View Single Post
  #2  
Old January 28th 05, 02:49 PM
Mike M
external usenet poster
 
Posts: n/a
Default

There is little or no point in removing viruses or trojans from the
_RESTORE archive as they are totally harmless and in doing so you are
destroying the integrity of the archive. Once you have got your system
clear of malware reset system restore so as to clear the archive and
create a new clean reference checkpoint.

However if you are repeatedly detecting a virus or other malware in a
location other than the C:\_RESTORE folder then this would suggest that
you are not cleaning your system of the virus and that it is regenerating
itself. This behaviour is becoming increasingly prevalent especially with
some adware such as recent versions of the VX2 and CoolWebSearch parasite.

See MS KB 263455 - "Antivirus Tools Cannot Clean Infected Files in the
_Restore Folder" (http://support.microsoft.com?kbid=263455).
--
Mike Maltby



coyote wrote:

My anti-virus always finds the following viruses in two different
restore archives: troj_stilen.A and VBS_PSYME.B. It only is
successful in removing them by deleting the folder. However, when i
run the antivirus again, the viruses are still there. So everytime i
run the antivirus it stops at that point and asks to have the viruses
deleted, so that the problem is never really resolved. Anybody have
any thoughts? THanks.