It is currently Tue Sep 01, 2026 1:11 pm


Virus made Folder viewing impossible

Support for any program including installing and running

Moderator: liljim

Which Is the best Anti Virus under FreeWare

Poll ended at Sun Aug 17, 2003 7:36 pm

AVG Anit Virus
0
No votes
Kaspersky Anti Virus
0
No votes
Avast Home Edition
0
No votes
 
Total votes : 0

Virus made Folder viewing impossible

Postby akshat » Fri Jul 18, 2003 7:36 pm

Maa,m/Sir
A very peculiar situation has arised as you see I am one of the free version user of the AVG Anti Virus 6.0 + ([url]grisoft.com[/url]), and just today I updated the virus database file, after running the antivirus, the Anit virus detected two virus from the Window /Web folder in Folder.htt file & Root Kernel and said that as the Anti-virus is unable to disable it, I should move it into Virus Vault, so I did.

Now when I try to view any folder(s) in their respective directories in Web View, it doesn't do it. moreover, when i restored the files from the Virus Vault, and I try to click the option of "View" >> "as Web Page" from the Menu Bar, it gives the AVG anti virus "Viru Info" and ask me whether to give it access, or not, or to heal it, healing doesn't work, so I have to disallow access. I also tried the "give Access" then it shoed a pop up in and says that certain script has gone wrong.

Please help me what to do, the virus info are as below:;

Results of Complete Test, date and time 7/17/03 12:28:20 :

Testing C:\ serial 0E3C-0ED5
C:\WINDOWS\SYSTEM\KERNEL.DLL repaired
C:\WINDOWS\WEB\FOLDER.HTT Virus found VBS/Redlof
Testing D:\ serial 0E55-0F07
Testing E:\ serial 0E3A-0FD5

Test Completed
30902 objects tested, 2 found infected

Please give me guidance in step by step as I am a complete novice and if a patch for this could you provide or a web-link would be also good. Please Please Please Help me.

Akshat
:(
eakshat@excite.com
User avatar
akshat
Newbie
Newbie
 
Posts: 1
Joined: Sat Jul 19, 2003 1:00 am
Location: Lucknow, Uttar Pradesh, India

Thanks given:0
Thanks received:0
Top

Postby teststrips » Fri Jul 18, 2003 9:48 pm

you could try this web based virus scanner.



Other than that I've seen great deals on Norton Systemworks, which comes with Norton Antivirus. Norton's antivirus is my favorite, and what I use on my home PC's. With systemworks, you also get some great diagnostic/fix tools like disk doctor, speed disk, and win doctor
User avatar
teststrips
Geek Alumni
 
Posts: 542
Joined: Fri Jan 24, 2003 1:00 am
Location: USA - Pennsylvania

Thanks given:0
Thanks received:0
Top

Postby NaTaS » Sat Jul 19, 2003 1:04 am

If you're running WindowsXP or WindowsME - you'll need to consider the restore feature. The restore feature backs up selected files automatically to the C:\_Restore folder. This means that an infected file could be stored there as a backup file, and VirusScan will be unable to delete these files. You must disable the System Restore Utility to remove the infected files from the C:\_Restore folder.

WindowsME


1. Right click the My Computer icon on the Desktop and click on Properties.
2. Click on the Performance tab.
3. Click on the File System button.
4. Click on the Troubleshooting tab.
5. Put a check mark next to 'Disable System Restore'.
6. Click the 'OK' button.
7. You will be prompted to restart the computer. Click Yes.

Note: To re-enable the Restore Utility, follow steps one to seven and on step five remove the check mark next to 'Disable System Restore'.


WindowsXP


1. Right click the My Computer icon on the Desktop and click on Properties.
2. Click on the System Restore tab.
3. Put a check mark next to 'Turn off System Restore on All Drives'.
4. Click the 'OK' button.
5. You will be prompted to restart the computer. Click Yes.

Note: To re-enable the Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'.
User avatar
NaTaS
Senior Geek
Senior Geek
 
Posts: 155
Joined: Thu Sep 20, 2001 1:00 am
Location: USA

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sat Jul 19, 2003 9:26 pm

I’m sorry to say but VBS.Redlof is a nasty virus.
VBS.Redlof will be inserted into all new e-mail messages created by an infected user.
Depending on the location of the Windows System folder, the virus copies itself as one of the following:
%windir%\System\Kernel.dll
%windir%\System\Kernel32.dll
VBS.Redlof spreads by adding itself as the default stationery that is used to create email messages:
The virus makes many changes to the registry to allow execution of .dll files as script files.

Removal Instructions:
Any files with VBS.Redlof must be deleted.
Replace deleted files from a clean backup or reinstall them.

To reverse the changes that the virus made to the registry:
CAUTION: I strongly recommend that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files.

To back up the registry:
Click Start, and click Run. The Run dialog box appears.
Type regedit and then click OK. The Registry Editor opens.
Click File, click Export
I always name mine the current date 7-19-03 remember where you save the file!
Now navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
Kernel32

navigate to the key:
HKEY_CURRENT_USER\Identities\[Default Use ID]\Software\
Microsoft\Outlook Express\[Outlook Version].0\Mail
In the right pane, delete the values:
Compose Use Stationery
Stationery Name
Wide Stationery Name

navigate to the key:
HKEY_CURRENT_USER\Software\Microsoft\Office\9.0\Outlook\Options\Mail
In the right pane, delete the value:
EditorPreference

navigate to and delete these subkeys:
HKEY_CLASSES_ROOT\dllFile\Shell
HKEY_CLASSES_ROOT\dllFile\ShellEx
HKEY_CLASSES_ROOT\dllFile\ScriptEngine
HKEY_CLASSES_ROOT\dllFile\ScriptHostEncode

Exit the registry editor your done.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Misc. Software

Who is online

Users browsing this forum: No registered users and 0 guests

cron