Viruses in "Restore to Factory Settings"...???

T4x series specific matters only
Post Reply
Message
Author
T7TrainingSystems
Freshman Member
Posts: 63
Joined: Sun Apr 15, 2007 9:02 am
Location: Sydney, Australia
Contact:

Viruses in "Restore to Factory Settings"...???

#1 Post by T7TrainingSystems » Wed Jan 07, 2009 3:00 am

I'd have thought this would be impossible, but...

I bought a T40 for a relative off eBay. Avast virus checker said that XPclient.exe had a trojan horse virus. No matter I figured, going to restore to factory settings anyway, and did so. Sure enough, after restoring to factory settings, it was gone.

Then we did a backup using R&R and lo and behold, the virus was back!! Seems it is regenerated with the other R&R files when it's run the first time. How could that be possible?? The laptop hadn't been on the net at all. A few days later, she did a scan with Comodo (I think) and it found these:

Anti.0064.xpoint.variantID C\ProgramFiles\xpoint\agent\epagent.exe
VBS.ak.S.A(ID=oxa5e) C\ProgramFiles\xpoint\pe\dig\lastboot.exe
VBS.ak.S.A.(ID=oxa58) C\ProgramFiles\xpoint\pe\dig\RECRTSP.exe
VBS.ak.S.A.(ID=oxa5e) C\ProgramFiles\xpoint\pe\dig\xpshell.exe

Can anyone shed some light on this? Is it possible that a virus is in the pre-installation environment? Are these false positive? Or am I missing something here? Anyone else experienced this?
Main: T60 -- 500gig 4gig Win7/Vista dual
1 x T42, 2 x T41, 4 x T40, 2 x T30, 1 x T23, 1 x T22
Ex-main: T23 1.13Ghz, 20gig, XP SP1
Ex-ex-main: 600X - 10gig 256mb Win98 - very fast on Win98!!
http://www.T7.net.au

Mike Blake
Sophomore Member
Posts: 248
Joined: Sun Mar 30, 2008 4:28 pm
Location: Warwick, Rhode Island

Re: Viruses in "Restore to Factory Settings"...???

#2 Post by Mike Blake » Wed Jan 07, 2009 4:17 am

This could be a case of mistaken identity. One site
I found lists, for example, two xpagent.exes, one part
of R&R, the other as malware:
XPAgent
Name: Xpagent
Command: xpagent.exe
Status: Unknown
Description: Part of the IBM/XPoint Rapid Restore utility.

Name: XPAgent
Command: XPAgent.exe
Status: Definitely not required. Usually Malware.
Description: Reported as the CLICKER.LE TROJAN by Panda Anti-Virus. Do not confuse this with the IBM/XPoint Rapid Restore file which is generally located in the PROGRAM FILES\XPOINT\AGENT folder
There were a number of other R&R files also listed.

I think you may want to do some research/Googling
on those file names you found. (It's 4 in the morning
here, so I'm not feeling inspired to do it for you right
now. :wink: )
--Mike Blake

T7TrainingSystems
Freshman Member
Posts: 63
Joined: Sun Apr 15, 2007 9:02 am
Location: Sydney, Australia
Contact:

Re: Viruses in "Restore to Factory Settings"...???

#3 Post by T7TrainingSystems » Thu Jan 08, 2009 3:50 pm

Thanks Mike, I'd come to a similar conclusion from Googling but wasn't feeling very at ease about it.

To see someone else come to the same conclusion is reassuring!

Only doubt in my mind is that I'd imagine there'd be lots of mentions of this false-positive on the board here, but I find practically none.

Still, I'm planning to circumvent the whole issue next time we do a factory restore by interrupting the factory restore process with a BartPE CD and deleting these files before they're inflated (unzipped...?) and install the latest restore program from the IBM site.

I've tried this on my own T40/T41 laptops and it works a treat!

Thanks for your reply!
Main: T60 -- 500gig 4gig Win7/Vista dual
1 x T42, 2 x T41, 4 x T40, 2 x T30, 1 x T23, 1 x T22
Ex-main: T23 1.13Ghz, 20gig, XP SP1
Ex-ex-main: 600X - 10gig 256mb Win98 - very fast on Win98!!
http://www.T7.net.au

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad T4x Series”

Who is online

Users browsing this forum: No registered users and 7 guests