Re: backdoor.trojan



Hi David,

I've done all that you have instructed and have successfully had McAfee
deleted some of the Trojan files. However, as i rebooted into windows
again, I still saw "backdoor.trojan virus found" alert by my Norton
Antivirus program.

I'm guessing that is probably because when I ran the scan in normal
mode, some of the files were in use/protected that the scanner simply
couldn't have done anything to it.

And when I ran it in safe mode, since the windows that I have which is
affected by trojan is in f: drive, by default, the scanner ran would
ONLY be scanning C:. So I got an error when I tried to run it from f:
drive in the command line.

I am guessing there must be a way to go around this. Otherwise, the
scanner is of no use if trojan existed in drive other than the default
C.

Thanks,
Dennis



David H. Lipman wrote:
From: <dennis.pong@xxxxxxxxx>

| Hi,
|
| I realize my computer is infected with backdoor.trojan. The sympton is
| I do get virus alert windows popped up once in awhile saying a .exe
| file generated by backdoor.trojan has been quarantined (after failing
| to clean it by the default action). I tried all the suggested removal
| instructions posted on
|
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.trojan.html#removalinstructions
| But I do not see anything was registered in my registry, win.ini, and
| system.ini that is pertained to the virus. So I'm guessing my problem
| right now is really the nagging .exe file generator hidden in my
| computer / remotely away from my computer.
| Any suggestions as to how to remove it or block it from being
| activated/run ?
|
| Some background info:
| I've Symantec Antivirus installed in my computer and the real-time scan
| is turned on.
| My virus definition update is current as of now.
| Full system scan has been performed and nothing has been detected as
| viral.
| I always deleted those .exe files immediately as soon as they were
| detected by the real-time scan.
|
| Any help / advice is appreciated.
|
| Thanks,
| Dennis


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm

.



Relevant Pages

  • Re: Current security settings put your computer at risk ...
    ... They want me to disable or at least prompt "Download Active X ... ... Reboot and ... ... Download, install, run, update and perform a full scan with the ... Download/Install the latest Windows Installer: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: same update-15times 15 days
    ... the update from the Microsoft Download center, ... Then order a pizza ... I uninstalled ALL Windows Media Hotfixes from add/remove. ... Didn't Reboot. ...
    (microsoft.public.windowsupdate)
  • Re: IE8 does not work with XP Pro
    ... Internet Explorer 8 requires interaction from you to install. ... Download, install, run, update and perform a full scan with the ... Download/Install the latest Windows Installer: ... * will take time, will take a reboot. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: 0-length ntoskrnl.dll (NOT ntoskrnl.exe)
    ... | Windows xp system at all, so I am tempted to remove this file ... FireWall to allow it to download the needed AV vendor related files. ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: My scanner issue again (sorta)
    ... but at least you wouldn't have to reboot to ... and transferring the scan from Windows to Mac isn't all too ... run the scanner, ...
    (comp.sys.mac.system)