Safe Mode - Backdoor

From: MichelleT (anonymous_at_discussions.microsoft.com)
Date: 02/12/04


Date: Wed, 11 Feb 2004 16:39:48 -0800

What does safe mode mean? Is this when you turn system
restore off?
My file C:\WINDOWS\SYSTEM\svchost.exe is infected with
the Backdoor.IRC.RPCBot.D virus. I have ran NAV and
stinger and they both state that it is unable to
eliminate the virus. In both cases, system restore was
turned off. In the case of NAV, I updated virus
definitions. Nothing has worked. Has anyone else
encountered this problem.
IS IT POSSIBLE TO DELETE THE SVCHOST.EXE FILE? WHAT
WOULD HAPPEN IF I DID THIS?



Relevant Pages

  • xp and NAV2002
    ... Why would you want to repair a virus file? ... >They are quarantined but NAV says unable to repair them, ... >fixable or NAV is corrupt by a virus already? ... >scan with boot disc and also Restore off. ...
    (microsoft.public.windowsxp.security_admin)
  • "Help & Support" Does Not Work !
    ... a virus. ... I wanted to "restore" my system to a previous checkpoint ... Then I went to send an email (I'm running MSN Premium) ... Then I tried re-running NAV which gives me all sorts ...
    (microsoft.public.windowsxp.general)
  • HELP & SUPPORT Do Not Work !!
    ... a virus. ... I wanted to "restore" my system to a previous checkpoint ... Then I went to send an email (I'm running MSN Premium) ... Then I tried re-running NAV which gives me all sorts ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Cant Run Task Manager or MSCONFIG.exe
    ... Let nortons do it thing. ... Also your going to need to turn system restore off, reboot, then turn system ... this cause the restore points hold the virus as well. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: xp and NAV2002
    ... Suz said "I am still getting viruses through my email even though I have ... but no attachement is worth a virus. ... > They are quarantined but NAV says unable to repair them, ... > scan with boot disc and also Restore off. ...
    (microsoft.public.windowsxp.security_admin)