Hi, I was just recently infected w/ a trojan (atiacm64.dll RogueAV_709 -> and it was producing win32.pornpopup cookies in my browsers) that somehow got into my computer w/o my knowledge.
But I manage to get rid of it and I posted in the malware forums (http://forums.whatthetech.com/Need_help_w_Win32_Pornpopup_t112679.html&gopid=660878#entry660878) in which LDTate helped me to make sure its traces are gone.
A few hours after the trojan was removed I decided to run 3 different online scans to make sure it was completely gone. (Norton, Panda 2.0, and Mcafee) But I noticed that I had 109 GB of space in my C: Drive and after the scans I had .7 MB.
After a few hours of googling, I found this program called TreeSize that helped me find where the missing space had gone.
I found out that 131 GB is in C:\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized
I went to Control Panels -> Internet Options -> General Tab- -> Browsing History -> Delete -> unchecked "Preserve Favorites website data" -> and then I pressed delete
and I got my 131 GB back.
LDTate replied "I'd be very very surprised if an infection was doing this.
I suggest you start a new topic in our Windows forum and see what the Tech Team suggest. "
So I am here to ask for help.
Had the trojan destroyed some of my window's files that caused the memory to go to temporary files like that?
Is there a way to check to make sure my computer is perfectly fine and not damaged in anyway? (like sounds, internet, registry, my programs, etc)
Thanks for the help.
Well, it was interesting to research what this virtualized folder is. And leaves some definite curiosity to what it actually was before you deleted it. The virtualized folder is a folder that Vista or Windows 7 creates for the protected mode version of Internet Explorer. Basically, in Vista and 7, Internet Explorer runs in a limited mode where it has very little permissions to write to anything on the system. This prevents security holes from allowing your computer to get infected while you browse the web. But, for reasons that are still a little uncertain to me, Microsoft created this virtualized folder where it will mirror the REAL file system (like the windows system folders) if Internet Explorer tries to write to any of these locations. So, instead of it writing to the real folders, it is writing to a virtual folder. This prevents it from actually touching protected files while allowing the software to continue as if nothing even went wrong. Kind of interesting, as it would seem that if the program was unable to write to areas it needed to write to that a failure message would be more useful.
So, this raises questions as to what was actually being stored in that folder. The file structure in that folder mirrors the real file structure in that you could've browsed it and saw something similar to program files, or windows folders in there where you could've seen exactly what was being written out. Its a little late now because you deleted it all. However, if the system is clear of malware, it would seem those scans needed to write a large amount of data to the drive. I might even suggest that those scans did not run properly because you did not run Internet Explorer in administrator mode before starting the online scan. So, one explanation might be that the scan actually copied a lot of system files and program files to the virtual folder because the on-line scan was unable to manipulate them the way it was supposed to be able to. The scan appeared to complete properly but in reality it did not finish correctly. Do you know if you ran Internet Explorer in adminstrator mode when running the online scan? TO do so you would right-click the internet explorer icon and choose run as administrator.
Finally, if LDTate has given the system an all clear then it is most likely clean. However, nobody can say for 100% certainty that every piece of the infection is completely gone. Nobody can say for sure some critical system file wasn't corrupted or changed in some way. And malware often times does mess with a lot of registry and security settings that might never be the same again even though the infection is technically gone. In my opinion, although you can be fairly certain your computer is no longer doing anything malicious, it is impossible to know the full extent of the damage caused by the infection. Only time will tell as you use various functions of your computer. Often times significant infections do enough damage that a complete reload of the operating system is required to get everything running stable and smoothly again. This is no fault of our malware removal team, just a reality of having something malicious on your computer that really has no regard for the stability of your system as it does its dirty work. Sometimes infected systems literally become a test bed for hackers to try new code and viruses. So, I'm sure you can understand that probably the only way to be certain everything is 100% back in order is to just wipe the drive and reload everything fresh. Otherwise, if your system is running well, and you are happy, you probably have nothing further to worry about. If you have problems with specific issues you can probably create a new thread here and receive support for those issues if possible.
Thanks for the reply,
before I deleted the contents of the folder through the internet options (clearing the Browsing History, cookies, etc), I did try to go into the folder to see what was in it.
I enabled to see hidden folders/files as well but I could not see anything in the folder except for this weird MSN logo icon with the name a mixture of letters and #s.
As for the admin thing for IE, I think I did run as admin for one of the scans but not for the other (although I dont remember which). But for Panda Online Scan, it was through firefox.
I did notice my computer slow up a huge amount after the scans (could this possibly be because of the large Temp folder even though I dont use IE as a browser?)
My computer went back to normal speed after I removed this folder through control panels internet options.
Another problem I did have was for FireFox-> when I tried to click the "View all comments" on facebook, it would not respond at all. The cursor would change to the finger pointing thing but it would never load and show all the comments.
-> I fixed it by reinstalling firefox.
I will continue to keep track to see if any computer programs/problems occurs.
Thanks a lot for the help!
Most likely the large slow down was due to the limited disk space you had. You basically choked your operating system by not having enough room on the hard drive to manipulate files and memory. You should always have at least a few gigs free on the hard drive. Anything less will start impacting performance significantly.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI