Monday, May 24, 2010

I have a trojan Horse Dropper.Generic.dtk in c:_restore\temp\A0020008.cpy file. How can I get it out?

when I go into the search and find the file it is in, C:_RESTORE\TEMP\A0020008.CPY, It will not let me delete it. I'm using AVG virus scan.

I have a trojan Horse Dropper.Generic.dtk in c:_restore\temp\A0020008.cpy file. How can I get it out?
Disable System Restore and Reboot (this will purge older system restore points). After rebooting, re-enable System Restore.





For reference, see the following from Bleeping Computer





Problems with System Restore





There are some problems associated with System Restore when it comes to viruses. When restore points are created they are stored in a directory that is accessible only to the System account and not to a user. This keeps the restore points safe from misuse and tampering. Unfortunately this also means that any virus scan software you may have installed can not scan the files located there as well. This causes a problem if a file that is infected with a virus gets backed up into a restore point because now the anti-virus software can not clean it. Now if you ever restore from a restore point, that file that is infected will be introduced back into your system.





With this in mind, if you find that you are infected with a virus, hijacker, or spyware and want to make sure you do not get reinfected if you restore a restore point, you should turn System Restore off and then back on again to clear all the restore points. This will guarantee that their are no infected files that could be restored.
Reply:The problem you have is your using a very poor AV - turn off system restore %26amp; in safe mode do a online scan:


http://www.bitdefender.com/scan8/ie.html


when computer clean turn system restore back on %26amp; get a good AV
Reply:scann your pc http://www.infectedornot.com and then downloading Ad-aware





Good Luck


No comments:

Post a Comment