Fake .sys file?

DJ EHKOS

Banned
Hi, I am using Vista Home Premium 64bit and Trend Micro anti virus+ anti spyware.
I was playing 2moons for about three weeks before this happened. Changes that have occured include me being made an admisinstrator and UAC being turned off. I started playing 2moons and after a minute it froze up.Trend Micro alerted me that a program was trying to make unauthorized changes and it didn't help when I allowed or didn't allow said change.It now happens everytime I run 2moons but only that program. I tracked it to my Local\Temp folder and its name fluxuates. Its called yvnta.sys and will move around the first three-four letters each time it tries to change something. I scanned it with TM but it found nothing. its about 10 kb. Is this a legit sys file, if not should i delete it? Let me know if you need more info.
I moved it to the recycle bin and ran the program agian, now there is another file named yvatn.sys. they are now both in the recycle bin. Could it be coming from 2moons?
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    HP a6750y
    CPU
    AMD Phenom 9650 Quad-core 2.30 GHz
    Motherboard
    idk
    Memory
    8 gigs
    Graphics card(s)
    ATI Radon 3200
    Sound Card
    stock
    Monitor(s) Displays
    Compaq WF 1907
    Hard Drives
    700 gig HP
    Case
    stock
    Cooling
    fans
    Mouse
    HP
    Keyboard
    HP
    Internet Speed
    Comcast w/powerboost 25 megabits per second
Hi EHKOS and welcome to Vista Forums :party:

Is this a legitimate version of 2moons? Google has no information on either variant af the file you mentioned, which is suspicious. It could be that this file is part of the security features of this program, but its behaviour, particularly the dynamic changing of its name is alarming.

You can try to see if scanning with either or both of these online sites reveals anything.
Online File Scanner Sites - Windows 7 Forums
 

My Computer

System One

  • Manufacturer/Model
    Dwarf Dwf/11/2012 r09/2013
    CPU
    Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Bridge) (OC 4.2GHz)
    Motherboard
    ASRock Z77 Extreme4-M
    Memory
    4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2A1600C9B (16GB)
    Graphics card(s)
    MSI GeForce GTX770 Gaming OC 2GB
    Sound Card
    Realtek High Definition on board solution (ALC 898)
    Monitor(s) Displays
    ViewSonic VA1912w Widescreen
    Screen Resolution
    1440x900
    Hard Drives
    OCZ Agility 3 120GB SATA III x2 (RAID 0) Samsung HD501LJ 500GB SATA II x2 Hitachi HDS721010CLA332 1TB SATA II Iomega 1.5TB Ext USB 2.0 WD 2.0TB Ext USB 3.0
    PSU
    XFX Pro Series 850W Semi-Modular
    Case
    Gigabyte IF233
    Cooling
    1 x 120mm Front Inlet 1 x 120mm Rear Exhaust
    Mouse
    Microsoft Comfort Mouse 3000 for Business (USB)
    Keyboard
    Microsoft Comfort Curve Keyboard 3000 (USB)
    Internet Speed
    NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2)
    Other Info
    Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray Lexmark S305 Printer/Scanner/Copier (USB) WEI Score: 8.1/8.1/8.5/8.5/8.25 Asus Eee PC 1011PX Netbook (Windows 7 x86 Starter)
Yes, I got the program off of the acclaim website, I even un/reinstalled it.
I ran it through both those online scanners and they found nothing.
I ran 2moons again with the file in the recycling bin and another one was created in the same spot local\temp, with a slightly varied name.
 

My Computer

System One

  • Manufacturer/Model
    HP a6750y
    CPU
    AMD Phenom 9650 Quad-core 2.30 GHz
    Motherboard
    idk
    Memory
    8 gigs
    Graphics card(s)
    ATI Radon 3200
    Sound Card
    stock
    Monitor(s) Displays
    Compaq WF 1907
    Hard Drives
    700 gig HP
    Case
    stock
    Cooling
    fans
    Mouse
    HP
    Keyboard
    HP
    Internet Speed
    Comcast w/powerboost 25 megabits per second

My Computer

System One

  • Manufacturer/Model
    Dwarf Dwf/11/2012 r09/2013
    CPU
    Intel Core-i5-3570K 4-core @ 3.4GHz (Ivy Bridge) (OC 4.2GHz)
    Motherboard
    ASRock Z77 Extreme4-M
    Memory
    4 x 4GB DDR3-1600 Corsair Vengeance CMZ8GX3M2A1600C9B (16GB)
    Graphics card(s)
    MSI GeForce GTX770 Gaming OC 2GB
    Sound Card
    Realtek High Definition on board solution (ALC 898)
    Monitor(s) Displays
    ViewSonic VA1912w Widescreen
    Screen Resolution
    1440x900
    Hard Drives
    OCZ Agility 3 120GB SATA III x2 (RAID 0) Samsung HD501LJ 500GB SATA II x2 Hitachi HDS721010CLA332 1TB SATA II Iomega 1.5TB Ext USB 2.0 WD 2.0TB Ext USB 3.0
    PSU
    XFX Pro Series 850W Semi-Modular
    Case
    Gigabyte IF233
    Cooling
    1 x 120mm Front Inlet 1 x 120mm Rear Exhaust
    Mouse
    Microsoft Comfort Mouse 3000 for Business (USB)
    Keyboard
    Microsoft Comfort Curve Keyboard 3000 (USB)
    Internet Speed
    NetGear DG834Gv3 ADSL Modem/Router (Ethernet) ~4.0 Mb/s (O2)
    Other Info
    Optical Drive: HL-DT-ST BD-RE BH10LS30 SATA Bluray Lexmark S305 Printer/Scanner/Copier (USB) WEI Score: 8.1/8.1/8.5/8.5/8.25 Asus Eee PC 1011PX Netbook (Windows 7 x86 Starter)
I couldn't find anything that metions something like this. I don't really care about the game running, I just don't want this file to be malicous and I don't want to delete a system file.
 

My Computer

System One

  • Manufacturer/Model
    HP a6750y
    CPU
    AMD Phenom 9650 Quad-core 2.30 GHz
    Motherboard
    idk
    Memory
    8 gigs
    Graphics card(s)
    ATI Radon 3200
    Sound Card
    stock
    Monitor(s) Displays
    Compaq WF 1907
    Hard Drives
    700 gig HP
    Case
    stock
    Cooling
    fans
    Mouse
    HP
    Keyboard
    HP
    Internet Speed
    Comcast w/powerboost 25 megabits per second
Changes that have occured include me being made an admisinstrator and UAC being turned off.
...
I tracked it to my Local\Temp folder and its name fluxuates. Its called yvnta.sys and will move around the first three-four letters each time it tries to change something.

This does not sound very good, and I cannot think any legitimate software be doing this.

I suggest you start by performing some serious virus scanning. I am running x86 myself, but I think these three will run in 64 bit. Download and install the free editions of Malwarebytes, Spybot and SuperAntiSpyware. You do not have to install them all at once, try them one by one. Do not install anything memory resident (as Tea Timer), just use them on-demand. Run them from both normal and safe mode. Also try Vistas MRT, that's actually a good start.

You can also try some on-line scanners like e.g. ESET, Kaspersky and MS Live one-care.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista, Intel X25-M G2 160 GB for W7, Maxtor OT III External HDD, WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
I ran it through all the online scanners, Malwarebytes, and Spybot. Surprisingly nothing was found :confused: so i opened it using notepad and it looks corrupt. I decided to delete it and uninstall 2moons. I want to thank you both for your help, and I hope I can be of help to people too :D.
 

My Computer

System One

  • Manufacturer/Model
    HP a6750y
    CPU
    AMD Phenom 9650 Quad-core 2.30 GHz
    Motherboard
    idk
    Memory
    8 gigs
    Graphics card(s)
    ATI Radon 3200
    Sound Card
    stock
    Monitor(s) Displays
    Compaq WF 1907
    Hard Drives
    700 gig HP
    Case
    stock
    Cooling
    fans
    Mouse
    HP
    Keyboard
    HP
    Internet Speed
    Comcast w/powerboost 25 megabits per second
I ran it through all the online scanners, Malwarebytes, and Spybot. Surprisingly nothing was found :confused: so i opened it using notepad and it looks corrupt. I decided to delete it and uninstall 2moons. I want to thank you both for your help, and I hope I can be of help to people too :D.

Thank you for posting back.
We look forward to you helping out in due course.;)
 

My Computer

System One

  • Manufacturer/Model
    LAPTOP. HP Pavilion dv7-1005TX .
    CPU
    IntelCore [email protected] x2
    Memory
    4.00 GB installed, max capacity 8 GB.
    Graphics card(s)
    Nvidia GeForce 9600M GT & 512MB DDR2 dedicated graphics mem.
    Monitor(s) Displays
    17.0" diagonal WXGA + High definition brightview widescreen infinity display.
    Screen Resolution
    1440 x 900
    Hard Drives
    SPECS. Drive 1. 298.09 GB Fujitzu MHZ2320BH G2 ATA Device Drive 2. [ All as above.] CONFIG. C:\287.65 GB, D:\298.09 GB, E:\10.44 GB.
    Case
    Laptop / notebook.
    Cooling
    Stock.
    Mouse
    Synaptics PS/2 Port touch pad.
    Keyboard
    IBM enhanced
    Internet Speed
    ADSL [ Too slow.]
    Other Info
    Webcam.
Ditto
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS720
    CPU
    Intel Quad Q6600 2.40GHz
    Motherboard
    Dell 0YU822, NVIDIA nForce 680i SLI SPP / SLI MCP
    Memory
    4GB DDR2 800MHz
    Graphics card(s)
    Gainward GeForce GTX 560 Ti, 1024 MB GDDR5
    Sound Card
    Creative SB X-Fi Xtreme Gamer
    Monitor(s) Displays
    Dell 2407WFP-HC
    Screen Resolution
    1920x1200
    Hard Drives
    NVIDIA 640GB SATA Raid 0 (2x320GB) (7200 rpm) for Vista, Intel X25-M G2 160 GB for W7, Maxtor OT III External HDD, WD Elements 1 TB External HDD
    Internet Speed
    100/20
    Other Info
    M779 PCIe PAL/SECAM/DVB-T Desktop TV Tuner. Broadcom NetXtreme 57xx Gigabit Controller.
Back
Top