|
|
 |
|

24th Jan 04, 12:50 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
This was found by an online symantec security check and I swear I cannot find the files on my computer and nav does not detect it. What to do??
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004950.exe is infected with Trojan Horse
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004951.exe is infected with Trojan Horse
__________________
|
|

24th Jan 04, 12:54 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
Found it in the registry under Search assistant/ACMru. Wtf?
__________________
|
|

24th Jan 04, 01:31 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
Ok fixed the registry but another scan gave me this again:
Virus Status: Infected!
Your computer is infected with at least one known virus or Trojan horse.
Warning! The scan detected a virus that is active in your computer's memory.
The scan ended to prevent further infection.
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004950.exe is infected with Trojan Horse
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004951.exe is infected with Trojan Horse
__________________
|
|

24th Jan 04, 01:41 AM
|
BetaONE Supporter
|
|
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
|
|
Disable system restore on all drivers and restart windows and re-enable system restore.
Problem soloved. That is if the scanner is telling the truth.
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003
Download: http://war59312.admuncher.com/download.shtml
|
|

24th Jan 04, 02:20 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
Scanning again now. Last scan after reboot gave me this before enabling system restore.
Virus Status: Infected!
Your computer is infected with at least one known virus or Trojan horse.
No viruses were detected in memory
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004950.exe is infected with Trojan Horse
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\A0004951.exe is infected with Trojan Horse
__________________
|
|

24th Jan 04, 02:37 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
I still get the virus warning on the scan again
__________________
|
|

24th Jan 04, 02:46 AM
|
 |
Administrator
|
|
Join Date: Nov 2001
Posts: 2,996
|
|
You will have to delete the infected files manually from this folder:
D:\System Volume Information\_restore{17AB8B64-AA5E-4A0C-B064-2B695B43C137}\RP56\
Make sure that the options to view hidden and system files is checked in folder options.
If windows says you are not authorised to access those folders then turn off simple file and folder sharing, assign youself access to the folders and then delete the files.
|
|

24th Jan 04, 02:55 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
So far I cant find the folder. Its like it doesnt exist but I found stuff in the registry about it. This is too wierd and yes hidden files are enabled
__________________
|
|

24th Jan 04, 03:06 AM
|
 |
Senior Member
|
|
Join Date: Sep 2001
Location: New York, USA
Posts: 515
|
|
war59312 should be right... The infected file was captured within a snapshot most likely from System Restore... In order for you to removed the virus, you need to turn off System Restore for that drive (D: in your case), then restart the computer. Next turn back on System Restore and then run another virus scan on your system to see if it comes back up. The _Restore is associated with your System Restore snapshots.
James55, you are saying that after turning off System Restore on your D: drive, and then rebooting the system did not remove all of you past Restore Points? that is very interesting... If that is the case, then I would say to do what DoG suggested which is to continue to have System Restore off for your D: drive and then going in and manually remove the Restore Point directory that contains the virus, which is RP56. Once that is done, you should be able to turn back on System Restore for your D: drive.
-SlickVic78
__________________
 - Pentium 4 3.20GHz Processor
- 1 Gig DDR 400MHz RAM
- 100 Gig 7200 RPM Western Digital HDD
- 80 Gig 7200 RPM Western Digital HDD
- Lite-On LTR-52327S CD-RW Burner
- Lite-On SOHW-1633S DVD Burner
- ATI Radeon 9700 Pro
- Sound Blaster Audigy
- Microsoft Windows XP Pro SP-2
|
|

24th Jan 04, 04:36 AM
|
 |
Senior Member
|
|
Join Date: Jul 2001
Location: Carmichael,California,Usa
Posts: 647
|
|
Still working on it. I did a scan with the recue disk and nothing found. Nav did not find it. Could it be that the online scan was screwed up?
__________________
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 12:55 PM.
|
|