Computing.Net > Forums > Security and Virus > Virus / _RESTORE Folder Nightmare

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Virus / _RESTORE Folder Nightmare

Reply to Message Icon

Original Message
Name: Jay
Date: June 17, 2002 at 14:45:08 Pacific
Subject: Virus / _RESTORE Folder Nightmare
Comment:

1.discovered i had a virus named "WIN95.CIH.1003.A", along with a worm called "Win32.Hybris.plugin worm".
2.installed new virus scanner (e Trust EZ Antivirus)....ran it, removed most of them, then found another 738 versions of the same virus in my _RESTORE folder.....which as you know, cannot be touched or deleted.
3.Tried the My Computer>properties>performance>file system>troubleshooting>disable system restore (which supposedly purges ALL restore files on startup)
think again - nothing.......almost 1.4 GB of files still there. tried this 3 times.....nothing
4.found out about a too good to be true program called "System Restore Remove Pro 1.5 final" - bingo - too good to be true.....doesn't work, web tech support nonexistent) all files still in _RESTORE.
bottom line, the virus will continue to spread itself all over my hard drive until this folder's contents are deleted. Heck - i downloaded the new antivirus program and as i ran it the virus had already spread itself to it in the first virus check. What can I do to get this folder clear. i pray this message makes it to post before explorer crashes once again!


Report Offensive Message For Removal


Response Number 1
Name: DW
Date: June 17, 2002 at 19:25:00 Pacific
Reply: (edit)

This link will walk you through removing a virus from your Restore folder,
it is not the fault of your anti virus program
Good luck


Report Offensive Follow Up For Removal

Response Number 2
Name: JackG
Date: June 17, 2002 at 19:25:11 Pacific
Reply: (edit)

Sounds like your system is already corrupted. Check the Norton/McAfee web sites and read other posts on this virus. Then get their removal tool and follow the instructions. You must kill this virus out of memory before doing a virus scan or the the virus scan will spread it.

The files in _Restore are not a problem. They are in compressed files. Everytime you run an infected program, the virus is back in memory and infects files that are opened. This causes them to place into the restore folder again.

Get out your Windows boot diskette. Make sure the write protect tab is OPEN. Boot your system from the diskette and at the DOS prompt enter:

DELTREE C:\_RESTORE

This will prompt you to verify removing all of the _RESTORE folder and files. And will get rid of that minor issue while you attack the virus. You can also attack the virus from the DOS diskette, by deleting the infected file that is being loaded when you boot.


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software