Re: w32/sdbot

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 08/15/04

  • Next message: angry and tired: "what's this now"
    Date: Sun, 15 Aug 2004 13:55:20 -0400
    
    

    Please read the following URL:
    http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

    The objective:
    ------------------
    - Turn off the System Restore function
    - Reboot the PC
    - Using your AV package, perform a full scan of all files on the platform and clean/delete
           infectors found
    - Turn on the System Restore function, and re-apply any System Restore preferences,
           e.g. HD space to use
    - Reboot the PC
    - Create a new System Restore point.

    If you have problems, it can be done manually....

    Use the WinME floppy boot disk and boot from drive "A:"
    When you get to a DOS prompt enter the following command

    attrib -r -s -h c:\_RESTORE
    rename c:\_RESTORE c:\RESTORE.old

    Reboot the PC.

    In Windows delete the folder; c:\RESTORE.old

    Please report back your results.

    Dave

    "john" <anonymous@discussions.microsoft.com> wrote in message
    news:683e01c482e5$abcd59e0$a601280a@phx.gbl...
    | i have one file(C:\restore\temp\ (a10017605.cpy)infected
    | with a worm. msafee is unable to clean this file as it is
    | write protected.any suggestions please.


  • Next message: angry and tired: "what's this now"

    Relevant Pages

    • Re: fs66.cab/generic dialer
      ... Turn off the System Restore function ... Reboot the PC ... The Cabs are archived files and I ...
      (microsoft.public.security.virus)
    • Re: Viruses in C:RestoreTemp*.cpy files that are write protected
      ... Turn off the System Restore function ... Reboot the PC ... | My McAfee antivirus software has isolated multiple viruses ...
      (microsoft.public.security.virus)
    • Re: Invalid Procedure Call or Argument
      ... annoyances), cleaned infection (with System Restore turned off?), still had ... Boot into Safe Mode and use MS Config to go into Diagnostic Mode. ... note what Services and Startups AVG ... Reboot normally, ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: RPC shutdown (not msblast)
      ... Reboot the infected PC into Safe Mode ... Re-enable System Restore and re-apply any System Restore preferences, ... | Her machine then went into a reboot cycle caused by the RPC process | termianting. ...
      (microsoft.public.windowsxp.general)
    • Re: Atheists: Americas most distrusted minority
      ... number of machines and I can't remember the last time I had to reboot (other ... another machine because a known bug in one of the updates meant that I ... move it back and do a system restore. ... didn't occur to them that eSATA drives were, well, e, and so you can't ...
      (rec.arts.sf.tv.babylon5.moderated)

  • Quantcast