Re: Backdoor.Ircbot.AV infection

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 11/24/03


Date: Mon, 24 Nov 2003 13:14:29 -0500

Melvin:

Not knowing how the reporting is done in AVG I don't know why you still have an infected
file.

If you turned off System Restore, rebooted and the performed a scan and the scan was clean.
How can it report an infected file ?

When you re-enabled System Restore it is empty. When you created a new Restore Point it
will then have a snapshot of your PC at that time. It should be clean. So I don't know
what is happening or was is being reported.

Dave

"melvin" <anonymous@discussions.microsoft.com> wrote in message
news:02c301c3b2b4$0ed36be0$a301280a@phx.gbl...
| Hello David;
| Thanks for the quick response. I followed your
| instructions up to and including "Create a New System
| Restore Point". This went OK. When I ran the AV package,
| it reported no virus infection found. However, when I look
| in the Test Results, of the AVG package, and click on one
| of the files that is highlighted in red and click Detail
| Info, it still states I have an infected file. Please let
| me know what my my next step should be, if any. Thanks in
| advance. I really appreciate the help.
| melvin
| ------------------------------------
| >-----Original Message-----
| >Please read the following URL:
| >http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.ht
| m
| >
| >The objective:
| >------------------
| >- Turn off the System Restore function
| >- Reboot the PC
| >- Using your AV package, perform a full scan of all files
| on the platform and clean/delete
| > infectors found
| >- Turn on the System Restore function
| >- Reboot the PC
| >- Create a new System Restore point.
| >
| >If you have problems, it can be done manually....
| >
| >Use the WinME floppy boot disk and boot from drive "A:"
| >When you get to a DOS prompt enter the following command
| >
| >attrib -r -s -h c:\_RESTORE
| >rename c:\_RESTORE c:\RESTORE.old
| >
| >Reboot the PC.
| >
| >In Windows delete the folder; c:\RESTORE.old
| >
| >Please report back your results.
| >
| >Dave
| >
| >
| >"melvin" <anonymous@discussions.microsoft.com> wrote in
| message
| >news:02ce01c3b224$0fe8d5f0$a301280a@phx.gbl...
| >| Hello;
| >| AVG Antivirus informed me that my machine was infected
| >| with the subject virus. I suspect it got into my machine
| >| because I had not updated the virus file. I am running
| >| Windows ME so I did a System Restore to an earlier date
| >| which seems to got rid of it. When I look in the Test
| >| Results in AVG, it states I have infected files named:
| >| C:\_Restore\Temp\A0149115 and A0149116. Was it an OK
| >| procedure to use System Restore? Should I delete the
| >| infected files or just leave them alone? As far as I can
| >| determine my machine runs OK. Thanks for you help in
| >| advance.
| >
| >
| >.
| >



Relevant Pages

  • Re: Unable to do system restore
    ... it failed with an unknown error and I had to reboot. ... Tried a system restore to yesterday which appeared to work until the ... that restore point and all others made after the initial infection. ...
    (microsoft.public.windowsxp.basics)
  • Re: Download.Trojan?
    ... site can cause infection if certain browser vulnerabilities are not patched. ... If you are running Windows Me or Windows XP, ... remove threats in the System Restore folder. ... Symantec Security Response fully tests all the virus definitions for quality ...
    (microsoft.public.windowsxp.security_admin)
  • Re: cant get rid of anti-spyware or message
    ... | goes on to say theres possible harmful infection and click here to DL ... On Win9x/ME platforms the report will not be shown in your bowser ... It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML ...
    (microsoft.public.windowsxp.security_admin)
  • Chemical Reaction May Have Caused Eye Infections
    ... Officials also believe the fungal contamination occurred in patients' ... After the same research team came out with a preliminary report in May, ... For the 34 million contact lens wearers in the United States, ... an infection that can lead to blindness or the ...
    (sci.med.vision)
  • Re: windows fonts corrupted
    ... Can try running to an earlier "system restore point" ... But if she has an infection, ... The fonts also display incorrectly in safe mode. ... That did not sound correct but did sound like ...
    (microsoft.public.windowsxp.general)