Author Topic: Not-A-Virus.Tool.Reboot  (Read 4809 times)

0 Members and 1 Guest are viewing this topic.

rdmaloyjr

  • Guest
Not-A-Virus.Tool.Reboot
« on: November 08, 2005, 02:41:39 AM »
Ewido has discovered and removed (it is quarantine) this Infection [Not-A-Virus.Tool.Reboot] in C:\WINDOWS\_MSRSTRT.EXE.  Ewido rates this infection as high risk.  What is it and is it dangerous?  What does it do?  Thanks.

Ewido found it 7/5/2005.  If I click on "Remove finally" will ewido remove just Not-A-Virus.Tool.Reboot or C:\WINDOWS\_MSRSTRT.EXE with Not-A-Virus.Tool.Reboot?
I know that is probably a dumb question.  I don't know if  C:\WINDOWS\_MSRSTRT.EXE is a legitimate file or part of the infection.

galooma

  • Guest
Re: Not-A-Virus.Tool.Reboot
« Reply #1 on: November 08, 2005, 02:55:52 AM »
Hi and welcome,
A google search revealed lots of hits. This one seems to answer your question
http://64.91.226.241/showthread.php?t=58140
good luck  :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89336
  • No support PMs thanks
Re: Not-A-Virus.Tool.Reboot
« Reply #2 on: November 08, 2005, 04:02:44 PM »
What is your OS?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rdmaloyjr

  • Guest
Re: Not-A-Virus.Tool.Reboot
« Reply #3 on: November 09, 2005, 11:02:23 PM »
What is your OS?

XP sp2.  You will find it listed in my sig. ;D

Quote
avast!; Ad-Aware SE; BitDefender Free; ewido; Firefox; Microsoft AntiSpyware; Spybot Search & Destroy; SpywareBlaster; SpywareGuard; WinPatrol; XP SP2 auto-updates; Yahoo Anti-Spy; ZoneAlarm

                       A to Z Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89336
  • No support PMs thanks
Re: Not-A-Virus.Tool.Reboot
« Reply #4 on: November 09, 2005, 11:19:20 PM »
Oops, damn eyes again ;D.

The reason I asked, for stuff like this to get established (e.g. put files in system folders, create registry entries, etc.) it needs certain admin privileges, give yourself a fighting chance and deny these rights.

Whilst browsing or collecting email, etc. if you get infected then the malware by default inherits the same permissions that you have for your user account. So if the user account has administrator rights, the malware has administrator rights and can reap havoc. With limited rights the malware can't put files in the system folders, create registry entries, etc. This greatly reduces the potential harm that can be done by an undetected or first day virus, etc.

Check out the link to DropMyRights (in my signature below) - Browsing the Web and Reading E-mail Safely as an Administrator.

If you are not getting a virus warning that and you believe it's a new or undetected virus, then if you can zip and password protect ('virus', will do) the suspect file and send it to virus @ avast.com (no spaces).

Give a brief outline of the problem (a link to this thread, etc.), the fact that you believe it to be a new or undetected virus and include the password in the body of the email. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rdmaloyjr

  • Guest
Re: Not-A-Virus.Tool.Reboot
« Reply #5 on: November 10, 2005, 11:41:07 PM »
Thank you DavidR.


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89336
  • No support PMs thanks
Re: Not-A-Virus.Tool.Reboot
« Reply #6 on: November 11, 2005, 12:23:08 AM »
Your welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security