Author Topic: help me please  (Read 16615 times)

0 Members and 1 Guest are viewing this topic.

ryan445

  • Guest
help me please
« on: June 14, 2007, 02:34:34 AM »
I have a unique problem. I have an hp computer with a restore partition on the main drive. It has become infected with 3 viruses. So everytime i restore my computer, the viruses come back. How do I get rid of these viruses without damaging my only source of backup? two infections are located in the system restore volume information, and if i delete them system restore never works. ARG!!!1 >:(

Spiritsongs

  • Guest
Re: help me please
« Reply #1 on: June 14, 2007, 03:04:10 AM »
 :)  Hi Ryan :

      We need to know the SPECIFIC Name of your antiVIRUS program ?

      In addition, have you used this Forum's "SEARCH" feature ? I think your
      question has been asked several times before with appropiate Responses.

ryan445

  • Guest
Re: help me please
« Reply #2 on: June 14, 2007, 03:12:21 AM »
Avast of course....lol. If you need to know the virus name it is Win32 Adware-gen

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: help me please
« Reply #3 on: June 14, 2007, 03:58:09 AM »
Which program do you use for backup?
If it is a partition image, I see no other way than restoring the partition, cleaning it, deleting the system restore points, enable system restore again, make a new partition backup...
The best things in life are free.

ryan445

  • Guest
Re: help me please
« Reply #4 on: June 14, 2007, 04:27:51 AM »
It's a standard HP restore partition, it holds a complete copy of my operating system and all programs that come with it. It's accessible through the bios.

mauserme

  • Guest
Re: help me please
« Reply #5 on: June 14, 2007, 04:53:13 AM »
What is the name of the detected file on the D: (?) partition?  Its entirely possible that the infection is one of the pre-installed programs like WeatherBug that come with HP/Compaq and Dell computers.

The detections in System Restore are not a big problem, but lets deal with the other first.

ryan445

  • Guest
Re: help me please
« Reply #6 on: June 14, 2007, 06:20:14 AM »
Win32:Adware-Gen. [Adw] That's the only virus I have. It is infecting some system restore files on the partition and some other files. And it loves to come back. Fun.

mauserme

  • Guest
Re: help me please
« Reply #7 on: June 14, 2007, 01:17:17 PM »
Quote from: ryan445 link=topic=28833.msg235888#ms
... and some other files.
Does avast! give you these file names?

eg  D:\recovery\minibug.exe
« Last Edit: June 14, 2007, 01:43:17 PM by mauserme »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: help me please
« Reply #8 on: June 14, 2007, 02:43:24 PM »
Does avast detect that partition? (I'm not sure how avast behave with hidden partitions).
Anyway, you'll be able to unhide that partition and scan it, sending to Chest the infected files. Then, hiding it again.
Try http://partitionlogic.org.uk/  8)
The best things in life are free.

mauserme

  • Guest
Re: help me please
« Reply #9 on: June 14, 2007, 02:54:50 PM »
If something from an outside source has infected the recovery partition it should be removed, but if its simply an adware program that came preinstalled it might be better to leave it alone.  A file name might help decide which action is best.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: help me please
« Reply #10 on: June 14, 2007, 03:06:13 PM »
But if its simply an adware program that came preinstalled it might be better to leave it alone.
Hmmm... Why? Are you affraid to avoid restoring of the partition if you manage it?
The best things in life are free.

ryan445

  • Guest
Re: help me please
« Reply #11 on: June 14, 2007, 06:14:39 PM »
Avast just recognizes it as drive D ands scans it with no problems. The files that are infected are A0013978.exe, A0013979.exe, CompaqPresario_Spring..., and HPPavillion_Spring06.exe These are all infected with Win:32Adware-gen. [Adw] I put everything I found in the chest already.

mauserme

  • Guest
Re: help me please
« Reply #12 on: June 14, 2007, 08:03:44 PM »
But if its simply an adware program that came preinstalled it might be better to leave it alone.
Hmmm... Why? Are you affraid to avoid restoring of the partition if you manage it?
My concern was, if this was part of an broader installation or archive file that is normal to the computer, the ability to recover other programs might be removed with the adware.  If the adware is of the more benign type that comes pre-installed on HPs its better, imo, to leave it rather than risk damaging anything.  If it is this type it would normally only reinstall to C: if requested by the user anyway.

Searching those 2 file names, however, implies there was more going on than just pre-installed junk programs. 

@ ryan - Are you sure those 2 files were found in the D: drive, or were they in System Restore?  The recovery partition and System Resore are different things.

« Last Edit: June 14, 2007, 08:05:33 PM by mauserme »

ryan445

  • Guest
Re: help me please
« Reply #13 on: June 14, 2007, 10:40:52 PM »
They are in something called system volume information/_restore then a bunch of numbers. I have 4 on the D drive and 1 on C.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help me please
« Reply #14 on: June 14, 2007, 11:39:13 PM »
The other alternative is to make a drive image of your system using something like Acronis and then you would not need the restore partition