The above video goes away if you are a member and logged in, so log in now!
 

CIGAR REVIEWS | CIGAR VIDEOS | INTERVIEWS | CIGAR NEWS | OUR TWO CENTS BLOGS | PUFFCAST | CIGAR FORUMS | PUFF LIFESTYLE | CONTACT

Puff Cigar Discussion Forums

Go Back   Puff Cigar Discussion Forums > Non Cigar Related Specialty Forums > Everything But Cigars > General Discussion

I admit defeat

This is a discussion on I admit defeat within the General Discussion forums, part of the Everything But Cigars category; Yes, it seems that even one as computer savvy as myself can be defeated by viruses. So now I must ...

Reply
 
LinkBack Thread Tools
Old 11-19-2007, 07:52 PM   #1
On the sidewalk
 
Seanohue's Avatar

Seanohue's Profile
Join Date: Oct 2006
City: Pasadena, MD/Terre Haute, IN
Posts: 3,930
Gameroom cash: $250
Ring Gauge: 5702
Seanohue's Icons
 
I admit defeat

Yes, it seems that even one as computer savvy as myself can be defeated by viruses. So now I must ask for others help to defeat this one. I'll try to describe it as best I can:

In the background, I keep hearing a clicking noise, like a new window is being opened. At some point, I'll start hearing commercials; no window or anything, just sound. The two files that seem to be controlling this is Indt2.sys and ndt2.sys, and both are located in the system32 folder. When I end those processes and delete the files in the system32 folder, the clicking stops and all is fine. But after a restart, the files are up and running again. Also, during boot-up, a "personalizing settings" window pops up the upper left corner to say that something is being configured in C:\WINDOWS\system32\Bifrost\server.exe. I'm thinking that this has to be what is causing the problems. I can locate the server.exe file through windows search, but I can't find the Bifrost folder in system32. Ad-Aware and AVG aren't picking up a single thing, so I have no idea what to do now.
__________________
A-P is still down....
Seanohue is offline   Reply With Quote
Old 11-19-2007, 07:58 PM   #2
Here Sometimes
 
Old Sailor's Avatar

Old Sailor's Profile
Join Date: Jul 2006
City: Canada
Posts: 11,631
Gameroom cash: $250
Ring Gauge: 11983
Old Sailor's Icons
 
Re: I admit defeat

Do you have "view hidden folders" option checked, if not you won't see all important file stuff.
__________________
Dave
Gone for awhile.





I WAS ALWAYS TAUGHT TO RESPECT MY ELDERS.... NOW I DON'T HAVE ANYONE TO
RESPECT!
Old Sailor is offline   Reply With Quote
Old 11-19-2007, 08:00 PM   #3
On the sidewalk
 
Seanohue's Avatar

Seanohue's Profile
Join Date: Oct 2006
City: Pasadena, MD/Terre Haute, IN
Posts: 3,930
Gameroom cash: $250
Ring Gauge: 5702
Seanohue's Icons
 
Re: I admit defeat

Yea, I have that checked; the Bifrost folder still won't show though.
__________________
A-P is still down....
Seanohue is offline   Reply With Quote
Old 11-19-2007, 08:03 PM   #4
Here Sometimes
 
Old Sailor's Avatar

Old Sailor's Profile
Join Date: Jul 2006
City: Canada
Posts: 11,631
Gameroom cash: $250
Ring Gauge: 11983
Old Sailor's Icons
 
Re: I admit defeat

Ok, try this start, run, type in regedit, see if it shows that way any where. if so try deleting it there.
__________________
Dave
Gone for awhile.





I WAS ALWAYS TAUGHT TO RESPECT MY ELDERS.... NOW I DON'T HAVE ANYONE TO
RESPECT!
Old Sailor is offline   Reply With Quote
Old 11-19-2007, 08:14 PM   #5
On the sidewalk
 
Seanohue's Avatar

Seanohue's Profile
Join Date: Oct 2006
City: Pasadena, MD/Terre Haute, IN
Posts: 3,930
Gameroom cash: $250
Ring Gauge: 5702
Seanohue's Icons
 
Re: I admit defeat

Ok, I can kill the folder now, but it still comes back after a restart. Is there anyway to track what has created that file?
__________________
A-P is still down....
Seanohue is offline   Reply With Quote
Old 11-19-2007, 08:17 PM   #6
Here Sometimes
 
Old Sailor's Avatar

Old Sailor's Profile
Join Date: Jul 2006
City: Canada
Posts: 11,631
Gameroom cash: $250
Ring Gauge: 11983
Old Sailor's Icons
 
Re: I admit defeat

If it still comes back, its gotta be in the registry somewhere, usually the above post about regedit will remove all traces of it. Other than that I'm stumpped.
__________________
Dave
Gone for awhile.





I WAS ALWAYS TAUGHT TO RESPECT MY ELDERS.... NOW I DON'T HAVE ANYONE TO
RESPECT!
Old Sailor is offline   Reply With Quote
Old 11-19-2007, 08:39 PM   #7
Maturing Puffer Fish
 
Danh78's Avatar

Danh78's Profile
Join Date: Sep 2007
City: Glen Burnie, MD
Posts: 108
Gameroom cash: $250
Ring Gauge: 169
Danh78's Icons
 
Re: I admit defeat

Try running msconfig to see if you might find that service in the startup?
Danh78 is offline   Reply With Quote
Old 11-19-2007, 08:43 PM   #8
I smoke sub $7.00 cigars
 
JaKaAch's Avatar

JaKaAch's Profile
Join Date: Sep 2006
City: Wear the fox hat, Kansas
Posts: 2,690
Gameroom cash: $250
Ring Gauge: 3191
JaKaAch's Icons
 
Re: I admit defeat

Quote:
Originally Posted by Old Sailor View Post
If it still comes back, its gotta be in the registry somewhere, usually the above post about regedit will remove all traces of it. Other than that I'm stumpped.
I have read somewhere a virus can show back up after a restart because it is in a restore point. Delete all system restore points, that might get it.
__________________
I want to die in my sleep like Grandpa, Not screaming in terror like his passengers!!
JaKaAch is offline   Reply With Quote
Old 11-19-2007, 08:56 PM   #9
Puffer Fish with many spikes
 
xxwaldoxx's Avatar

xxwaldoxx's Profile
Join Date: Apr 2006
City: Reading, PA
Posts: 912
Gameroom cash: $250
Ring Gauge: 241
xxwaldoxx's Icons
 
Re: I admit defeat

Check out www.geekstogo.com and head over to the forums

They have tons, and tons or info on Malware removal.
__________________

Walt White
xxwaldoxx is offline   Reply With Quote
Old 11-19-2007, 08:56 PM   #10
Puffer Fish with many spikes
 
Golfman's Avatar

Golfman's Profile
Join Date: Jul 2006
City: Manhattan, New York
Posts: 977
Gameroom cash: $250
Ring Gauge: 297
Golfman's Icons
 
Re: I admit defeat

yea turn windows restore off... because the virus is using that windows feature which regenerates deleted folders to prevent it from crashing against you. once you turn off system restore and delete the files they should be gone for good and problem solved.. just look online how t turn off system restore cuz i forgot hehe
__________________
"Look your last upon the Sun"

"A well chosen cigar is like armor, and is useful against the torments of life" -Zino Davidoff
Golfman is offline   Reply With Quote
Old 11-19-2007, 09:05 PM   #11
kvm
Huge Puffer Fish packed with spikes
 
kvm's Avatar

kvm's Profile
Join Date: Sep 2005
Posts: 2,220
Gameroom cash: $250
Ring Gauge: 1298
kvm's Icons
 
Re: I admit defeat

Sounds like a variant of this.
http://www.symantec.com/security_res...151-99&tabid=2

You can start by disabling system restore and killing the process.
Then connect to trendmicro and run housecall to see if it can remove it.
I didn't check all the charateristics of it but if AVG was already installed on your system it may have been affected by it.
__________________
"Life is what happens to you when you're busy making other plans" - John Lennon

"The truly great are never deterred by the truth!" - Anon-y-mouse
kvm is offline   Reply With Quote
Old 11-19-2007, 09:42 PM   #12
On the sidewalk
 
Seanohue's Avatar

Seanohue's Profile
Join Date: Oct 2006
City: Pasadena, MD/Terre Haute, IN
Posts: 3,930
Gameroom cash: $250
Ring Gauge: 5702
Seanohue's Icons
 
Re: I admit defeat

Killed it! The Bifrost folder had to be deleted through the registry and the Indt2.sys and ndt2.sys files were deleted in safemode. No more annoying clicks! Thanks for all the help guys
__________________
A-P is still down....
Seanohue is offline   Reply With Quote
Old 11-19-2007, 09:54 PM   #13
Here Sometimes
 
Old Sailor's Avatar

Old Sailor's Profile
Join Date: Jul 2006
City: Canada
Posts: 11,631
Gameroom cash: $250
Ring Gauge: 11983
Old Sailor's Icons
 
Re: I admit defeat

__________________
Dave
Gone for awhile.





I WAS ALWAYS TAUGHT TO RESPECT MY ELDERS.... NOW I DON'T HAVE ANYONE TO
RESPECT!
Old Sailor is offline   Reply With Quote
Old 11-19-2007, 10:00 PM   #14
Son of Evil Emperor Zurg
 
jjirons69's Avatar

jjirons69's Profile
Join Date: Jul 2007
City: In the Gamma Quadrant
State: South Carolina
Real First Name: Jamie
Posts: 2,583
Gameroom cash: $335
Ring Gauge: 3443
jjirons69's Icons
 
Re: I admit defeat

Great job guys! What an aggravating problem to have.

I smile while reading as my Mac and I continue our bit and byte journeys...
__________________
I'll have a cafe, mocha, vodka, valium latte to go please.
jjirons69 is offline   Reply With Quote
Old 11-19-2007, 10:05 PM   #15
Leading Puffer Fish
 
a2vr6's Avatar

a2vr6's Profile
Join Date: Oct 2006
City: Ajax, Ontario
Posts: 1,121
Gameroom cash: $665
Ring Gauge: 534
a2vr6's Icons
 
Re: I admit defeat

Now get yourself a decent antivirus. I highly recommend Nod32, worth every penny and not a resource hog like Mcafee or Norton. Oh yeah, get a couple of spam sweeping tools on your machine and run a scan every week.
a2vr6 is offline   Reply With Quote
Reply

Bookmarks

Tags
admit , defeat

Go Back   Puff Cigar Discussion Forums > Non Cigar Related Specialty Forums > Everything But Cigars > General Discussion

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On





All times are GMT -4. The time now is 06:53 AM.


© 2009 by Puff Enterprises. All rights reserved. Puff Cluster hosted by Hostway.
Terms of Service - Privacy Policy