Re: Invaded by trojan

From: Br0wnbear (brownbearat_at_canadadotcom)
Date: 05/21/04


Date: Fri, 21 May 2004 13:00:11 -0400

On Fri, 21 May 2004 09:23:20 -0700, "smitty"
<anonymous@discussions.microsoft.com> wrote:

>After running CA EZ Virus scan I keep getting a pop-up
>box reporting that EZ Scan has found that "System Volume
>Information\_restore\ file #....... exe is Win 32.Jeem.C
>trojan" How can I go about deleting this file?
>Also, the scan shows three trojan infected files
>identified as follows: "Documents and
>Settings\Administrator\local settings\Temp. Internet
>files\Content.IE5\file 3 .....
>How can I delete these files?
>Thanks for any thoughts!

Smitty
Remove your system restore point.
Run AV again
Rebuild system restore point.
here is a link about this
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
hth
John Brown
Bears are always happy, we get to hibern8



Relevant Pages

  • Re: GONE! Trojan Horse Downloader.agent.2.BK
    ... I think the trojan is gone! ... disabled system restore according to the instructions, ... Lo and behold, AVG ... >updated antivirus, in safe mode if you want, you ...
    (microsoft.public.security.virus)
  • Re: Torjan and Virus
    ... But how do I know if its in that one folder? ... So If I do a disk cleanup on system restore, will it just get rid of that ... > A trojan is a specific type of virus - a program that pretends to be ... If you want to speed up this process use Disk Cleanup on the ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: MT CHAT - Anyone know what happened?
    ... | It's a trojan bot that's been around on a number of websites - I ... Before the computer went completely down, Ad-Aware said at ... least part of the trojan was in the system restore files, ... which enables me to run IE "natively" in Firefox. ...
    (sci.med.transcription)
  • Pdox runtime 9 trojan (not)
    ... Some of my customers have lately been reporting to me that a file I've been ... distributing with a paradox program is infected with a trojan. ... as being infected with TROJ_CIH.DAM by the latest definitions in Trend Micro ...
    (comp.databases.paradox)
  • Re: Problem with winlohonhook trojan!!
    ... I had aproblem with this trojan winlogonhook on my computer. ... I have the windows XP home eddition instaled on my comp. ... getting reinfested because you failed to flush System Restore. ... We need to know _where_ your antimalware product finds the malware, ...
    (alt.comp.anti-virus)