Computing.Net > Forums > Security and Virus > infected files

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

infected files

Reply to Message Icon

Original Message
Name: Helpneeder
Date: November 4, 2002 at 21:16:47 Pacific
Subject: infected files
OS: ME
CPU/Ram: 64MB
Comment:

My computer scanned and detected some virus in _Restore/temp/ folder. I couldn't quarantine, delete, nor modify it. I try to delete it from Dos, but didn't help. Any idea how to get it fixed?


Report Offensive Message For Removal


Response Number 1
Name: wawadave
Date: November 4, 2002 at 21:22:00 Pacific
Reply: (edit)

hello
you must disable system restore reboot scan again for viruses and if none found set a restore point. reboot.


Report Offensive Follow Up For Removal

Response Number 2
Name: capt
Date: November 4, 2002 at 21:26:41 Pacific
Reply: (edit)

You need to disable "system restore", and then shutdown the computer. I would also delete the temp internet files, just to make sure there are no viruses there. Restart and then run the scan, if the system is clean you can enable "system restore" and everything should be fine. Take care and all the best!


Report Offensive Follow Up For Removal

Response Number 3
Name: helpneeder
Date: November 4, 2002 at 21:28:49 Pacific
Reply: (edit)

Disable system restore!? How do I do so?? you mean by launching system restore in msconfig?


Report Offensive Follow Up For Removal

Response Number 4
Name: Wizzy
Date: November 4, 2002 at 21:34:53 Pacific
Reply: (edit)

I think I got it. Thanks for the instant responses!


Report Offensive Follow Up For Removal

Response Number 5
Name: capt
Date: November 4, 2002 at 21:43:43 Pacific
Reply: (edit)

Open control panel>system>look for system restore and you will see the check mark by turn off system restore.


Report Offensive Follow Up For Removal


Response Number 6
Name: capt
Date: November 4, 2002 at 21:47:23 Pacific
Reply: (edit)

You can also right click my compter>properties>system restore and check it there.


Report Offensive Follow Up For Removal

Response Number 7
Name: xtech
Date: November 4, 2002 at 22:06:16 Pacific
Reply: (edit)


Document ID:2000092513515106
Last Modified:08/30/2002


Cannot repair, quarantine, or delete a virus found in the
_RESTORE or System volume information folder

Situation:
Norton AntiVirus (NAV) has detected a virus in the _RESTORE or the
System volume information folder, but it cannot repair, quarantine, or
delete the infected file.

Solution:
One of the new features of Windows Me and Windows XP is System
Restore. This feature, which is enabled by default, is used by Windows to
restore files on your computer in case they become damaged. Windows
Me keeps the restore information in the _RESTORE folder. Windows XP
stores this information in the System volume information folder. These
folders are updated when the computer restarts.

If the computer is infected with a virus, then it is possible that the virus
could be backed up in the _RESTORE or System volume information
folder. By default, Windows prevents System Restore from being
modified by outside programs. Because of this, any repair attempts made
by Norton AntiVirus will fail. To work around this, you must disable
System Restore, and restart the computer. This will purge the contents of
the _RESTORE or System volume information folder. You must then run
a full system scan.

To disable System Restore:
Follow the steps that apply to your operating system:

Windows Me:

1. Close all open programs.
2. Right-click My Computer on the Windows desktop, and then click
Properties.
3. Click the Performance tab.
4. Click File System.
5. Click the Troubleshooting tab.
6. Check Disable System Restore, click OK, and then click Close.
7. Click Yes to restart. This disables the System Restore feature and
will purge the contents of the _RESTORE folder when the system is
restarted.
8. Run LiveUpdate and download the latest virus definitions.
9. Make sure that NAV is set to scan all files and all drives, and then
scan the computer.
10. After cleaning the infected files, repeat steps 1 through 7, except
in step 6, uncheck Disable System Restore.
(skip the nav part if you don't have nav, or substitute it with your av software)


Report Offensive Follow Up For Removal

Response Number 8
Name: Iceman man
Date: December 28, 2002 at 16:06:11 Pacific
Reply: (edit)

ya i have an infected file called trojan horse the file it is in is the system volume information i finally got it to show it on my c: drive then i disable the system restore but the funny part is that when i try to scan it it scanned no files, and then i tryied to double click it but it won't let me into it does anybody have any ideas how to do this i , to get rid of the trojan thank you

Dan


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you own an iPhone?

Yes
No, but soon
No


View Results

Poll Finishes In 6 Days.
Discuss in The Lounge
Poll History




Data Recovery Software