Author Topic: Virus infected system files  (Read 3701 times)

0 Members and 1 Guest are viewing this topic.

Frank1

  • Guest
Virus infected system files
« on: April 14, 2009, 11:27:14 AM »
I downloaded a file that was passed by the current Avast checker, both in the .rar and .exe states. The computer was fine up to this point. When I executed this file Avast came up with .sys files having  viruses and suspecting the .exe file doing some funny things I told Avast to place those files into the virus vault.

I managed to close the .exe but the pc was slow so switched it of and tried to reboot. I am now unable to boot, I get a critical error when I try to boot in, normal, last good known or safe mode.

I am now unable to do system restore because I can't boot. What can do is boot my BartPE CD. This is how I am writing this post. I looked in the virus chest with windows explorer and can see the files that have been moved in there, but the filenames are changed to some alpha numeric. So, I can't move them back to windows\system32 folder.

What can I do to restore my computer?
Help would be appreciated.

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3695
  • If at first you don’t succeed; call it version 1.0
Re: Virus infected system files
« Reply #1 on: April 14, 2009, 12:31:19 PM »
Do you happen to have the Windows disk that came with the OS? (or any Windows disk of the same OS, in order to perform a repair install?)
What was the program downloaded, and where from?
Sounds like it may have been harbouring something a bit untoward.
Windows 10,Windows Firewall,Firefox w/Adblock.

Frank1

  • Guest
Re: Virus infected system files
« Reply #2 on: April 14, 2009, 12:47:28 PM »
Well, yes and no. I originally installed from a Windows XP Pro SP2. Since then SP3 came out and I installed it and slip streamed a cd with SP3. So, now I have a Windows XP Pro SP3. If this cd is considered the original, then I have it.

However, I would have preferred to repair by some sort of System Restore. Since I am not convinced that the 6 .sys files placed in the vault have viruses, if I could restore the .sys files in the virus vault, I think it would work. Is there a way to launch the Virus Vault window from Avast while running BartPE?
Thanks

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Virus infected system files
« Reply #3 on: April 14, 2009, 02:18:25 PM »
Is there a way to launch the Virus Vault window from Avast while running BartPE?
I don't think so.
You'll need to copy the Chest contents to another computer, replace the Chest of this clean computer with the other one, open avast, open Chest and then restore the files to a safe folder (USB drive?). Then move the files to the original place. But, if they're really infected, I don't see much reason to do that. Maybe overinstalling Windows.
The best things in life are free.

Frank1

  • Guest
Re: Virus infected system files
« Reply #4 on: April 14, 2009, 11:10:29 PM »
I think my problem is bigger than I thought. Just noticed in BartPE that it refuses to access my C: drive. It says that file or drive is corrupted. It looks like a restore install wouldn't work now.
It looks like I will have to reinstall windows from scratch.

Frank1

  • Guest
Re: Virus infected system files
« Reply #5 on: April 15, 2009, 11:12:16 AM »
Realized I had a image backup. Restored that, it's a little old but works fine.
Thanks for all the help here.