Page 1 of 1

Unknown restore file virus maybe

Posted: Sat Nov 28, 2009 1:37 am
by jwc
I found out what AstInfo is (a virus?), but something used
the dir name of my Zeronet directory as part of it's name.

Can't see it anywhere when looking for it in file manager(s).
It is only showing in aisbackup, and it's colored brown too.

Do you know what it might be, or how to del it?

Image

Posted: Sat Nov 28, 2009 10:38 am
by Barry
AISBackup's Select Files for Restore screen shows Alternate Data Streams (ADS) in maroon colour.

AISBackup's Manage Backup / Modify Files and Folders option can show ADS, simply check the Show NTFS ADS option. There are right click options one of which is Delete ADS.

Barry

Posted: Sat Nov 28, 2009 3:26 pm
by jwc
Hi Barry,

I tried that (with backup dvd in the drive), and checked that
box and it says Extracting Alternate Data Streams, but it doesn't
show up in the directory tree at all so I cannot select Delete ADS.

Showing ADS

Posted: Sat Nov 28, 2009 4:36 pm
by Barry
I am not sure if you understood me, or indeed if I understood you:

Are you wanting to see the ADS on the PC (not the backup)? If so then:

Select any backup job (does not matter which one)
Manage Backup / Modify Files and Folders List
Check Show NTFS ADS

Do you see the ADS on the folder now?

Please download the latest version of AISBackup as there was a problem displaying ADS on folders in earlier versions of AISBackup (files were okay).

Barry

Posted: Sat Nov 28, 2009 7:05 pm
by jwc
No, tried that and it doesn't show the ADS on the folder, root dir, or anywhere.
When that job was run, I didn't know it was there until I did a restore (as in the
screen shot at top of this thread)

But I ran a program yesterday, and deleted all suspected root kits. It's gone
now, but it was recorded on that certain backup job I think. And I won't be
using that backup dvd again. :) (formated it for a new job)

I've been using v2.8.0.361 since it was released. Is there a newer version?

ADS

Posted: Sat Nov 28, 2009 9:27 pm
by Barry
I see, you cannot see the ADS now because the root kit deleted it. FYI: If you had to restore the folder you could have gone in and deleted the ADS afterwards using the right click option.

Barry