Please register or login. There are 3 registered and 1003 anonymous users currently online. Current bandwidth usage: 51.80 kbit/s December 04 - 01:37am EST 
Hardware Analysis
      
Forums Product Prices
  Contents 
 
 

  Latest Topics 
 

More >>
 

    
 
 

  You Are Here: 
 
/ Forums / Software /
 

  Virus problem associate with System32? 
 
 Author 
 Date Written 
 Tools 
David Peck Jun 29, 2004, 11:38am EDT Reply - Quote - Report Abuse
Private Message - Add to Buddy List Replies: 4 - Views: 29
I'm looking for info on System32 (WindowsXP).

Running System Suite 5's virus program, it detected a trojan horse in this directory c:\Windows\system32\restsrv32a.sys. A side note- I had Norton AV updated and running on this computer since it was new and it did not detect this.

Anyhow, I directed SystemSuite to clean the file. It could not. Then it offered me the choice of deleting the files archive. I'm very hesitant to do this because I don't know what System32 is or does and if removing it would break my system. Would removing this files archive disrupt the functioning of Windows XP?

Any thoughts or suggestion?

Thanks!
-Dave



Want to enjoy less advertisements and more features? Click here to become a Hardware Analysis registered user.
***CaSToRTrOy*** Jun 29, 2004, 01:56pm EDT Reply - Quote - Report Abuse
Private Message - Add to Buddy List

Edited: Jun 29, 2004, 01:58pm EDT

 
>> Re: Virus problem associate with System32?
Hey,

Delete it, even though system32 is a dangerous place to be deleting stuff, but if you have windows XP, no big deal delete the file reboot run AV again, then goto run, and type this in... sfc /scannow

This will scan and repair any system files that are corrupted or deleted. Also...

Click Start > Run.

Type regedit

Then click OK.


Navigate to:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce


In the right pane, delete any values that refer to the file detected as Adware.Margoc.

Good Luck,
CT

Abit NF7-S 2.0
Athlon XP M2500+ @ 2.41Ghz
512MB PC3200 DDR SDRAM
120GB W.D. 7200RPM 8MB
ATI Radeon 9800PRO 128DDR
LG 52x32x52 CD/RW
Samsung Syncmaster 753DF
Coolermaster Aerogate
Aerocool High Tower
Thermaltake Extreme Giant III
angryhippy Jul 02, 2004, 07:17am EDT Reply - Quote - Report Abuse
Private Message - Add to Buddy List

Edited: Jul 02, 2004, 07:35am EDT

 
>> Re: Virus problem associate with System32?
http://it.trendmicro-europe.com/enterprise/security_info/ve_de...mp;VSect=T

This virus is less than 2 weeks old. That's probably why it didn't catch it. Are you regularly updating the AV program. Update it and run it again. It's OK to delete it and any other files it dropped as shown. If it won't clean it and you have to delete it but it won't let you go into safe mode and delete it. Make sure you have show hidden files and folders enabled in the file options in control panel. Also delete your system restore files in system properties/system restore tab.

Computer tips, links, 60s music
& help. http://www.angryhippy.net
http://angryhippy.net/images/my_other_day_job.jpg
Specs: Blah blah blah. Blah blah. With a blah blah!
Rory Witham Jul 02, 2004, 07:30am EDT Reply - Quote - Report Abuse
Private Message - Add to Buddy List  
>> Re: Virus problem associate with System32?
Norton is poor (being polite now)
The box is great for lighting fires. Ive been on so Many CALLOUT's with NORTON, Big Pile of S

Norton dont work, wont work, I dont see what going on and why they have not fixed it.

there is a topic i made state anti virus tell you about it a links to show what failing and what not.

LINKs HERE
http://www.hardwareanalysis.com/content/topic/21435/
and
http://www.hardwareanalysis.com/content/topic/19010/

system 32 or any file is ok to delete, as long as you know what it is and can download a replacement to place there just incase. (you will need to know about DOS but if you can read , there is a help file.)

as some one said, if it dont work there restore... UMM NO. you will need to remove all the system restor points and them norton proteced files, as this will keep it for you and re install it.

Just down load the file you abot to delete, check with a search to find out what it is and was it does. if it s virus only them dont download it, :)

there you go happy days again



Custom Computers: http://www.gtwcmt.co.uk/GT%20PERFORMANCE%20COMPUTERS/index.html
Computer maintenance: http://www.gtwcmt.co.uk/Computer_maintenance/index.html
Computer repairs: http://www.gtwcmt.co.uk/Computer-repairs/index.html
Michael A. Jul 02, 2004, 03:53pm EDT Reply - Quote - Report Abuse
Private Message - Add to Buddy List

Edited: Jul 02, 2004, 03:55pm EDT

 
>> Re: Virus problem associate with System32?
It would be very bad to delete your entire System32 directory as this is basically the core of Windows. However the infected file is within the directory so you can safely delete it without touching the rest. Once you've removed the file run the repair as Castor suggested. Then, get another antivirus because Norton is fairly poor. (I recommend two antiviruses, one is Panda and the other is McAfee. AVG ain't bad if you can't afford anything else.) Norton's detection rate is way down and its ability to clean is very low.

Good luck cleaning your system!

Michael A.
Website: http://itnode.net

Write a Reply >>


 

    
 
 

  Topic Tools 
 
RSS UpdatesRSS Updates
 

  Related Articles 
 
 

  Newsletter 
 
A weekly newsletter featuring an editorial and a roundup of the latest articles, news and other interesting topics.

Please enter your email address below and click Subscribe.