Ask the Expert

Getting rid of .rar files

Of late we have noticed that a lot of files with .rar extensions are being created on our systems. We have the latest anitivirus and SP intalled, but we aren't able to get rid of them. Can you suggest how to get rid of them? (These rar files actually contain a virus.)

    Requires Free Membership to View

The .rar extension is associated with both the bat.rahiworm Trojan horse virus (July 3, 2001) and W32.HLLO.Rozak virus (Feb. 18, 2002, a very new virus). Only has information on the W32.HLLO.Rozak since it is so new.

Both are easy to remove using the Symantec antivirus tools. Both modify the following file types: exe, mpg, mpg4, zip, doc, rar, avi and bat.

Ensure you have the current updated virus definitions and run the Symantec tool. Run a full systems scan including ALL FILES (exe, compressed 'zip,' dat, etc). Have the program "DELETE" all infected files, then recover those files from vendors or trusted sources. Recovery of these files may be difficult due to backup virus corruption as well. Be careful upon removing. Delete all files found to be infected, do not quarantine.

If you need further assistance go to the Symantec site and type both the virus and Trojan names. Ensure you clean all media and all files.

For more information on this topic, visit these other resources:
Virus Prevention Tip: Cleaning out a virus infection
Virus Prevention Tip: Fear no attachments
Best Web Links: Common Vulnerabilities & Prevention Tips

This was first published in March 2002

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: