LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: pastywhitegurl on June 28, 2011, 12:55:37 PM

Title: Help with clean-up after anti-virus found malware
Post by: pastywhitegurl on June 28, 2011, 12:55:37 PM
My Avira scanner found this in it's regular scan last night and performed the action noted:

QuoteVirus or unwanted program 'TR/Dropper.Gen [trojan]'
detected in file 'C:\System Volume Information\_restore{68480595-7674-485C-A152-6C9D5382B3BE}\RP1056\A0187627.exe.
Action performed: Deny access

Then Windows did an update.  After the computer rebooted,  I created a new system restore point.

I see that the malware found was in a system restore point.  I'm assuming I should delete all restore points but the one I just made.  Is that correct?  And, once I do that, is there anything else I need to do?


As always, thank you so much for your help!
Title: Re: Help with clean-up after anti-virus found malware
Post by: Corrine on June 28, 2011, 02:41:00 PM
Hi, pastywhitegurl.  Yes, that would be the best step to prevent inadvertently restoring the computer to an infected point.

First, create a fresh restore point:

1.  Click Start, click All Programs, click Accessories, click System Tools, and then click System Restore.
2.  Click Create a Restore Point, and then click Next.
3.  Name your restore point. (i.e., clean)
4.  Click the Create button.
5.  When the new restore point has been created, click Close.

Now select the files to be removed as well as all but the new restore points:
The disk clean up utility will remove the selected items.  When it completes, please restart the computer to properly record the changes made to the hard disk.

Have you run an updated scan with MBAM and/or SAS?
Title: Re: Help with clean-up after anti-virus found malware
Post by: pastywhitegurl on June 29, 2011, 02:45:05 AM
Did the clean up of old restore points as instructed.

And the MBAM scan showed everything clean.

I appreciate the help, Corrine.  Thanks!
Title: Re: Help with clean-up after anti-virus found malware
Post by: Corrine on June 29, 2011, 01:57:28 PM
You're welcome. 

I know you'll ask if you have other questions. :)