Virus Chest File Recovery

I performed a virus scan about a week ago and the operation returned about a dozen infected files, which I deposited into the virus chest. The problem is that I immediately removed/erased the files from the chest without thinking to much about it. From skimming the posts here, I don’t think I was supposed to do that. At any rate, my computer has not been functioning properly since the scan. I think that one or more of the infected files that were erased could have been files necessary for proper function of my computer. I have searched for a file recovery option, but have not as yet located it.

Can anyone be of assistance concerning this matter?

Thank you

There is no hard and fast what you should or shouldn’t do, but it doesn’t make sense to move something to the chest and then delete it, you could just as easily cut out the middle man and deleted them right away, not a good decision.

Deletion isn’t really a good first (or early) option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate.

There is no rush to delete anything from the chest, a protected area where it can do no harm. Anything that you send to the chest you should leave there for a few weeks. If after that time you have suffered no adverse effects from moving these to the chest, scan them again (inside the chest) and if they are still detected as viruses, delete them. Having deleted them from the chest they are gone/history they are no more.

The fact that your system doesn’t appear to be running well isn’t a 100% indication you deleted something important, you could possibly have hidden or undetected malware.

Only by telling us what was detected before can we even hazard a guess if you might have deleted something important.

What is the malware name, the infected file name, where was it found e.g. (malware name, C:\windows\system32\infected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections. C:\Program Files\Alwil Software\Avast4\ashLogV.exe

You may find it easier to go to the source file, open it with notepad and copy and paste the entries for the infected files (nothing else, there will be other entries) into your next post.

9/10/2006 3:47:41 PM Brian 1544 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: E:\setup.exe (E:\setup.exe) returning error, 0000A474.
6/6/2007 1:40:36 PM SYSTEM 1264 Function setifaceUpdateFiles() has failed. Return code is 0xC0000142, dwRes is C0000142.
6/6/2007 1:40:36 PM SYSTEM 1264 An error has occured while attempting to update. Please check the logs.
7/1/2007 5:41:36 PM Brian 2652 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP954\A0138668.exe” file.
7/1/2007 5:55:40 PM Brian 2652 Sign of “Win32:Adware-gen. [Adw]” has been found in “C:\WINDOWS\system32\dbxDgrevCheck.dll” file.
11/27/2008 12:17:17 PM SYSTEM 1264 Function setifaceUpdateFiles() has failed. Return code is 0xC0000142, dwRes is C0000142.
11/27/2008 12:17:17 PM SYSTEM 1264 An error has occured while attempting to update. Please check the logs.
12/31/2008 8:24:33 AM Brian 1924 Sign of “Win32:Downloader-KK [trj]” has been found in “C:\Documents and Settings\Brian\Local Settings\Temp\ICD1.tmp\UERS_9999_N91S2507NetInstaller.exe” file.
12/31/2008 8:29:54 AM Brian 1924 Sign of “Win32:Trojan-gen {Other}” has been found in “C:\Documents and Settings\Brian\Local Settings\Temp\UPRP_0001_D21M2103\installer.exe[Embedded_R#005470]{app}\UPRPPChk.dll” file.
12/31/2008 8:33:46 AM Brian 1924 Sign of “Win32:WinFixer-W [trj]” has been found in “C:\Documents and Settings\Brian\Local Settings\Temp\UPRP_0001_D21M2103\installer.exe[Embedded_R#005470]{app}\uprpcw.exe” file.
12/31/2008 8:41:16 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\Program Files\Common Files\Wise Installation Wizard\WISC27B94AA60AB4B509D630928CDC889C3_5_5_3.MSI\Cabs.w1.cab\InstPlug.exe[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 8:43:00 AM Brian 1924 Sign of “Win32:Agent-YBZ [trj]” has been found in “C:\Program Files\Common Files\Wise Installation Wizard\WISC27B94AA60AB4B509D630928CDC889C3_5_5_3.MSI\Cabs.w1.cab\DeskTopAuthor4_Manual.exe” file.
12/31/2008 8:43:09 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\Program Files\Common Files\Wise Installation Wizard\WISC27B94AA60AB4B509D630928CDC889C3_5_5_3.MSI\Cabs.w1.cab\dbdrm.dbp[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 8:44:21 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\Program Files\DeskTopAuthorEval\dbdrm.dbp[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 8:45:54 AM Brian 1924 Sign of “Win32:Agent-YBZ [trj]” has been found in “C:\Program Files\DeskTopAuthorEval\DeskTopAuthor_Manual.exe” file.
12/31/2008 8:46:09 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\Program Files\DeskTopAuthorEval\InstPlug.exe[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 8:46:35 AM Brian 1924 Sign of “Win32:Spyware-gen [trj]” has been found in “C:\Program Files\iplaynet\ipReset.exe[Embedded_I#464e8]” file.
12/31/2008 8:46:48 AM Brian 1924 Sign of “Win32:Timesink [trj]” has been found in “C:\Program Files\iplaynet\ipReset.exe[Embedded_I#64ae8]” file.
12/31/2008 8:46:51 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\Program Files\iplaynet\ipReset.exe[Embedded_I#9cae8]” file.
12/31/2008 9:10:13 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190260.MSI\Cabs.w1.cab\InstPlug.exe[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 9:11:01 AM Brian 1924 Sign of “Win32:Agent-YBZ [trj]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190260.MSI\Cabs.w1.cab\DeskTopAuthor4_Manual.exe” file.
12/31/2008 9:11:12 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190260.MSI\Cabs.w1.cab\dbdrm.dbp[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 9:11:19 AM Brian 1924 Sign of “Win32:Agent-YBZ [trj]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190261.exe” file.
12/31/2008 9:14:55 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190262.exe[UPX][Embedded_R#INSTPLUG][Embedded_R#DIGITALRIVER]” file.
12/31/2008 9:15:08 AM Brian 1924 Sign of “Win32:Spyware-gen [trj]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190263.exe[Embedded_I#464e8]” file.
12/31/2008 9:15:11 AM Brian 1924 Sign of “Win32:Timesink [trj]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190263.exe[Embedded_I#64ae8]” file.
12/31/2008 9:15:15 AM Brian 1924 Sign of “Win32:Adware-gen [Adw]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190263.exe[Embedded_I#9cae8]” file.
12/31/2008 9:15:16 AM Brian 1924 Sign of “Win32:Timesink [trj]” has been found in “C:\System Volume Information_restore{ED28D15B-E4CB-41F7-9E40-60E52CF4B817}\RP1557\A0190263.exe” file.
12/31/2008 9:25:29 AM Brian 1924 Sign of “Win32:Downloader-KK [trj]” has been found in “C:\WINDOWS\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe” file.
1/3/2009 9:06:02 AM SYSTEM 1284 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
1/3/2009 9:06:04 AM SYSTEM 1284 An error has occured while attempting to update. Please check the logs.

Well a quick look at the file names and their locations indicate there are no system files, nor files that are likely to have a impact on the system.

The detections in the C:\System Volume Information_restore points, are placed there by system restore when you delete or move files from the system folders, etc. and they are effectively inert unless you use system restore to a point which would include these infected restore points.

However, if there is any doubt on a restore point it is best out of the C:\System Volume Information\ folder so it can’t possibly bite you in the rear some time in the future. So at worst you simply couldn’t use that restore point in the future, which isn’t that much of a big deal considering why it is in the C:\System Volume Information_restore folder, you previously deleted or moved it from a system folder. The older that restore point is the less benefit it is as if there was a problem from the original deletion it should have presented itself.

So I would suggest running some more tools.
If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).

  1. SUPERantispyware On-Demand only in free version.
  2. MalwareBytes Anti-Malware, On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.

Also after running the above, use this analysis tool.
Program & Tutorial - Also useful as a diagnostic tool - FileHippo Download - HiJackThis and post the contents of the HJT log file here. - HJT Information HiJackThis Tutorial.

Download and run HJT and post the contents of the log file (cut and paste or attach the log file) into this topic, you may need to split it over two or more posts depending on how large it is.

You suggested running more tools. I understood that it is not wise to have more than one anti-virus software loaded at one time. At any rate, here is the HijackThis Logfile. Thanks for your help :slight_smile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:34:21 AM, on 1/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\SM1BG.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\dad9.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=192.168.0.1:87
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = systemcontrolcenter.com;192.168.0.1;*.local;
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM..\Run: [ISUSScheduler] “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start
O4 - HKLM..\Run: [SunJavaUpdateSched] “C:\Program Files\Java\jre6\bin\jusched.exe”
O4 - HKLM..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] “C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe”
O4 - HKLM..\Run: [BCROReminder] C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
O4 - HKCU..\Run: [MSMSGS] “C:\Program Files\Messenger\msmsgs.exe” /background
O4 - HKCU..\Run: [MoneyAgent] “C:\Program Files\Microsoft Money\System\Money Express.exe”
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [BCROReminder] C:\Program Files\ByteCrusher\RegistryOptimax\BCRO.exe -rem
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Corel\WordPerfect Office 2000\Register\Remind32.exe
O4 - Global Startup: Desktop Application Director 9.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\dad9.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.kifm.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {164B406B-0FD6-4E7F-BA7E-64D227D4CA37} (dnlplayer Class) - http://www.digitalwebbooks.com/reader/dbplugin.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://email.health.state.ny.us/go/egg2.health.state.ny.us/iNotes6.cab
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
O16 - DPF: {5EDB10D9-7E95-4833-A218-62F375DAFCF1} (Aventail Installer ) - https://email.health.state.ny.us/postauthI/epi.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe


End of file - 9064 bytes

Do you really think I would suggest something that would conflict with avast ???

Just take a look at my signature.

If you can’t trust me how can I possibly help you.


From your HJT log :

You do not seen to have an active process of a firewall on your system. If you do, please tell us what firewall.

This one is very bad and is related to a variant of CoolWebSearch or Home Search Assistant :

O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll (file missing)

http://www.file.net/process/msopt.dll.html

http://research.sunbelt-software.com/threatdisplay.aspx?name=Looking-For.Home%20Search%20Assistant&threatid=14938