Computing.Net > Forums > Security and Virus > PE CIH virus

PE CIH virus

Reply to Message Icon

Original Message
Name: bill 2
Date: March 3, 2002 at 05:31:30 Pacific
Subject: PE CIH virus
Comment:

Running Windows ME and have PE CIH virus in three files c:\_RESTORE\TEMP\A0013084 A0013085 AND A001306. _RESTORE AND TEMP are both hidden and protected. How do I get rid of these three files?


Report Offensive Message For Removal


Response Number 1
Name: Worm
Date: March 3, 2002 at 05:53:26 Pacific
Reply: (edit)

You have to purge all your Restore points. This is how to go about it:
1) Hold down the ALT key while you double click the "My Computer" icon to bring up the "System Properties" dialog box.
2) Click the "Performance" tab.
3) Click the "File System" button.
4) Click the "Troubleshooting" tab.
5) Checkmark the option "Disable System Restore".
6) Click "Apply", then "OK".
7) Reboot the machine.

You've now purged all your previous System Restore points and the virus will be gone. Re-enable "System Restore" by removing the checkmark from "Disable System Restore" and rebooting again. Windows automatically creates a new Restore point, but you can also create one manually as well.

Last but not least, run a thorough virus scan to make sure that every trace of the virus has gone.


Report Offensive Follow Up For Removal

Response Number 2
Name: bill 2
Date: March 3, 2002 at 06:29:47 Pacific
Reply: (edit)

Did it and it now scans clean.


Report Offensive Follow Up For Removal

Response Number 3
Name: Sanjaya Sugiarto (by Sanjaya)
Date: March 3, 2002 at 09:00:04 Pacific
Reply: (edit)


Hmmm try here: http://grc.com/cih.htm


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: PE CIH virus

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge