help
Doris

Spider
May 2nd, 2006, 01:20 PM
Boot to Safe Mode with Networking (http://space.hostrocket.com/safe.mode/safe.mode.with.networking.html)

I'll assume you boot to the user name "Administrator" for this...

Start
Run...
type cmd hit enter
type cd\ hit enter
type cacls "c:\system volume information" /E /G administrator:F hit enter
leave this command prompt window open

Open a Windows Explorer and go into the "System Volume Information" folder and delete
everything in there. A file or 2 will not delete, this is normal.

When done deleting go back to the command prompt window...
type cacls "c:\system volume information" /E /R administrator hit enter

While still there in "Safe Mode with Networking" go to Trend Housecall (http://www.trendmicro.com/hc_intro/default.asp) and scan the entire computer.

dfarino
May 2nd, 2006, 01:32 PM
Im running Windows 2000 professional on the first hard drive and Windows XP on the second hard drive.

Im not sure if im booting to Administrator or another name to be honest.

Im at work now but when I get home I will do as you suggested..

Thanks again for all your help..

Doris
:thumbsup:

Spider
May 2nd, 2006, 05:55 PM
Im not sure if im booting to Administrator or another name to be honest
If you right-mouse click the Windows 2000 Taskbar and select
Properties
Advanced(tab)
put a check mark on Display Logoff
OK

When you then click the Start(button) you'll see it says just above "Shut Down"
Log Off (the user name)...

For Windows XP you just click the Start(button) and on the top of the main menu (in Blue) is the booted user name.

dfarino
May 2nd, 2006, 11:14 PM
it wont let me log on as administrator
And i couldnt find the "System Volume Information" folder while i was running safe mode with networking

Spider
May 3rd, 2006, 05:55 AM
it wont let me log on as administrator
Explain in more detail please.
couldnt find the "System Volume Information" folder
You can set this in normal Windows but you'll have to set it again in Safe Mode.

Start
Run...
type explorer click OK
in the menu
Tools
Folder Options...
View(tab)
click Show hidden files and folders
uncheck Hide protected operating system files (Recommended)
an alertbox pops up...You have chosen to display protected....etc click Yes
click OK