Author Topic: Worm..Please Help Win32: Blaxe[Wrm] and Win32: Astabar-UPX[Wrm]  (Read 4838 times)

0 Members and 1 Guest are viewing this topic.

shyes

  • Guest
Worm..Please Help Win32: Blaxe[Wrm] and Win32: Astabar-UPX[Wrm]
« on: November 19, 2004, 07:35:04 AM »
 :o To cut a long story short, i suspect that i have been dooped and sold a second hand hard-drive. Becasue I ran a recovery on it to check if it was in fact a second hand drive and anyway Avast(it rocks)  ;D detected over 100 or more files that are affected by : Win32: Blaxe[Wrm] & Win32: Astabar-UPX[Wrm]. Since then i had my computer for a month or more and i have encountered these two  >:(worms about 5 times so far, and takes me about 10 min to delete them only to surface again.

Eg. of Win32: Blaxe[Wrm] found in C:\system volume information\_restore{e786c302-cd25-4b6c-8626-33997f3e6bbb}\rp8\a0007485.exe"

Eg. of Win32: Astabar-UPX[Wrm]. found in "C:\system volume information\_restore{e786c302-cd25-4b6c-8626-33997f3e6bbb}\rp8\a0007717.exe" file.

P.S I have installed and ran Avast Virus Cleaner Tool, but to no avail. Whenever this scanner encounters a file such as the above it cannot scan it and Avast Anti Virus pops up and then i have to start deleting about 100 or more files as usuall.

Any help would be greatly appriciated  :) : ???
« Last Edit: November 19, 2004, 07:42:13 AM by shyes »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Worm..Please Help
« Reply #1 on: November 19, 2004, 07:39:14 AM »
Disable system restore, reboot and the problem is solved. ;)

shyes

  • Guest
Re:Worm..Please Help
« Reply #2 on: November 19, 2004, 07:46:03 AM »
Disable system restore, reboot and the problem is solved. ;)

Cool, If I do that would I be able to restore windows to a previous date(restore point) if I manage to somehow stuff up windows in the future.  :-\
And ah would these two worms be deleted.

Thanks heaps  :)

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Worm..Please Help Win32: Blaxe[Wrm] and Win32: Astabar-UPX[Wrm]
« Reply #3 on: November 19, 2004, 02:48:10 PM »
These are not actual worms, they are false reports caused by the way Windows is handling the system restore folder. After doing as I suggested, you can re-enable system restore, but don't be surprised if you get a new false infection warning.

Best thing to do is leave system restore disabled and create a image of the working system and after that regular backups. What good is system restore if the drive itself fails or if you can't boot Windows in anyway?

shyes

  • Guest
Re:Worm..Please Help Win32: Blaxe[Wrm] and Win32: Astabar-UPX[Wrm]
« Reply #4 on: November 20, 2004, 02:15:32 AM »
 :)Thanks heaps  ;D