Computer Security & Viruses/AVG finds virus but doesn't remove it

Advertisement


Question
Hi,

My AVG program finds the IRC/BackDoor.SdBot virus, and tells me it is in the file...

C:\System Volume Information\_restore{891528B5-F29F-44D7-A53C-44C38CC7AC8C8}\RP266\A0082261.exe

It then says...

To remove this virus, please run AVG for windows

...but when I run AVG it doesn't find it. Any ideas? I've tried other Anti-Virus software (Panda, TDS-3) with no success.


Thanks

Answer
Thank you for giving such detailed information. It turns out that the problem is that your antivirus program misinformed you. The virus is hiding in System Restore. No antivirus program can remove anything from System Restore unless you first disable it.

How to disable or enable System Restore in Windows ME:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDo...

How to disable or enable System Restore in Windows XP:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDo...

After disabling System Restore, run your antivirus program. Once it has removed the virus you can reactivate System Restore.

Computer Security & Viruses

All Answers


Answers by Expert:


Ask Experts

Volunteer


Carolyn Meinel

Expertise

I cover Windows, Linux, TCP/IP and Ethernet security questions. I do not cover Mac, smart phones, or other networking issues.

Experience

Books by Carolyn Meinel: wrote a chapter for The Hacking of America book (see http://www.amazon.com/exec/obidos/ASIN/1567204600/happyhacker) My article Code Red for the Web for Scientific American was reprinted in the book Best American Science Writing 2002 (see http://www.amazon.com/exec/obidos/ASIN/0060936509/happyhacker). My book The Happy Hacker: A Guide to Mostly Harmless Hacking is now in 4th edition with a Japanese edition (see http://happyhacker.org/hhbook/).

Organizations
IEEE, AAAS

Publications
See a list with some online links at http://cmeinel.com

Education/Credentials
MS, Industrial Engineering, The University of Arizona Took a course in computer forensics at the University of Texas at Austin/

Past/Present Clients
DARPA, SAIC, Palmer Labs

©2012 About.com, a part of The New York Times Company. All rights reserved.