Can Vundo live in system restore?

Discussion in 'Malware Help (A Specialist Will Reply)' started by pelted, Apr 26, 2007.

  1. pelted

    pelted Private E-2

    Hello to all. Last weekend, largely due to perusing excellent advice from the archives of this forum, I cleaned an infection of the Vundo trojan from my wife's laptop running Win XP. It seemed to have defeated Avast so after running the removal tool and verifying from the HijackThis log that it was gone, I uninstalled Avast and installed AVG. I ran two versions of the tool, Symantec's and VundoFix - both verified the trojan was gone.

    Everything has been fine all week until today. AVG detected a new threat and identified it as a trojan installer. It "healed" the threat but in the logs it says that it is in a system restore folder and cannot heal it. However the trojan does not appear to be active, everything is working fine.

    I did not delete the system restore point before running the vundo removal tool. It appears that maybe somehow the trojan got into the system restore folder, AVG can't remove it, but it can't act (maybe until that restore point is used).

    My question is, can a trojan somehow get into the system restore files? Should it just be a matter of removing the system restore point, running the removal tool to ensure it does not reside on the drive, and then making a new system restore point?

    Thanks for any help.

    Dell Inspiron 1405
    Win XP MCE
    AVG - Adaware - Spybot
    PC Tools Firewall Plus
    Mozilla Firefox

    (The system had Norton AV until last week when it expired - thats how the trojan got in there in the first place I suppose)
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi


    Yes Trojans/Virii and the collective Malware can get into the system restore points but they are dormant until you restore back, if you are free from all malware then turning off system restore > reboot and scan again for malware if not found re-enable system restore with a clean restore point.
     
  3. pelted

    pelted Private E-2

    Thanks, I'm going to try it tonight.
     
  4. pelted

    pelted Private E-2

    Cool, trojan gone...It was living in the system restore files just waiting for the day when I would use system restore...


    Avast anti-virus did not detect it. AVG did.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds