Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Dropper virus in System Volume Information folder

Status
Not open for further replies.

tazzzkitty

Technical User
Jul 25, 2003
15
US
A few days ago, a message popped up on my computer from my virus scanner saying that a trojan horse was found called dropper.small.dq in my System Volume Information folder. It said to run a virus scan and that that would clean it up. But then the virus scan found no viruses. I've tried it sevral times and with a few different virus scanners. I can't get into that folder to delete it manually because I guess it's protected. Can anyone tell me how I can delete this virus? It's causing no problems on my computer yet, which I guess means it hasn't activated yet, or hasn't dropped the virus yet, since that's what a dropper trojan horse does. But I want to get rid of it before it causes any problems! Any help would be greatly appreciated! Thanx!

 
Just disable System Restore, scan, then re-enable System Restore.
 
I tried both of these things, but neither one worked. That virus scanner was so out of date it wouldn't run and it wouldn't let me do the update for some reason. It had an error. Is there somewhere I can get a newer version of it? And I turned off System Restore and it still wouldn't let me have access to that folder. Any other ideas?
 
Use the "search" on windows (on the start menu) search for "dropper.small.dq", search hidden files also on all your drives (C:\ A:\ E:\ ect)if it find it delete it from search.

Do you think I should by a monkey, it's cheaper and better than windows :p
 
I am using AVG for my virus protection and I too have a similar problem. The virus is in the system volume information folder but even after I shut off the system restore I am unable to delete the virus.

AVG reports that the they are located in:

D:\System Volume Information\_restore{C13DACA1-5B31-4169-B9D4-F874BACC06A4}\RP205\A0143299.exe:\CrackerBox.CAB:\Crackerbox.exe which is Trojan horse DDoS.Crackerbox

and

D:\System Volume Information\_restore{C13DACA1-5B31-4169-B9D4-F874BACC06A4}\RP253\A0156653.exe:\install.exe Which is the Trojan horse Dropper.Small.DE

I have even tried to go into the system volume and manually deleting it with the system restore off and it still comes back. I am baffeled at this one. Anyone with any ideas?
 
Are you sure that you've turned off System Restore on your D: drive? Is your os ME or XP? Is this a dual boot system? What format is the D drive - NTFS or FAT32?
 
I had same problem with clients pc. AVG pointed to it intermittently, and never on a full scan. Had to give up in the end and reloaded OS.lovsan-a this time.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top