Thread: Weird Virus
View Single Post
  #18 (permalink)  
Old 09-November-2007, 02:52 PM
Moose's Avatar
Moose Moose is offline
Senior Member
 
Join Date: Nov 2002
Location: The Maritimes
Posts: 7,825
Send a message via MSN to Moose
Default

Sounds like Windows System Restore again. It's supposed to keep a backup of a successful system state and restore it if anything makes an unauthorized change. The problem is that it's very easy for malware to get into the backup.

I had to clean a XP (first flight) system where the user had been trying to delete a virus, only to have it reappear on every reboot. Before I discovered System Restore's role in this, I deleted the virus, then "touched" a file with the same name. (I just renamed a notepad text file.) I did this on the hypothesis that whatever was replacing the virus might not be doing the full CRC check and only looking to see if the dll "existed". It worked.

The short answer is: try turning off Windows System Restore. You can get it by going into your partition properties (my computer, right click on the drive letter, select properties), and reverse the tick-box that says to allow system restore to work on that drive.

Reboot, then undo the read-only attribute for the folder. You can then turn the system restore tick-box back on if you want that feature. I never do.
__________________
. o O ( "Quote that 'Blazing Saddles' scene at Mike, and the BAUTer gets it! " )
Reply With Quote