View Single Post
Old 06-05-2008, 10:11 PM   #9 (permalink)
arkoenig
Registered User
 
Join Date: Jun 2008
Posts: 42
OS: Windows XP SP3


Re: Found and removed WORM_AGENT.DFFZ and xyzdyn.exe infections; are there others?

Quote:
Originally Posted by Ried View Post
Absolutely--it's a great idea.

While it may not be needed at this time, infections these days tend to patch a lot of critical system files which often result in multiple problems, one of which can be an unbootable machine. Having Window's Recovery Console installed on your machine in advance can save a lot of heartache in the future.
I have, on occasion, resorted to removing the disk from a crashed machine and connecting it to a USB adapter on another machine so that I can get at its files.

Quote:
Apparently you've effectively erradicated the infection as your logs are clean.
Thanks -- I am gratified to hear the news. I've actually had a fair amount of system administration experience, just not on Windows.

Quote:
What you'll want to do now is create a clean restore point (If you haven't already.)

Click Start >> Run - type SYSDM.CPL & press Enter
* Select the System Restore Tab
* Tick on the checkbox - "Turn off System Restore on all drives"
Click Apply
* Then untick the same checkbox & click OK
This will flush out previous restore points (which contain the infections) and create a new restore point.
Done--though I find it easier to right-click "My Computer" and select "Properties" than to type SYSDM.CPL into the Run dialog :-)

By the way, one thing I found interesting was that Norton Antivirus 2008 did not detect either of these infections, and when I contacted them for advice about how to deal with the first one I had found, they said they wanted me to install a remote access ActiveX control to give them control over my machine and pay them $100. I suggested to them that if their software was unable to detect the problem, I had little confidence that their people would be able to do so either, and I would rather hunt around for solutions by myself first.

That hunt is what led me to this forum. It's been an interesting education -- thanks! I might say something about it on my blog.
arkoenig is offline