downloader trojan!?!

Discussion in 'malware problems & news' started by red meat, Apr 3, 2004.

Thread Status:
Not open for further replies.
  1. red meat

    red meat Guest

    AVG keeps on notifying me that I have a trojan called Downloader.Rvp.D is found in file C:\System Volume Information\_restore{EEB01FF0-0722-40BC-8DCA-5D3D36C315C6}\RP21\A0003639.exe

    It continues to pop up and tell me to run AVG to remove it, but AVG can neither find nor remove it. What should I do?
     
  2. LowWaterMark

    LowWaterMark Administrator

    Joined:
    Aug 10, 2002
    Posts:
    18,278
    Location:
    New England
    That's the System Restore area and no anti-virus can clean a file out of there because it's a protected area on XP. The proper way to remove an infected file from there is to cycle System Restore, which deletes all restore points and therefore deletes the infected file as well.

    This page at Symantec describes System Restore and also how infected files get in there and how to cycle it to clean the infection out:

    http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039
     
  3. red meat

    red meat Guest

    do I then run AVG and others and then turn it back on?
     
  4. snapdragin

    snapdragin Registered Member

    Joined:
    Feb 16, 2002
    Posts:
    8,415
    Location:
    Southern Ont., Canada
    Hi redmeat,

    Yes, after you have turned your System Restore off, rebooted your computer to clear all the old restore points, then you can run your antivirus again if you like, (and that is always a good idea as a double-check). Then if nothing comes up as infected, then turn your System Restore back on (follow the directions from the link that LowWaterMark gave you), reboot your computer, then set a new System Restore point.

    Regards,

    snap
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.