Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Stubborn Trojan


  • Please log in to reply
4 replies to this topic

#1 qgerms

qgerms

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 17 June 2008 - 03:08 PM

Hello,

I'm having problems ridding myself of some files I suspect might be due to a trojan.

Operating System:

Windows Vista Home Premium
HP Pavilion dv9700 Notebook
Intel Core 2 Duo T7250 @2.0 GHz
3070 MB RAM
32-bit system

Symptoms:

1). I have some files that insist on being shared files despite having Network File and Folder Sharing set to "Not Shared". I found these by clicking "Show me all the files and folders I am sharing" in the Network and Sharing Center within the Windows Vista control panel.

Suspect regenerating files:

C:\Users\tigergerms\AppData\Roaming\nvModes.dat
C:\Users\tigergerms\AppData\Roaming\nvModes.001
C:\Users\tigergerms\AppData\Local\Virtual Store\Program Files\Common Files\Adobe PCD
C:\Users\tigergerms\AppData\Local\Virtual Store\Program Files\Common Files\Adobe\cache
C:\Users\tigergerms\AppData\Local\Virtual Store\Program Files\Common Files\Macrovision Shared\fnp_registrations.xml

I've tried deleting these files & folders but they come back after a few reboots. I think they reappear after I run a program or do some action but have not been able to identify what actions are causing the files to regenerate.

2). After allowing the nvModes.dat and nvModes.001 files to exist (ie. not deleting them and restarting computer a few times), my wireless Internet connection begins to fail. The SSID reverts back to manufacturer settings. The error identified by Windows in the Network and Sharing Center when trying to connect to my wireless router is: "There may be a problem with your Domain Name Server (DNS) configuration. Windows found a problem that cannot be repaired automatically. Contact your Internet service provider or network administrator."

I have been able to re-configure the router back to the settings I had before these anomalies started appearing.

3). Internet Explorer button adds itself to the Quick Launch menu bar.

I use Mozilla for most web browsing. I suspect the nvmodes.dat & nvmodes.001 files appear after signing into MSN Messenger but have not been able to confirm.



I've tried using anti-virus applications (Malware Bytes and PC Tools Spyware Doctor) but they have not caught/identified any problem files, even when run in safe mode. I've also tried re-installing Windows Vista but the same files reappear in the same place after a few restarts. I'm out of ideas.

How does one go about trying to identify trojans and back-door hijacks?

Any help would be appreciated. Thanks.

BC AdBot (Login to Remove)

 


#2 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 22,878 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:12 PM

Posted 17 June 2008 - 06:42 PM

You could try uploading those files at Jotti for analysis.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#3 qgerms

qgerms
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 18 June 2008 - 02:34 AM

Thanks Budapest. However, all 20 scans found nothing. :thumbsup:

#4 qgerms

qgerms
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:12 PM

Posted 27 June 2008 - 04:17 AM

bump

#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 30,797 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:10:12 PM

Posted 27 June 2008 - 06:45 AM

I think they reappear after I run a program or do some action but have not been able to identify what actions are causing the files to regenerate.

Then try to identify the program that is creating them.

These files do no appear to be malicious and your jotti scan seems to confirm that. I am seeing a lot of users having the same files in various logs where they posted for assistance in regards to other issues. What I find in common is that all of them are using Nvidia graphics/drivers. What I have noticed in some of these logs, those files have the same date/timestamp as nvapps.xml and nvudisp.exe which are Nvidia related.

Some files are necessary for a program to perform properly and are recreated if they are deleted.

Edited by quietman7, 27 June 2008 - 06:46 AM.

Microsoft MVP - Consumer Security 2007-2014 MVP.gif

Member of UNITE, Unified Network of Instructors and Trusted Eliminators




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users