Author Topic: some help on A00647896.exe safe removal  (Read 7782 times)

0 Members and 1 Guest are viewing this topic.

yankanuk

  • Guest
some help on A00647896.exe safe removal
« on: August 09, 2004, 06:54:03 PM »
Hi,
I keep getting this alert when running my Avast! It is found in:
C:\system volume information\_restore{279652C7-28D4-4A08-94C8-5555A2
Virus description: Win32:Trojan-gen. {other}

I've been reading posts and it says to disable system restore and then reboot. BUT, I am using a Beta version of SP2 and there is a restore point  that will let me revert back to the SP1. So I'm leary about that. Is there any way of removing the problem without losing my restore point?
Windows XP version:6.02900.2149.xpsp_sp2_rc2.040610-1520
Avast free home edition

Thanks,
Peter

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:some help on A00647896.exe safe removal
« Reply #1 on: August 09, 2004, 07:02:29 PM »
Just disable system restore (info) and you will be fine.
Remember that SP2, although it is about to be released, still has many issues  :-\

And as MS says "don't use SP2 in a operational environment"

yankanuk

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #2 on: August 09, 2004, 07:07:40 PM »
Just disable system restore (info) and you will be fine.
Remember that SP2, although it is about to be released, still has many issues  :-\

And as MS says "don't use SP2 in a operational environment"

Ok,, for my next question, is that trojan-gen harmfull to my system?
Oh, by the way, I've used SP2 for almost 2 months now and it is much superior to SP1 and I didn't bother using the windows firewall, I use Sygate.

Now, if I turn off system restore and reboot...when I turn on system restore, will I still have that trojan?
Thanks,
Peter

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48839
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re:some help on A00647896.exe safe removal
« Reply #3 on: August 09, 2004, 07:10:41 PM »
Hi yankanuk
The infected files are in one of the restore points on your system. To get rid of the virus notification, you have to clear the system restore points and the AFTER A REBOOT, RESTART system restore.
Just follow the instructions: Disable SystemRestore
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

whocares

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #4 on: August 09, 2004, 07:14:48 PM »
(from: Bagmaster50 on avast)

There is a way to get into the system volume information folder and delete singly restore points.
1st, open folder options, view, hidden files and folders, check show all files and folders.
2nd, turn off simple file sharing, click apply and then close the folder options.
3rd, browse to the C:/system volume information folder, right click on it, select properties. You'll now see a Security tab, click on it.
4th, On the security page under Group or users names click on "add", on the Select Users or Groups page that opens type in your user name in the enter window then click on check Names button to verify the name with. Now click on the ok button.
5th, now you can give yourself full control in the Permissions window, click apply and you're done.
Now you can turn back on simple file sharing and still be able to open the system volume information folder.

yankanuk

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #5 on: August 09, 2004, 07:22:18 PM »
(from: Bagmaster50 on avast)

There is a way to get into the system volume information folder and delete singly restore points.
1st, open folder options, view, hidden files and folders, check show all files and folders.
2nd, turn off simple file sharing, click apply and then close the folder options.
3rd, browse to the C:/system volume information folder, right click on it, select properties. You'll now see a Security tab, click on it.
4th, On the security page under Group or users names click on "add", on the Select Users or Groups page that opens type in your user name in the enter window then click on check Names button to verify the name with. Now click on the ok button.
5th, now you can give yourself full control in the Permissions window, click apply and you're done.
Now you can turn back on simple file sharing and still be able to open the system volume information folder.

Thanks for all that info, sure appreciate it. But what I was told to do was turn off system restore. What I really need to know is...will that trojan-gen return after I turn system restore back on.
Thanks

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:some help on A00647896.exe safe removal
« Reply #6 on: August 09, 2004, 07:23:54 PM »
Not the exactly same, but yes, it is very likely you will get again this false positive

yankanuk

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #7 on: August 09, 2004, 07:25:21 PM »
Not the exactly same, but yes, it is very likely you will get again this false positive

So my final question....is this trojan-gen harmfull to my system?

whocares

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #8 on: August 09, 2004, 07:32:12 PM »
Hi eddy,

how would you know that this is a false positive ?? Or that he will get it again ?

yankanuk should
- upate avast & reboot and rescan
- tell us where (if at all) the trojan was found outside the  RESTORE-folder -> avast's reports/logs and XP's event-Log need to be examined..







« Last Edit: August 09, 2004, 07:33:07 PM by whocares »

yankanuk

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #9 on: August 09, 2004, 07:34:08 PM »
Thanks for all the replies,
I'm gonna up-date and reboot and then re-scan and post back what's going on,
Thanks

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48839
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re:some help on A00647896.exe safe removal
« Reply #10 on: August 09, 2004, 07:40:15 PM »
yankanuk
Quote
Thanks for all that info, sure appreciate it. But what I was told to do was turn off system restore. What I really need to know is...will that trojan-gen return after I turn system restore back on.
Thanks
Turning System Restore off, clears the restore points from your computer.
If the virus or trojan is still on your system and again winds up in a restore point, before you get rid of it, then, you would be back to where you started.
Clear system restore. Makes sure the virus is gone and then restart system restore and create a clean restore point.
Hope that's clear.
« Last Edit: August 09, 2004, 07:41:38 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

yankanuk

  • Guest
Re:some help on A00647896.exe safe removal
« Reply #11 on: August 09, 2004, 09:57:45 PM »
yankanuk
Quote
Thanks for all that info, sure appreciate it. But what I was told to do was turn off system restore. What I really need to know is...will that trojan-gen return after I turn system restore back on.
Thanks
Turning System Restore off, clears the restore points from your computer.
If the virus or trojan is still on your system and again winds up in a restore point, before you get rid of it, then, you would be back to where you started.
Clear system restore. Makes sure the virus is gone and then restart system restore and create a clean restore point.
Hope that's clear.

Hi, Thanks for the reassuring help. I did what you said and then did a new virus scan and so far there is no virus yet....touch wood!
Thanks,
Peter

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48839
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re:some help on A00647896.exe safe removal
« Reply #12 on: August 09, 2004, 11:12:03 PM »
yankanuk
Your welcome. Nothing nicer than a clean system. Keep your operating system and Avast! uptodate at all times and it should stay that way.
Providing you surf sensibly. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet