Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read

Sponsored Links

How to fix win32/pepatch virus

Networking & Security

Thread Tools Search this Thread
Old 19-02-2008
Join Date: Jan 2006
Posts: 2,259
How to fix win32/pepatch virus

I am using AVG virus cleaner and this keeps detecting win32/pepatch virus in my "system volume information/_restore " folder in a .dll file.

when i try to delete it manually it wont get delete and comes back again

Anyone can help me ?


With great power comes great responsibility - Spiderman's Uncle

The Greatest Sig Ever
Reply With Quote
Old 19-02-2008
Join Date: Aug 2006
Posts: 222
turn off system restore...delete the"SRDISKID.DAT" in the _restore folder...either the one on c:\, d:\, e:\, ect. depends how many partitions and drives you have.
check your msconfig startup items. Make sure there is not 2 IEXPLORE's running there. If there is, look to see if one has a zero (0) instead of an oh (o). Delete/disable it if it has a zero, as well as delete it's corresponding registry key.restart the computer.
make sure you have a good software firewall to make sure it is not "sending out" any info.

Virus Name: Rbot.FAY
3 of 5
3 of 5
2 of 5
Type: Worm
Aliases: [Win32/]Rbot.FAY; [Win32/]Spybot.4wq!Worm (InoculateIT); [Win32/]Packed.Win32.PePatch.aw (Kaspersky); [Win32/]Rbot.FAY;

Date Modified: 11-May-2006
Date Published: 11-May-2006


Win32.Rbot.FAY is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants.

This particular variant of Rbot is distributed as a 71,578 byte, Win32 executable that exhibits the following specific characteristics:

When executed this variant copies itself to the %System% directory as W1nUpdate.exe and makes the following modifications to the registry to ensure that this file is executed at each Windows system start:

HKLM\Software\Microsoft\Wind ows\CurrentVersion\Run\Microsoft Windows Update Service = "w1nupdate.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Windows Update Service = "w1nupdate.exe"

Note: '%System%' and '%Windows%' are variable locations. The determines the location of these folders by querying the operating system. The default location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95,98 and ME is C:\Windows; and for XP is C:\Windows.
Just a reply to say thank you for these links and posts I have a lot to read and learn now!

Reply With Quote

  TechArena Community > Technology > Networking & Security
Tags: , , , ,

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads for: "How to fix win32/pepatch virus"
Thread Thread Starter Forum Replies Last Post
Win32/Alureon.H virus can not be cleaned and blocks virus updates and windows updates-need help Illinois Networking & Security 6 06-08-2010 01:59 AM
How to get rid of this Win32.Aliz virus Abhirath Networking & Security 5 01-04-2010 03:10 AM
How to get rid of Win32.Sumom.a virus? KennedII Networking & Security 5 07-03-2010 03:34 AM
Virus.Win32.Protector.c karan k Networking & Security 3 30-09-2009 09:31 AM
Win32/PEPatch Bleep Networking & Security 3 20-02-2009 11:26 PM

All times are GMT +5.5. The time now is 01:34 PM.