Virus has infectd System Restore in Win XP - Need Help!

Croda

Member
Jan 3, 2000
178
0
0
Norton reports that I have the backdoor.w3krat virus. I quarantined secure.exe which it could not fix. I deleted the file because I don't trust quarantine

Now the fun starts.

Norton still detects the virus at: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\BackupRestore\FilesNotToBackup\SystemRestore - the value of which is: \System Volume Information\_restore{2530B4DD-C3AD-43BD-B474-6F8C55F3D5DC}\* /s

It is the value of this key which Norton tells me is infected: The file
C:\System Volume Information\_restore{2530B4DD-C3AD-43BD-B474-6F8C55F3D5DC}\RP73\A0079236.EXE
is infected with the Backdoor.Y3KRat virus.
Access to the file was denied.


Now, can I delete this key? I'm not sure what to do to get rid of this.

A search on A0079236.EXE yields nothing. Subsequent Virus Scans do not find the problem. My antivirus is up to date (just checked it).

Any ideas greatly appreciated.