1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

system restore disabled after virus attack

Discussion in 'Windows XP' started by janhelpseeker, 2008/07/19.

  1. 2008/07/19
    janhelpseeker

    janhelpseeker Inactive Thread Starter

    Joined:
    2008/07/19
    Messages:
    16
    Likes Received:
    0
    :confused:A few weeks ago my virus scanner (e-trust) alerted me that I was being infected by a W32.benmaazen virus. System shut down, but rebooted seemingly normal, although I lost Internet connection and got crazy error messages. It took me a few days to get the system working again, after I installed Avast and Teatimer. Since then System restore is disabled (whatever I do). Changed virusscanner to latest avast (e-trust was not working anymore) and discovered in the HKEy_CURRENT_USER\...MICROSOFT...\CURRENTVERSION\RUN the file
    a58oq.exe, which I blocked with teatimer. Nevertheless all to no avail, it keeps popping up in my registry, even when regedit is open! Avast can't repair the thing seemingly and I can't get it out of my system. God knows how many files are infected. By blocking the thing with teatimer it does not (under this name) reappear in my running processes, but blocks every system restore point (only the last when rebooting). It affects also some changes in IE (resets always to 'normal safety') etc... But for the rest everything seems to be working normal. What to do???
     
  2. 2008/07/20
    BurrWalnut

    BurrWalnut Well-Known Member Alumni

    Joined:
    2003/03/05
    Messages:
    628
    Likes Received:
    8

  3. to hide this advert.

  4. 2008/07/20
    sparrow

    sparrow Inactive

    Joined:
    2004/03/21
    Messages:
    2,282
    Likes Received:
    0
    If you're running XP-Pro this page might help.
     
  5. 2008/07/21
    janhelpseeker

    janhelpseeker Inactive Thread Starter

    Joined:
    2008/07/19
    Messages:
    16
    Likes Received:
    0
    thanks BurrWalnutt, but essentialy the same

    I downloaded and ran Superantispyware, al it found was a possible trojan baring the name BF4FM.DLL, located in ...C:\WINDOWS\SYSTEM32\
    Had it quarantained, but no obvious difference in behaviour: still no repair points (only the last when I rebooted, thus today), still no possibility to alter my startup programs... Otherwise the system seems stable, it just doesn't seems to want to change some settings. (like the IE security setting)
    What to do next???

    Thanks anyway for helping me to remove 1 trojan (or son of the original one)
    But my baby still stinks.
    Jan
     
  6. 2008/07/21
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Arie,
    #5

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.