📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Virus advice please

Options
I've recently switched to using AVG free anti-virus (dumped Norton) and this morning it picked up on a trojan virus - PSW.Perfect.B - which was embedded in four of my system files on drive E (a partitioned part of my HD) which hasn't been used for several weeks since doing a fresh install of XP on drive C, so the virus must have been sat there for some time and was never picked up by Norton :mad:

I disabled system restore then scanned the whole HD again but they had disappeared!!!! :eek: ... scan came back as no virus found :confused:

AVG hadn't healed or deleted them during the first scan because they were embedded in the system so I can't understand where they've gone. Any ideas please?
"An Ye Harm None, Do What Ye Will"
~
It is that what you do, good or bad,
will come back to you three times as strong!

Comments

  • blinky
    blinky Posts: 1,684 Forumite
    Part of the Furniture Combo Breaker
    Sounds like the trojan was in system restore files.

    When you disable system restore on a drive it deletes all system restore files on that partition.

    If norton wasn't set to do a full scan it probably wouldn't have picked up the ones in system restore (the realtime scanner only scans files when they are used).
    Hug provider for depression thread :grouphug:
    "I'm not crazy, I'm just a little unwell.." - Unwell by Matchbox Twenty
  • Curry_Queen
    Curry_Queen Posts: 5,589 Forumite
    1,000 Posts Combo Breaker
    So should I re-run a scan now that I've re-enabled system restore to see if they are still there? ... and if they are, what can I do to get rid of them?

    I'm planning to reformat that part of the HD pretty soon anyway, once I've finished retrieving any data that I need from it. I'm just worried about possibly transferring the virus across to the partition I'm currently using though :confused:

    Just a thought, but would it be safer to keep system restore on drive E disabled to prevent the virus being activated?
    "An Ye Harm None, Do What Ye Will"
    ~
    It is that what you do, good or bad,
    will come back to you three times as strong!

  • I could be wrong but I am pretty sure that when you disable system restore ( to run a virus check for instance) that the restore file gets deleted.

    A new one is made when you restart the system restore function.

    This could be why they weren't found.
  • alanrowell
    alanrowell Posts: 5,386 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    I thought that when you disabled System Restore all your backups were deleted so assuming that to be true you should be able to turn SR back on with no problems
  • blinky
    blinky Posts: 1,684 Forumite
    Part of the Furniture Combo Breaker
    Yes, disabling system restore, deletes the restore files. I've edited my original reply to reflect this. Sorry for any confusion.
    Hug provider for depression thread :grouphug:
    "I'm not crazy, I'm just a little unwell.." - Unwell by Matchbox Twenty
  • Curry_Queen
    Curry_Queen Posts: 5,589 Forumite
    1,000 Posts Combo Breaker
    Ok, thanks for all your help ... fingers crossed it's gone now :)
    "An Ye Harm None, Do What Ye Will"
    ~
    It is that what you do, good or bad,
    will come back to you three times as strong!

  • mr_pinkle
    mr_pinkle Posts: 16 Forumite
    I also had this problem last night. I could take a wild guess but could anyone explain exactly what System restore is and how to disable/enable it? Don't like messing around with things that I don't know anything about!
  • System restore is a part of the Windows system which takes a snapshot of your computer and allows you to revert back if necessary. You get to it by start>programs>accessories>system tools>system restore. Sometimes virusses get into the part of the hard disk which holds this snapshot and the only way of getting rid of it is to disable system restore. This purges the snapshot from your system, get rid of the virus and when clean turn restore back on. Its got me out of trrouble a few times.(you turn of by using the system restore settings box in the bit above.
    Down south where, unfortunately, the government does remember us.
  • Just a thought, but do you have any other AV programs? I also use AVG Free, but it doesn't always pickup Viruses and other Malware. I would reccomend that you also install a back up anti-virus, and run this scan straight after the AVG scan, which should be done at least once a week. Although this will take quite a bit of time, it's well worth it, as the second program should pick up anything AVG misses. I also use Ad-Aware SE, which is free as well. This can do a general virus scan, and can also be set to target Adware programs, which can be hard to shift.
    To get rid of some of these programs, such as Prevadkeep.exe, you may need other software. Beacuse Prevadkeep runs as a system process, the anti-virus programs cannot access it to delete it. Hijackthis (available free also - do a google for it) can 'grab' programs running as a process, and kill then delete them.
    Be VERY careful when deleting system processes, and if you're not sure what it does, leave it alone. Visit a tech forum for more advice on whether or not it should be removed.
    I haven't been asked to tell you that I'm the [highlight]Board Drunk[/highlight] for this board. As the night wears on, my posts will become worse, with simple spelling mistakes, inane ramblings, and a blatant disregard for the truth. I have no authority to do anything, so there's no point asking or telling me. If you see me past midnight, please tell me to get my coat and order me a taxi.

    Free Ebay Simple Profit/Loss Spreadsheet. PM me for a download link.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.2K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.3K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.