Out of nowhere yesterday AVG pops up this message that says:

Virus
Trojan horse Downloader.VB.R
is found in file
C:\System Volume Information\_restore{3DC5992C-442B-447A-AD9E-257ADBA15496}\RP102\A0009289.exe
To remove this virus, please run AVG for Windows

So i scan with AVG and a few other AV progs i have and none of them find any viruses. I think i had a similar virus to this one before and part of getting rid of it required me to turn off system restore IIRC. Anybody know any way of getting rid of this? Thanks in advance.

Dani AI

Generated

Short summary tied to this thread: saw AVG flag a Downloader.VB.R entry buried in a protected backup area while other scanners reported nothing. pointed to the backup/restore angle and a linked fix cleared the alert. The steps below expand on that outcome and show how to confirm a real infection, remove persistent copies safely, and harden the system afterward.

A practical cleanup/checklist:

  1. Back up personal documents to external media (avoid copying executables or installers).
  2. Create and boot from a reputable rescue environment (bootable AV/rescue USB) and update its signatures, then run a full offline scan. Offline scanning can remove items that live inside backups or are locked in the running OS.
  3. After offline cleaning, boot normally and run a second, updated on-demand scanner (different engine). Use a rootkit scanner and an autorun/startup inspector to look for persistence points (services, scheduled tasks, startup entries).
  4. If only one scanner flags a file, treat it as possible false positive: obtain the file hash or sample (if accessible) and check it on a multi-engine scanner or submit it to the vendor for analysis.
  5. When certain the system is clean, recreate a fresh backup snapshot and enable normal backup/restore functions again.

Extra cautions and follow-up: disabling or deleting backup snapshots removes their copies of files, so plan backups accordingly. After cleanup, update the OS and all apps, rotate important passwords, and keep AV signatures current. If there is any doubt about full cleanup or signs of compromise remain, a clean OS reinstall is the safest course.

Recommended Answers

All 4 Replies

Yes, the _restore folders under your C:\System Volume Information directory are indeed when the System Restore backups are stored, and they are protected systems folders which even anti-virus programs don't have permissions to modify.

One of our members had a similar situation only two days ago; read through that thread for more info and (hopefully) a solution:


Also keep in mind that any anti-virus program is only truly effecitive if you keep it updated with the most current virus definitions. Most AV programs have an option to install those updates automatically, but many will only give you a limited free subscription to those updates. If your subscription has expired, you do need to renew it (even though it will cost $$).

I only use free AV programms but i have them all set to update automaticaly and scan once daily.

Thanks for the link that solved everything. :cheesy:

Cool- glad we could help you get it sorted! :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.