Re: "TROJAN" in System Volume Information folder

From: lazaruslong (lazaruslong_at_discussions.microsoft.com)
Date: 10/30/05


Date: Sat, 29 Oct 2005 15:29:01 -0700

Thank you David; but I DID follow that procedure...four times. I also
followed the procedures you prescribed for getting rid of the NETSKY virus to
someone in this newsgroup 11/15/04, i.e. ran Sysclean and Stinger. Both to
no avail. Both report "access denied" to numerous files. Sysclean's log
reports it found 8 viruses but also reports it FAILED to clean the 8. And
Earthlink's SPYAUDIT program STILL reports the "Trojan DP" mentioned.
Any other possibilities?

-- 
lazaruslong
"David H. Lipman" wrote:
> From: "lazaruslong" <lazaruslong@discussions.microsoft.com>
> 
> < snip >
> 
> |
> | AVG’s TECH SUPPORT REPLY:
> |
> | Dear Sir/Madam,
> |
> | Thank you for your email.
> | According to your information the file is stored in System Volume
> | information folder. Also according to the file name it really is a virus
> | itself and not a correct file that has been infected.
> | Files placed in the System_volume_information folder are source files for
> | the system restore function that is available in Windows XP operating system.
> | Files that were healed were moved in their original INFECTED state into this
> | folder and it is necessary to DELETE them by following these steps:
> |
> | 1) Close all open programs. Then right-click My Computer on the Windows
> | desktop
> | 2) Click on Properties
> | 3) Click on the System Restore tab
> | 4) Check Turn off System Restore on all drives
> | 5) Restart the system
> | 6) Go through the first four steps again and uncheck the item mentioned in
> | step 4.
> |
> | Also please note that if the file is stored in this location it is not
> | possible for you to manipulate it. It is denied by your operating system. The
> | only way to remove the virus is described in the procedure above.
> |
> | OUR ORIGINAL REQUEST FOR AVG TECH SUPPORT:
> |
> 
> 
> AVG's email reply is correct.  Dump the contents of the System Restore Cache as prescribed.
> 
> Reboot the PC and then re-enable the System Restore Cache.
> 
> This will remove any latent infectors stored in the cache.
> 
> http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
> 
> -- 
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
> 
> 
> 


Relevant Pages

  • Re: Pixelsrvr.exe wont load on bootup
    ... Sounds like you got yourself a virus,. ... Adds the following line to the [windows] section of the Win.ini file: ... antivirus products, including the Symantec AntiVirus and Norton AntiVirus ... Disabling System Restore ...
    (microsoft.public.windowsxp.video)
  • Re: Is anyone experience like this? How did you removed this threat?
    ... | i'm not sure if these is the right place to post virus problems, ... | infected by backdoor these time on volume C. system restore. ... FireWall to allow it to download the needed AV vendor related files. ... This will bring up the initial menu of choices and should be executed in Normal Mode. ...
    (microsoft.public.windowsxp.general)
  • Re: virus problem
    ... > prompts me to this virus but cannot delete it. ... *not* contained only in System Restore points. ... Mode with TrendMicro's Sysclean: ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Java/Byte Verify Virus
    ... | Thanks for this David - I was looking for a solution and yours worked a treat! ... If you are using WinME or WinXP,Re-enable System Restore and re-apply any ... Got a virus that plaguing my anti-virus called ...
    (microsoft.public.security.virus)
  • Re: Windows XP Home boot problem
    ... If you have a virus, you don't want to do a System Restore because you have ... no way of knowing whether or not the SR file store is also infected. ... If not can I just do a Windows XP repair and make the laptop ...
    (microsoft.public.windowsxp.general)