Help - Search - Members - Calendar
Full Version: Trojan Horse infection in Restore
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
m229242
Can you help?

A window popped up recently to inform me that there was a Trojan Horse 'downloader.swizzor.2.bg' lurking in my machine. It's location is

c:\system volume information\_restore{94784957-b9ec-48ba-b152-ff97520e84b8}\rp97\a0030635.exe.

Have run AVG anti-virus but it didn't find any virus infection.

How can I tell if there really is a problem?

Kevin.
Hunter
What is System Restore?

One of the new features of Windows Me and Windows XP is System Restore. This feature, which is enabled by default, is used by Windows to restore files on your computer in case they become damaged. If you experience a problem with your system that is caused by software, System Restore gives you the opportunity to go back to a point where things were working correctly.

Windows XP stores this information in the SYSTEM VOLUME information folder. These folders are updated when the computer restarts.

NOTE: Both the _RESTORE folder in WinME and the System volume information folder in Win XP are marked with the hidden attribute, and, by default, Windows is set to not display such files or folders.

Even after you have found a virus and your AV has cleaned your PC you still might get an indication you still have the virus but it can not be deleted in these folders.

Problem is..the system restore also has a copy of all those virus and trojans that have infected your system. They are in a compressed mode...your ANTIVIRUS knows they are there but can not help you get rid of them, so you must do it manually.

GO TO THE FIRST LINK AND FOLLOW THE SCREEN SHOTS TO GET RID OF THIS IN THE "SYSTEM VOLUME" INFO FOLDER THE SECOND LINK WILL DO IT FOR WIN ME IN THE "_RESTORE FOLDER".


NAME: Disabling System Restore on Windows XP
ALIAS: Disabling Windows XP AutoRestore feature


http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml

NAME: Disabling System Restore on Windows ME
ALIAS: Disabling Windows ME AutoRestore feature

http://www.europe.f-secure.com/v-descs/sfc_dis.shtml

also if you are not using the new free AVG 7 but still the version 6..get rid of it and get the new version 7
Hunter
This is information on where to get the new version..do not wait till the last minute..and when you do install the new version it will uninstall the old AVG 6 during the install process..
http://forum.gladiator-antivirus.com/index...showtopic=19735
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.