Author Topic: c:\_RESTORE\ARCHIVE\FS82.CAB  (Read 6767 times)

0 Members and 1 Guest are viewing this topic.

rgdewar

  • Guest
c:\_RESTORE\ARCHIVE\FS82.CAB
« on: December 13, 2003, 11:28:03 PM »
I have this virus on my machine. It can't be removed, deleted, renamed or moved to a chest. Could you please help me? Thanks, R

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #1 on: December 13, 2003, 11:30:50 PM »
What virus name does it report (this is not a virus name, it's the name of the file containing the virus).

Are you sure it's the _RESTORE folder? Is it really called like this?

Can you actually see the file in the Windows Explorer?

Thanks
Vlk
If at first you don't succeed, then skydiving's not for you.

rgdewar

  • Guest
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #2 on: December 13, 2003, 11:52:35 PM »
Thanks, The virus is named " Win32:Litmus [Trj]" Appreciate any help you can give me. R

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #3 on: December 14, 2003, 12:01:40 AM »
Could you please try to answer the rest of my answers? ;)

Thanks.
Vlk
If at first you don't succeed, then skydiving's not for you.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #4 on: December 14, 2003, 12:03:34 AM »
scan here http://housecall.trendmicro.com
post the name of the virus it finds so I can look it up in the trend virus database and find removal instructions
"People who are really serious about software should make their own hardware." - Alan Kay

rgdewar

  • Guest
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #5 on: December 14, 2003, 12:52:58 AM »
Thanks, The virus is named " Win32:Litmus [Trj]" Appreciate any help you can give me. R  The file is named exactly as posted. I can't seem to find it when I open the folder. The "_" doesn't seem to exist.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #6 on: December 14, 2003, 01:05:39 AM »
ok heres what trend says

MANUAL REMOVAL INSTRUCTIONS

Click Start>Run, type Regedit then hit the Enter key.
In the left panel, double click the following:
HKEY_CURRENT_USER>Software>Microsoft
>Windows>CurrentVersion>Run
In the right panel, right-click and then delete this registry value:
LTM2 = %Windows%\Litmus\MSGSRV32.EXE
In the left panel, double click the following:
HKEY_USERS>.DEFAULT>Software>Microsoft
>Windows>CurrentVersion>Run
In the right panel, right-click and then delete this registry value:
LTM2 = %Windows%\Litmus\MSGSRV32.EXE
Reboot your computer.
Scan your system with Trend Micro antivirus and delete all files detected as BKDR_LITMUS.A. To do this Trend Micro customers must download the latest pattern file and scan their system. Other email users may use HouseCall, Trend Micro's free online virus scanner.
http://housecall.trendmicro.com

"People who are really serious about software should make their own hardware." - Alan Kay

rgdewar

  • Guest
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #7 on: December 14, 2003, 05:16:26 PM »
Thanks. Mission accomplished. I appreciate your help. R

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:c:\_RESTORE\ARCHIVE\FS82.CAB
« Reply #8 on: December 14, 2003, 05:23:20 PM »
youre welcome
"People who are really serious about software should make their own hardware." - Alan Kay