Scan picked up virus but path does not exist
csmith on March 12, 2006, 10:40:01 AM
Just did a scan on my Win 2000 server and it came up with a virus which it said it could not deal with.

The path/file was given as

But in fact this structure only goes down as far as

If I drop the full path name into windows explorer it says 'error'

I'm using avast! 4 Server Edition, (2 years) since Oct 05

It actually found two others also at the same time which it put in the chest and I then deleted .. they were




Any suggestions about this .....



Re: Scan picked up virus but path does not exist
igor on March 12, 2006, 03:07:43 PM
Well, I'm not sure if it's really a virus (what was the exact malware name reported?) - but it seems that your server is being abused for unauthorized software distribution - there may  be a lot of illegal software in these folders.

The path uses reserved filenames (con, prn) and it's not possible to manipulate the files in the ordinary way (e.g. using Explorer). Try to use the command line (cmd.exe) and prefix the path with \\?\ - you should be able to access it that way.
You may want to delete the whole folder C:\WINNT\system32\os2, I think?
Re: Scan picked up virus but path does not exist
Vlk on March 13, 2006, 06:44:54 PM
Looks like something fishy is definitely going on there... The "con" in the pathname is a clear indication that someone/something is trying to HIDE some data on your hard drive... I'd recommend also looking at which TCP/IP ports are open - use e.g. tcpview to get a basic overview http://www.sysinternals.com/Utilities/TcpView.html

Re: Scan picked up virus but path does not exist
csmith on March 16, 2006, 07:41:12 AM
Am having to split my message  as too long for forum ... so please see both parts

YES ... I've definately been hijacked .... hopefully the information below can help you advise me what to do ......

Have used TCPView (Thanks.. I didn't know of this utility)

and the results are

My problem  is I do not understand what I'm looking at here.

I do not know how to close/open ports

There is definately something strange going on with the server as my ISP just sent me a warning

I've postered their warning at


which might be helpful to see what the malware? is doing.

In fact my ISP has given me 48 hours to solve this or they are pulling the plug


Re: Scan picked up virus but path does not exist
csmith on March 16, 2006, 07:41:59 AM
PART TWO of post

I'm using my server (Win2000 server SP2) as a web server
Win 2000 IIS
I use remote backup to a company iBackup to make backups
I use VNC to remotely manage the machine myself
I use WS_FTP for uploading/downloading files
SQL database is running
Visitor to the website are allowed to use a form to upload suggested website details for me to add
see example form at the bottom of the page

The server is dedicated & is in a datahosting centre

Other strange anomolies I've noticed

When I restart the machine .... the prompt window has "log off administrator" rather that "Restart Machine" ... which it has always been at when restarting (remotely) for the last 3 years .... I'm a 1,000 miles away from the server physically.

Also noticed twice that that when I've recently shutdown the machine remotely (with RESTART) it has prompted me to say that there is another user online ... I've never seen that before ... but it did get the adrenalin flowing. (still is)

Today when I connected I found that although AVAST server was installed all the modules has been switched off !!!!  .... in fact I only use the standard one anyway


I've just switched it back on and and now doing another "Thorough Scan"
including archived files
Virus Database 0611-0, 03/14/06

RESULTS ARE (viruses found)
File Name: C:\WINNT\system32\os2\com\con\prn\iosys\site\0day_0730\Active.WebCam.v5.0.Cracked.WinAll-CPHV\cphv1acw.zip\Active.WebCam.v5.0.Cracked.WinAll-CPHV.part1.rar\crack\WebCam.EXE\[ASPack]
Malware Name: Win32:Crypto
Malware Type: Virus/Worm
VPS version: 0611-0, 03/14/2006

Action .. DELETED Permanently  (except final results say ERROR .. cannot delete)

File Name: C:\WUTemp\Tool\ser.exe
Malware Name: Win32:Trojan-gen. {Other}
Malware Type: Virus/Worm
VPS version: 0611-0, 03/14/2006

Action .. DELETED Permanently .. seemed successful


(Drat I cannot seem to 'right click' to copy&past)
Quite a number of files are shown as 'cannot scan'

SO copied using Screen Shots



I've just read about
and it sounds all doom and gloom ;-(
but does not tell me how to get rid of it .. or repair what it has done.



When I look in the folder

I find a file  oso001.009
with propertie
type of file: "009 FILE"
size 105KB

I find a folder named "dll"
and inside are two files
type of file: application extension
size 12,646 bytes

type of file: application extension
size 247,860 bytes



In the TASK Manager

Applications running are

Processes are


Sorry this is rather long .... but trying to consider all the information that might help you help me with what to do.


Desperately fighting panic ;-(


Actually I do like your prompt when AVAST finds something wrong ... "No Need to Panic" ;-)
Re: Scan picked up virus but path does not exist
csmith on March 16, 2006, 11:59:37 AM
Sorry Guys

A third part to this posting .. more info

I had a look at the User Profiles
see screen shot at

I don't remember seeing this
profile before .... but that might just be because I've not noticed it and it's been there all the time.

Also now when I go to the Control Panel
I cannot find a "Users and Passwords"
icon in the options ... it's not there.


Re: Scan picked up virus but path does not exist
csmith on March 16, 2006, 04:28:43 PM
I've found a whole bunch of exe files in
see screenshot at

Can I just delete all of these?

They may be part of my problem

Re: Scan picked up virus but path does not exist
Lisandro on March 16, 2006, 04:35:34 PM
Files on this path could be deleted.
They belong to temporary Windows updates. They will be regenerated when you go to windows update site again  ;)
Re: Scan picked up virus but path does not exist
csmith on March 20, 2006, 10:36:25 AM
Really disappointed with the support this time from the Avast Team

Avast (server edition) seems to have allowed Win32:Crypto virus/worm into my server and doesn't seem to be able to do anything about it now here.

I had higher expectations especially after the initial installation help.


Re: Scan picked up virus but path does not exist
igor on March 20, 2006, 11:03:31 AM
Well, I really don't think that the virus is your problem.
According to the path, the malware is stored in a RAR archive - so there's no surprise about avast! not detecting it previously (the Standard Shield doesn't scan RAR or similar archives when writing by default - it would slow down your system very badly). It also means that you are not infected - the virus inside of a RAR archive is not dangerous. (Actually, it might not really be a virus at all - these warez releases are usually packed with very strange packers, and it may even be a false alarm on a crack file... but that's not the point here).

You should delete the whole C:\WINNT\system32\os2\com folder, including subfolders (or even C:\WINNT\system32\os2, I'm not sure if this folder belongs to Win2000 system) - it might contain gigabytes of illegal software.

Then, you should secure your system regarding network access. I'm no expert on network stuff, so I don't know how the stuff got uploaded to your server and how it's downloaded from there - could be misconfigured FTP, web server, or even some remote control stuff...
Re: Scan picked up virus but path does not exist
Vlk on March 21, 2006, 01:23:42 AM
Also, is the server fully patched? This might be a warez problem allowed by unpatched IIS...
Re: Scan picked up virus but path does not exist
stevegilmore on March 24, 2006, 08:15:24 PM
When I did a W2K Server install a few years ago, before I was even finished someone found the server and started uploading their 'downloads' onto it. I had the latest versions of the most popular movies that were just released to the theatres. I just couldn't get to them.

The first  W2K Server releases did not have Security set by default, meaning anyone could do anything on it from anywhere. Like you, It was very difficult to find the files and they could not be accessed because of their length.

I fixed it by taking it off of the Network, formatting and reinstalling, install all Service Packs and Security features and secure firewalls, then plugging it back into the network.  It was much quicker then trying to undo the damage, not knowing the extent of the damage.
Re: Scan picked up virus but path does not exist
csmith on July 24, 2006, 07:21:57 PM
Better Late Than Never

Just to report back that I did delete everthing in the folder
C:\WINNT\system32\os2 ...
and there were no bad effects ... all rubbish files put there by someone.

Did some more scans to check the disk clean.

.. and all has been OK since then .... until the next hacker ;-(

Thanks to those who helped with the suggestions  .......

I have been very pleased with avast! Server Edition but I may well be moving to a managed hosting facility where someone will take over the security role ...