PDA

View Full Version : C:\system32\tools\restart


stratoc
February 6th, 2009, 06:46 AM
good morning, just done a scan and found the above file as possibly a variant win 32/adaware.agent? i spent a week cleaning up a trojan that slipped through 2 weeks ago, but surley this file is clean? i mean it was last modified june 2008. i have submitted it.
mbam and sas find nothing.
thanks.

nonoise
February 6th, 2009, 07:24 AM
try to upload it on virustotal (http://www.virustotal.com) and get it checked by 37 different AV solutions

stratoc
February 6th, 2009, 07:48 AM
have done thanks for that link.

stratoc
February 6th, 2009, 06:02 PM
have had no news back as yet, there is a folder ~ c;\system 32\tools that has 5 registry commands? the program copyright belongs to ecs who i thought was elitegroup the motherboard manufacturer. but in details it's spelt the following way elitgroup computer group, i have no idea what this program is, it's been on system since june, i have deleted the entire folder.
if anyone can shed any light on this i would be grateful, details of system to follow.
thanks
amd phenom II 940
msi k9n2 diamond (latest driver from msi site)
4gb ocz reaper ram
3x msi 280gtx oc driver (8122 driver from nvidia site)
vista ultimate
nod 32 3.0.684.0 antivirus
sas on demand
windows firewall
bt homehub firewall default
comodo reg cleaner (latest)
auslogics reg defrag


after removing this file i find no problems, if anyone can tell me what it was i would be forever grateful
many thanks