SYSTEM RESTORE BAGLE WORM

SYSTEM RESTORE BAGLE WORM

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
SYSTEM RESTORE BAGLE WORM simon 11-12-2005
Posted by simon on November 12, 2005, 8:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Some advice please. I have just run a scan on my computer using AVG free
edition. 33 files were found to be infected with BAGLE.IF and BAGLE.10.These
were automatically removed to the VIRUS VAULT. So fas so good, but then I
looked for more information on AVG and found the words "File had been
imported from the AVG Virus Vault 6.00". Does this mean they had been found
and placed into the VIRUS VAULT in the past and had somehow been restored?
I had recently carried out a system restore to an earlier date.
I did also find this: "file path: system volume
information/restore.........."

The only difference I can see on my computer after removing the worm is that
the little light bulb at the bottom of my screen which shows the state of
battery charge, has vanished. Surely a coincidence?




Posted by Max Wachtel on November 12, 2005, 8:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
simon simon@SIMONSPLACE.COM on 11/12/2005 in
thought,came up with this jewel:

> Some advice please. I have just run a scan on my computer using AVG
> free edition. 33 files were found to be infected with BAGLE.IF and
> BAGLE.10.These were automatically removed to the VIRUS VAULT. So fas
> so good, but then I looked for more information on AVG and found the
> words "File had been imported from the AVG Virus Vault 6.00". Does
> this mean they had been found and placed into the VIRUS VAULT in the
> past and had somehow been restored? I had recently carried out a
> system restore to an earlier date. I did also find this: "file path:
> system volume information/restore.........."
>
> The only difference I can see on my computer after removing the worm
> is that the little light bulb at the bottom of my screen which shows
> the state of battery charge, has vanished. Surely a coincidence?

It is a good idea to remove restore points when cleaning.Sometimes the
nasties are hiding in there! Better to use backup tools then to rely on
system restore. It might be a good idea to use David's tool to scan
your system.I have a link to it on my site: see Virus Removal
Instructions below-
max
--
Virus Removal Instructions: http://home.neo.rr.com/manna4u/
Keeping Windows Clean: http://home.neo.rr.com/manna4u/keepingclean.html
Windows Help: http://home.neo.rr.com/manna4u/tools.html
Playing Nice on Usenet: http://oakroadsystems.com/genl/unice.htm#xpost
To reply by e-mail change nomail.afraid.org to gmail.com
nomail.afraid.org is setup specifically for use in USENET
feel free to use it yourself. Registered Linux User #393236


Posted by Befunge Sudoku on November 14, 2005, 3:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
maxpro4u@nomail.afraid.org says...
> It is a good idea to remove restore points when cleaning.

Depends. Sometimes doing a system restore to a date before the
infection is the quickest way to get the machine going again.
And then you scan it completely anyway, of course.

While I do often disable System Restore, I prefer not to if I
don't need to, in case I want to use one of the restore points.

--
Pneumothorax is a word that is long


Similar ThreadsPosted
missing system restore tab October 16, 2005, 10:45 pm
System Restore and malware. January 4, 2006, 11:20 am
Attack by Unknowns and Defunct Norton AV and System Restore November 8, 2007, 9:36 am
Virus in restore file September 30, 2007, 8:29 am
Attention new worm ! W32/Rizalof.B.worm March 4, 2006, 4:30 pm
Glieder (aka Bagle, version eightysomething) June 2, 2005, 6:14 pm
A squared false positives for bagle? June 15, 2005, 8:59 pm
Modern times - nice malware example: Bagle... December 8, 2005, 11:11 am
Only 65% of AV software detected hidr.exe as Bagle / Mitglied September 1, 2007, 10:02 pm
McAfee DAT v4585 dat files have been released due to mutliple new variants of Bagle September 19, 2005, 10:00 pm

The site map in XML format XML site map

Contact Us | Privacy Policy