Computing.Net > Forums > Security and Virus > How does a cleaned virus reappear?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

How does a cleaned virus reappear?

Reply to Message Icon

Name: SweenCat
Date: September 11, 2007 at 11:08:39 Pacific
OS: Windows XP SP2
CPU/Ram: 2 GB
Product: HP XW4100 Workstation
Comment:

I use Computer Associates Security for my virus, spyware and Internet protection. Several months ago, I downloaded a program. I immediately scanned it for viruses or spyware and it came up clean. I then installed it. Many scans since then have come up clean. Now, months later, an overnight scan is showing a Win32/Ilar.O virus was deleted from the setup.exe. I don't understand where this came from at this late date. BTW, every few weeks, I update CA, Spybot and Adware, turn off System Restore, go into Safemode, and run the scans just to be sure nothing remains in the restore file. These have come up clean. This is not the first time this has happened. Each time a virus is found, it is a different name. I guess I just don't understand the anatomy of a virus and how it survives repeated cleanings, but only appears randomly under different names. Would one of you experts clue me in, please.



Sponsored Link
Ads by Google

Response Number 1
Name: XpUser
Date: September 11, 2007 at 11:47:03 Pacific
Reply:

Cleaned virus will reappear without challenge straight from the System Volume Information (SVI) folder managed by System Restore. SVI folders are off-limited to all AV programs.

If you have System Restore turned on, turn it off then rescan the PC to remove all traces.

i_Xp/VistaUser


0

Response Number 2
Name: XpUser4Real
Date: September 11, 2007 at 14:17:55 Pacific
Reply:

From what I read I can see that the poster turns OF system restore and scans (it may have been overlooked...np:)

**every few weeks, I update CA, Spybot and Adware, turn off System Restore, go into Safemode, and run the scans just to be sure nothing remains in the restore file. **

SweenCat, this is worth a shot. D/L Avast Free to your desktop:
http://www.avast.com/eng/download-a...

Looks like you maybe had Norton installed prior to setting up CA Trust. If so, go to the Norton website and user their uninstaller to remove whatever else is lurking on your PC. Then use regcleaner:
http://www.majorgeeks.com/download4...
to clean out the rest of the previous AV.

Now turn off CA and install Avast and make sure to put a check in that it does a bootscan on reboot. Move everything it finds to the chest.

If things are not running better, then go into safe mode with networking and do this free active X scan:
http://www.spywareinfo.com/xscan.php
also remove all it finds.

Post back on how you are making out. There's other suggestions yet. Thanks


Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 3
Name: XpUser
Date: September 11, 2007 at 14:25:54 Pacific
Reply:

You're rite - I missed reading that part.

i_Xp/VistaUser


0

Response Number 4
Name: XpUser4Real
Date: September 11, 2007 at 14:27:03 Pacific
Reply:

no problem, we all make reading mistakes....especially me at the best of times :)
To Er is human
Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 5
Name: SweenCat
Date: September 11, 2007 at 21:40:30 Pacific
Reply:

Thank you to all who responded. I followed all the suggestions made by XpUser4Real. The Avast scan turned up three Trojans. The active X scan showed a few infestations as well. I'll monitor future CA Trust scans to see if anything comes up again now that I turned it back on. I hope it is OK for me to ask some additional questions: (1) How did you know that I used Norton's before CA Trust? (2) Why did these viruses only show up in scans every once in a while--but not every time? (3) If I had given this same program to someone on a CD, would that have infected their computer as well? Thanks again!!!!


0

Related Posts

See More



Response Number 6
Name: XpUser4Real
Date: September 12, 2007 at 09:41:12 Pacific
Reply:

(1) How did you know that I used Norton's before CA Trust?

I figured it had to be Norton or McAfee, because they get so imbedded on a PC that unless everything is removed, no other AV or firewall will work properly

(2) Why did these viruses only show up in scans every once in a while--but not every time?

That's a hard one to explain, viruses have a habit of doing that

(3) If I had given this same program to someone on a CD, would that have infected their computer as well?

It is not the CD that's infected, it was because of what was left on your PC from other AV's.

FWIW, I just finished working on a retired Army friend's laptop. He had Roadrunner as his ISP and they offered CA Trust for free. He loaded that up and suddenly his PC took 10 minutes or more to boot up. Slow as mollasses. I did the same to his PC as what you did....Then I totally uninstalled CA and loaded up:
1-Avast Free
2-Comodo Free Firewall
3-Spyware Terminator

Now his PC boots up in 45 seconds....he was amazed.
See, Avast doesn't need any maintenance or scheduled scans....with the Avast webshield it catches any viruses in real-time allowing you to abort your connection to prevent getting them. This is great for home use.


Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 7
Name: SweenCat
Date: September 13, 2007 at 09:46:01 Pacific
Reply:

Thank you again XpUser4Real. I blew off CA Trust and installed the three programs as you suggested. So far, I like the marked improvement in speed. Not being an expert on this stuff, I ran into a few areas I'm unsure of. Would you lend me your expertise one more time, please? In Comodo Firewall, if I leave the Network Monitor on, it shows my "Protection Strength" as excellent. However, then I cannot share my desktop and laptop drives. If I turn it off, I can access all drives from either computer, but the "Protection Strength" is only good. Does this really leave me vulnerable? Secondly, under Avast, I get a pop up asking me to allow or deny an application called "svhost.exe" (Parent: services.exe). I looked this up and some web sites say it could be a malicious virus and some say it is a system file. Should I permanently 'allow' or 'deny'??? Thanks again for your "spot on" assistance!


0

Response Number 8
Name: XpUser4Real
Date: September 13, 2007 at 09:55:27 Pacific
Reply:

Is it svhost.exe or SVCHOST.exe that Avast is asking about?

For the Comodo question, you may want to send their support a question on that, they are pretty good at getting back to you in a short time.

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 9
Name: SweenCat
Date: September 13, 2007 at 19:21:50 Pacific
Reply:

Sorry, I typed it incorrectly. It is svchost.exe. Good file or bad file? I'll email Comodo about my networking problem. Thanks again for your help.


0

Response Number 10
Name: XpUser4Real
Date: September 13, 2007 at 19:28:45 Pacific

Response Number 11
Name: SweenCat
Date: September 14, 2007 at 09:15:10 Pacific
Reply:

Oh boy! Will it never end? Ok, when I first installed Comodo and turned off the Network Monitor on both computers, it let my desktop and laptop communicate on my home network. Then when I went back to use the laptop a second time, it only connects to my Linksys wireless router with limited or no connectivity. I followed the instructions for creating rules per the link that you so graciously provided, however, I still cannot get connected. I turned off all computers, the cable modem and the router. Then, after about 30 seconds, I turned them back on router > modem > computers thinking I would reset the router acquire a new IP address...but no luck. Since it all started after I installed Comodo, am I correct in assuming this is a Comodo problem? Also, in the instructions for creating the rules per the link, it didn't say if I was to leave all the rules already there or remove them and just use the four described. Sorry to be such a pain, but please,please, bear with me just a little bit longer. Otherwise, I'll have to blow Comodo off and just use the Windows firewall which I understand isn't too defensive. Thanks once again for your assistance.


0

Response Number 12
Name: XpUser4Real
Date: September 14, 2007 at 09:24:29 Pacific
Reply:

Did you hear back from the Comodo techs yet?

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 13
Name: SweenCat
Date: September 14, 2007 at 11:28:56 Pacific
Reply:

I misunderstood. I didn't contact Comodo cause I thought you were telling me to read the info at the link you gave me instead and do that first. I'll check with Comodo now. . .


0

Response Number 14
Name: SweenCat
Date: September 14, 2007 at 13:23:15 Pacific
Reply:

I just spent the last while perusing the Comodo website. I came across this link: http://forums.comodo.com/frequently...
I printed the instructions entitled "CPF Installation - Step by Step. I un-installed CPF on both my desktop and my laptop and re-installed it following these to the letter. I did not change anything or create any new rules and so far, everything appears to be working correctly. I have Internet on both computers and can file share. All seems right with the world (for now!). I guess I should have gone to the web site and looked these directions up before I installed the firewall. I didn't realize how many problems it could cause otherwise. Thank you for seeing me to the end of this.


0

Response Number 15
Name: XpUser4Real
Date: September 14, 2007 at 13:32:50 Pacific
Reply:

You are welcome and thanks for posting back!
Let's other people know if they have the same problem.
Thanks again.

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: How does a cleaned virus reappear?

How does a virus work? www.computing.net/answers/security/how-does-a-virus-work/6179.html

A Cleaning Program that Does it All www.computing.net/answers/security/a-cleaning-program-that-does-it-all/15053.html

How much does a server cost these days? www.computing.net/answers/security/how-much-does-a-server-cost-these-days/1524.html