Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Information > virus problem

Reply
Thread Tools

virus problem

 
 
zxcv
Guest
Posts: n/a
 
      04-28-2004
My virus scanner (AVG) keeps finding a virus in a bunch of files of the
format C:\_RESTORE\TEMP\A0253128.CPY that it cannot move to vault. I also
cannot delete the files, even in safe mode. What gives?


 
Reply With Quote
 
 
 
 
The Prophecy
Guest
Posts: n/a
 
      04-28-2004
zxcv wrote:
> My virus scanner (AVG) keeps finding a virus in a bunch of files of
> the format C:\_RESTORE\TEMP\A0253128.CPY that it cannot move to
> vault. I also cannot delete the files, even in safe mode. What
> gives?


Try disabling System Restore:

For Windows ME:
http://support.microsoft.com/default...b;en-us;264887

For Windows XP (Home or Pro):
http://www.microsoft.com/technet/com.../faqsrwxp.mspx

If you are using a different version of Windows, System Restore is not
available.


 
Reply With Quote
 
 
 
 
The Prophecy
Guest
Posts: n/a
 
      04-28-2004
zxcv wrote:
> "The Prophecy" <> wrote in message
> news:_WCjc.36295$NG2.3227@edtnps84...
>> zxcv wrote:
>>> My virus scanner (AVG) keeps finding a virus in a bunch of files of
>>> the format C:\_RESTORE\TEMP\A0253128.CPY that it cannot move to
>>> vault. I also cannot delete the files, even in safe mode. What
>>> gives?

>>
>> Try disabling System Restore:
>>
>> For Windows ME:
>> http://support.microsoft.com/default...b;en-us;264887
>>
>> For Windows XP (Home or Pro):
>> http://www.microsoft.com/technet/com.../faqsrwxp.mspx
>>
>> If you are using a different version of Windows, System Restore is
>> not available.
>>
>>

>
> Bingo. Thanks.


You're welcome.


 
Reply With Quote
 
zxcv
Guest
Posts: n/a
 
      04-28-2004

"The Prophecy" <> wrote in message
news:_WCjc.36295$NG2.3227@edtnps84...
> zxcv wrote:
> > My virus scanner (AVG) keeps finding a virus in a bunch of files of
> > the format C:\_RESTORE\TEMP\A0253128.CPY that it cannot move to
> > vault. I also cannot delete the files, even in safe mode. What
> > gives?

>
> Try disabling System Restore:
>
> For Windows ME:
> http://support.microsoft.com/default...b;en-us;264887
>
> For Windows XP (Home or Pro):
> http://www.microsoft.com/technet/com.../faqsrwxp.mspx
>
> If you are using a different version of Windows, System Restore is not
> available.
>
>


Bingo. Thanks.


 
Reply With Quote
 
Plato
Guest
Posts: n/a
 
      04-28-2004
zxcv wrote:
>
> My virus scanner (AVG) keeps finding a virus in a bunch of files of the
> format C:\_RESTORE\TEMP\A0253128.CPY that it cannot move to vault. I also
> cannot delete the files, even in safe mode. What gives?


Anti-virus cant deal with MS proprietary _restore files. Disable restore
and delete the restore files if the pc doesnt do it automagically. Then
run your anti-virus.


--
http://www.bootdisk.com/
 
Reply With Quote
 
Thor
Guest
Posts: n/a
 
      04-28-2004

"Plato" <|@|.|> wrote in message
news:408f3d2c$0$96429$...
> zxcv wrote:
> >
> > My virus scanner (AVG) keeps finding a virus in a bunch of files of the
> > format C:\_RESTORE\TEMP\A0253128.CPY that it cannot move to vault. I

also
> > cannot delete the files, even in safe mode. What gives?

>
> Anti-virus cant deal with MS proprietary _restore files. Disable restore
> and delete the restore files if the pc doesnt do it automagically. Then
> run your anti-virus.


I don't think it's a problem with being proprietary. Rather it's because
those files are *protected* system files, and windows will not allow an
outside program to manipulate them. At least that's what I understand it to
be.



 
Reply With Quote
 
Plato
Guest
Posts: n/a
 
      04-29-2004
Thor wrote:
>
> > Anti-virus cant deal with MS proprietary _restore files. Disable restore
> > and delete the restore files if the pc doesnt do it automagically. Then
> > run your anti-virus.

>
> I don't think it's a problem with being proprietary. Rather it's because
> those files are *protected* system files, and windows will not allow an
> outside program to manipulate them. At least that's what I understand it to
> be.


OK, lets assume, for example, that we have a perfectly friendly fat32
system with Me installed, which has _restore files. Of course one can
boot to dos with a bootdisk and then run F-Prot for dos. My recollection
is that F-Prot can ID a nasty in a _restore, but cant deal with it.
Since windows is not running, it cant be protected by windows right? ie
all files are fair game in dos unless its a proprietary form of
compression or other.
 
Reply With Quote
 
Thor
Guest
Posts: n/a
 
      04-29-2004

"Plato" <|@|.|> wrote in message
news:4090737c$0$1731$...
> Thor wrote:
> >
> > > Anti-virus cant deal with MS proprietary _restore files. Disable

restore
> > > and delete the restore files if the pc doesnt do it automagically.

Then
> > > run your anti-virus.

> >
> > I don't think it's a problem with being proprietary. Rather it's because
> > those files are *protected* system files, and windows will not allow an
> > outside program to manipulate them. At least that's what I understand it

to
> > be.

>
> OK, lets assume, for example, that we have a perfectly friendly fat32
> system with Me installed, which has _restore files. Of course one can
> boot to dos with a bootdisk and then run F-Prot for dos. My recollection
> is that F-Prot can ID a nasty in a _restore, but cant deal with it.
> Since windows is not running, it cant be protected by windows right? ie
> all files are fair game in dos unless its a proprietary form of
> compression or other.


Well, it may be that AV software can't remove the infected file from the
archive without screwing it up. And it can't very well just delete the file,
because they are tied to index files that would also screw up the restore
process. Seems to me that if they are using a proprietary or otherwise
unidentifiable type of compression, then the AV ware wouldn't be able to
scan, detect, and identify virus infected files within it. If the AV ware
can read and discern the files within, then it should be able to delete
those files, or deal with them. But to remove the infection in those files
would probably also require removal of some legitemate uninfected files that
are linked to the infected ones in the archive, (for example taking out the
whole restore point) and they just don't take that extra agressive step.
Pure speculation, of course, but I can't see how being too proprietary can
be the main issue when the reading the files within it are obviously well
within the AV-ware's capabilities.


 
Reply With Quote
 
Plato
Guest
Posts: n/a
 
      04-29-2004
Thor wrote:
>
> would probably also require removal of some legitemate uninfected files that
> are linked to the infected ones in the archive, (for example taking out the
> whole restore point) and they just don't take that extra agressive step.


Thats not how f-prot works tho. It always cleans ie it doesn't delete
any files except for files that are 100% virus. Most viruses attach
themselves to the end of a file. What f-prot does to clean it is snip
off the virus and a few bits off the end of the legit file. If a virus
was embedded withing a file, then it has to some sort of compression or
whatever that put some files together so f-prot cant clean it. As you
say, yeah, if the virus was withing a restore point and you took it out,
yeah, you'd take out the whole restore point I agree.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
virus or not virus Dangermouse Computer Support 5 10-13-2005 01:57 PM
SWsoft Acronis Disk Director Suite 9.0 Build 508, Acronis OS Selector 8.0 Build 917, Acronis Partition Expert 2003 Build 292, Acronis Power Utilities 2004 Build 502, F-SECURE.ANTI vIRUS.PROXY v1.10.17.WINALL, F-SECURE.ANTI vIRUS v5.50.10260 for CITRI vvcd Computer Support 0 09-25-2004 01:38 AM
VIRUS VIRUS VIRUS m II DVD Video 4 07-25-2004 02:07 AM
Virus in virus? DS Computer Support 3 02-08-2004 09:30 AM
Virus, Virus, Virus..... Phil B Computer Support 2 09-22-2003 05:02 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57