Kaspersky online found this

Discussion in 'Malware Help (A Specialist Will Reply)' started by jak3y, Dec 8, 2005.

  1. jak3y

    jak3y Guest

    (attached log)
    Was surprised considering this isn't a bootable drive, but rather backup stuff (for music, pics, etc).
    Apparently Kaspersky free AV cleaner is no longer available so can't use that to clean it up.
    Any suggestions?
    (yes i did the stickies, always do :p)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All those items are in a System Restore folder! System Restore should be disabled. If it is and the files still exist, boot into safe mode and delete the files manually.
     
  3. jak3y

    jak3y Guest

    Even if there isn't any bootable system information on that partition?
    It's just where i store photos, music, documents.
    I thought sys.res., was only for OS related issues (registry, cab, exe, dll-files, etc)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was this secondary drive ever used as a main boot drive in a system?
     
  5. jak3y

    jak3y Guest

    Never, brand spanking new, as my multimedia stuff. 200gigs (4 partitions)
    C: (OS) drive is my old 40gig drive.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. jak3y

    jak3y Guest

    Well Chas' I'm home and funny enough, I can't access that folder at all, "access denied".
    I unchecked "read only" and still nothing.
    Can't even delete the folder, let alone, getting into it and deleting those specific lines.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is System Restore disabled? Double check! Make sure it is disable on that drive. You should see both drives shown in your System Restore window! Select the drive and then click Settings and disable it.
     
  9. jak3y

    jak3y Guest

    Hi Chas', I had to do more than that, I had to customize the access as to who could.
    Would it be as simple as deleting the .executable's? or EVERYTHING within the folders? ie - log files as well.
    Apparently there are "data17" files, but with show all checked and show hidden files unchecked, i don't see the data17 files at all, as per the kaspersky log i attached earlier.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you probably do not need any of this (nor do you want it), just delete the restore point folders. (Like RP28, RP39, RP40, etc)
     
  11. jak3y

    jak3y Guest

    In a couple of those folders, there are TONS of things in them, only in the last folder #44, is there that one executable with a data file.
    The other folders have tons if inf, log, dlls, etc...straight deletion of folders will be fine? for sure? lol?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The whole folder is part of the restore point! They are infected! Thus....the folder must go!
     
  13. jak3y

    jak3y Guest

    Deleted the specific files initially, just finished the Kaspersky scan.
    Everything was fine, but, I deleted the folders regardless, who am I to argue with you C. :cool::cool::cool::cool: thanks again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Deleting only the individual files would have corrupted the restore points anyway. Data that would have been expected to be part of the RP would be missing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds