Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
My sisters computer is loading all kinds of garbage and filling the memory. I can't load the new virus program. A scan from my machine across the network found dozens of viruses many trapped in the _RESTORE files.
I'm trying to delete the entire restore folder and work forward from there, but get a ACCESS DENIED when I try to go to the recycle bin.
I've booted in safe mode using F8 still can't.
Booted in Safe mode and dropped to MSDOS found the hidden folder and tried to delete. Still no luck. Attempted to use the ATTRIB settings to -r and it won't let me do anything with the attrib just gets a ACCESS DENIED.
Exact location is C:\_RESTORE as a folder and I want to delete it, or everything in it at the least.

You cannot and should not delete restore files--you may need them one day, like right now, to restore your pc to an earlier date.
Do what Leroi said and do the disabling, and do not re-enable it until you are clean.
To get clean try running these scans and tools:
Trojan Scan:
http://www.windowsecurity.com/trojanscan/
(trojan killer) SWATIT:
http://swatit.org/download.htmlUse two of these, or knock yourself out and do them all:
http://housecall.trendmicro.com/
security.symantec.com/ (security.symantec.com)
www.ravantivirus.com/scan/ www.ravantivirus.com/scan)
http://www.bitdefender.com/scan/licence.php
http://www.pandasoftware.es/actives...ivescan-com.asp
http://security2.norton.com/ssc/vc_scan.asp
http://housecall.antivirus.com/
Yous should also put a firewall on it. I use this one:
Free Sygate firewall:
http://smb.sygate.com/products/spf_standard.htm
I also use Spybot and Adaware at these settings. Update them and run them no more than every three days:
Spybot:
Download and Read the SpyBot tutorial here:
http://s89223352.onlinehome.us/mirror/spybot/index1.php
Download it, Unzip the program, and immediately check for updates, install the updates and then do the scan.
Let it fix everything marked in red. Reboot but not with restart, shut it down for two full minutes. You’ve got two measely minutes and it’s worth it, and let Spybot run if it indicates.
To add an item to your ‘Ignore List” click on the little ‘+’ sign next to the item and left click it to highlight it, then right click it and a menu appears, select the function you want.
When you are done reboot again same way. Two full minutes shut sown is best.
Tea Time discussed by designer here:
http://forums.net-integration.net/index.php?showtopic=13433
Also, go to the update page. Notice 3 icons across the top. Between "Search For Updates" and "Download Updates" there is an icon for the download mirror location. After you click on ‘search for updates,’ the one in the middle will change. If it doesn't say "Spybot.US by Rootboxen.net USA" click on the dropbox arrows and click on Rootboxen, and use only that one. If you got a "checksum error" trying to download --that's why.
Ad-Aware:Download AdAware from http://www.lavasoft.de/
check for updates at "webupdate".
I use these settings (green check)
From main window click "Start" then make sure " Activate in-depth scan" has a green check next to it.
Put a black dot nest to "Use custom scanning options” and click Customize" next to it, then green check these options:
"Scan within archives" ,"Scan active processes", "Scan registry",
"Deep scan registry" ,"Scan my IE Favorites for banned URL"
"Scan my host-files"At the top of the “STATUS” page notice the Tweak (gear) icon. Click on it.
The first setting is “Scanning Engine.” Click on the little plus sign next to it, and in the drop-down green check "Unload recognized processes during scanning", and “include basic Ad-Aware settings in log file”. Next click on the ‘+’ next to "Cleaning Engine" and in the drop-down green check "Let windows remove files in use at next reboot" and Delete quarantine objects after restoring”
Click "proceed", that will save those settings.
Click "Scan"
When the scan finishes, mark everything for removal and delete it. Right-click the window and choose "select all" from the drop down menu, press ‘next’ and then ‘yes’ to the prompt: “remove all these entries”.
However, if you have certain programs running that will give a false indicator of a browser hijack attempt, such as Script Sentry, which places a monitoring function in the registry and looks like a browser hijacker but is not, then you may want to add that to the ignore list because you want to keep it there to do it’s job. To add an item to the ignore list, put the a cursor on the file it reveals and left click it to highlight it, then right click it and a menu appears. Click on ‘ignore list.’
I shut down fotr two minutes, but that is optional for you , and let Adaware run on reboot if it indicates.
If you must pay for an AV, use Nod 32. Otherwise I recommend and use AVG by Grisoft. Also update it every 3 days or so.
The idea is to be thorough. Avoid the temptation to go for any kind of quick fix.
Thresher

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |