Re: Trojanhorse problem

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 11/19/03


Date: Wed, 19 Nov 2003 13:07:38 -0500

Please read the following URL:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

The objective:
------------------
- Turn off the System Restore function
- Reboot the PC
- Using your AV package, perform a full scan of all files on the platform and clean/delete
       infectors found
- Turn on the System Restore function
- Reboot the PC
- Create a new System Restore point.

If you have problems, it can be done manually....

Use the WinME floppy boot disk and boot from drive "A:"
When you get to a DOS prompt enter the following command

attrib -r -s -h c:\_RESTORE
rename c:\_RESTORE c:\RESTORE.old

Reboot the PC.

In Windows delete the folder; c:\RESTORE.old

Please report back your results.

Dave

"Don" <anonymous@discussions.microsoft.com> wrote in message
news:00d301c3aec3$c73cc450$a401280a@phx.gbl...
| I'm running ME and I have a Trojanhorse Downloader
| Winshow.b on several of my _Restore\Temp files and I can't
| get it cleaned out. How can I delete these files?



Relevant Pages

  • Re: fs66.cab/generic dialer
    ... Turn off the System Restore function ... Reboot the PC ... The Cabs are archived files and I ...
    (microsoft.public.security.virus)
  • Re: Viruses in C:RestoreTemp*.cpy files that are write protected
    ... Turn off the System Restore function ... Reboot the PC ... | My McAfee antivirus software has isolated multiple viruses ...
    (microsoft.public.security.virus)
  • Re: W32.IrcBot
    ... Reboot the PC ... Turn on the System Restore function, and re-apply any System Restore preferences, ... Use the WinME floppy boot disk and boot from drive "A:" ...
    (microsoft.public.security.virus)
  • Re: DUMARU worm
    ... Reboot the PC ... Turn on the System Restore function, and re-apply any System Restore preferences, ... Use the WinME floppy boot disk and boot from drive "A:" ...
    (microsoft.public.scripting.virus.discussion)
  • Re: w32/sdbot
    ... Reboot the PC ... Turn on the System Restore function, and re-apply any System Restore preferences, ... Use the WinME floppy boot disk and boot from drive "A:" ...
    (microsoft.public.scripting.virus.discussion)