Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Win32.Trojan.Spy found in System Restore  (Read 3110 times)

0 Members and 1 Guest are viewing this topic.

black069

    Topic Starter


    Greenhorn

    Win32.Trojan.Spy found in System Restore
    « on: March 22, 2009, 02:09:10 AM »
    I was looking at the statistics in Ad-Aware AE today because I was going to remove the program.  However, I noticed (for the first time) that it had found malware several weeks ago.  I must have it set to automatically handle any bugs...not sure.  Obviously, the reason no other scans (AVG, Malwarebytes, SAS, and Ad-Aware AE itself) have found the bug is b/c it's in Ad-Aware's quarantine. 

    I think in a normal situation, I would just remove/delete the bug from the quarantine for good.  But the difference here is the location of the original files that were infected (see below).  They appear to be System Restore files.  Does that mean that all of my system restore points have been infected?  And, if so, do I need to, after removing the bug from the computer, turn off system restore, reboot, and then turn system restore back on? 

    I haven't been necessarily having any more problems than usual. My system standby/hibernate does not work (you can see my only other topic on Computer Hope, which unsuccessfully deals with that), but that has been going on for quite a while.

    I cut and paste the following from a log file from Ad-Aware AE scan dated 2/4/09:
    Quarantined items:
    Description: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1149\A0148857.scr Family Name: Win32.Trojan.Spy Clean status: Success Item ID: 536469 Family ID: 983
    Description: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1149\A0148889.dll Family Name: Win32.Trojan.Spy Clean status: Success Item ID: 536469 Family ID: 983


    Please let me know if you need any further info, etc.
    My system information is beside my profile.
    Thanks in advance.

    Karnac



      Specialist

      Thanked: 211
      Re: Win32.Trojan.Spy found in System Restore
      « Reply #1 on: March 22, 2009, 09:26:35 AM »


      Never argue with a stupid person, they'll drag you down to their level and beat you with experience.