Re: System File Restore

Tech-Archive recommends: Fix windows errors by optimizing your registry



I can assure you that the infection is not limited to two files.

Your courses of action here are: a) identify the infection (if possible) and remove it (if possible); or 2) erase the hard disk and start over.

If you're feeling brave and want to go after the bugger, we can point you to plenty of helpful resources on the web.
---
Leonard Grey
Errare humanum est

JasonH wrote:
I have a client with Windows XP Home SP2. His machine was infected with a virus that corrupted explorer.exe and svchost.exe. We have the virus quarantined and the system has been scanned to ensure no other files have been infected. I have XP SP2 on CD and would like to extract them from the CAB files. I believe the next course of action is to restore explorer.exe and svchost.exe. System Restore is not an option because the customer disabled it. However, I have not done this before. Can someone point me to an article describing how to do this? Also what CAB files are these two files located in.

You're help is greatly appreciated,

Regards,
Jason
.



Relevant Pages

  • RE: Strange servicepack.exe file (not service.exe) found.
    ... > machine that had to be rebuilt. ... Hmmmm. ... From what I've seen (online, in courses, at work, etc) ... > another infection on the affected machine. ...
    (Incidents)
  • Re: Download.Trojan?
    ... site can cause infection if certain browser vulnerabilities are not patched. ... If you are running Windows Me or Windows XP, ... remove threats in the System Restore folder. ... Symantec Security Response fully tests all the virus definitions for quality ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Backdoor.Ircbot.AV infection
    ... If you turned off System Restore, rebooted and the performed a scan and the scan was clean. ... How can it report an infected file? ... | it reported no virus infection found. ... |>- Reboot the PC ...
    (microsoft.public.security.virus)
  • Re: windows fonts corrupted
    ... Can try running to an earlier "system restore point" ... But if she has an infection, ... The fonts also display incorrectly in safe mode. ... That did not sound correct but did sound like ...
    (microsoft.public.windowsxp.general)
  • Re: Backdoor.Ircbot.AV infection
    ... it reported no virus infection found. ... >- Turn off the System Restore function ... it states I have infected files named: ...
    (microsoft.public.security.virus)