Re: DUMARU worm

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/22/04


Date: Sat, 21 Feb 2004 20:18:55 -0500

Please read the following URL:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

The objective:
------------------
- Turn off the System Restore function
- Reboot the PC
- Using your AV package, perform a full scan of all files on the platform and clean/delete
       infectors found
- Turn on the System Restore function, and re-apply any System Restore preferences,
       e.g. HD space to use
- Reboot the PC
- Create a new System Restore point.

If you have problems, it can be done manually....

Use the WinME floppy boot disk and boot from drive "A:"
When you get to a DOS prompt enter the following command

attrib -r -s -h c:\_RESTORE
rename c:\_RESTORE c:\RESTORE.old

Reboot the PC.

In Windows delete the folder; c:\RESTORE.old

Please report back your results.

Dave

"down on DUMARU worm" <anonymous@discussions.microsoft.com> wrote in message
news:146b801c3f8de$e1664530$a401280a@phx.gbl...
| how do I get rid of this worm. It is in
| c:\_RESTORE\TEMP\A0085862.
|
| It wont let me delete it. Is there a way and if there is
| how.
|
| Really appreciate any help
|
| B



Relevant Pages

  • Re: fs66.cab/generic dialer
    ... Turn off the System Restore function ... Reboot the PC ... The Cabs are archived files and I ...
    (microsoft.public.security.virus)
  • Re: Viruses in C:RestoreTemp*.cpy files that are write protected
    ... Turn off the System Restore function ... Reboot the PC ... | My McAfee antivirus software has isolated multiple viruses ...
    (microsoft.public.security.virus)
  • Re: Invalid Procedure Call or Argument
    ... annoyances), cleaned infection (with System Restore turned off?), still had ... Boot into Safe Mode and use MS Config to go into Diagnostic Mode. ... note what Services and Startups AVG ... Reboot normally, ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: RPC shutdown (not msblast)
    ... Reboot the infected PC into Safe Mode ... Re-enable System Restore and re-apply any System Restore preferences, ... | Her machine then went into a reboot cycle caused by the RPC process | termianting. ...
    (microsoft.public.windowsxp.general)
  • Re: Atheists: Americas most distrusted minority
    ... number of machines and I can't remember the last time I had to reboot (other ... another machine because a known bug in one of the updates meant that I ... move it back and do a system restore. ... didn't occur to them that eSATA drives were, well, e, and so you can't ...
    (rec.arts.sf.tv.babylon5.moderated)

Quantcast