1
   

How to get rid of a virus

 
 
neo
 
Reply Wed 24 Mar, 2004 11:06 pm
hi, i have installed anti virus (AVG 6.0) that detected a virus in C:\Windows\system32/msrex. The virus name is "trojan horse backdoor.je". This virus cannot be healed it is still showing "still infected" What do i do? How can i remove it? Thanks.
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,110 • Replies: 11
No top replies

 
satt fs
 
  1  
Reply Wed 24 Mar, 2004 11:16 pm
I could find only this page in English.

http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=98574
0 Replies
 
neo
 
  1  
Reply Wed 24 Mar, 2004 11:28 pm
i don't think it'll work as i do not have Mc Afee installed.
0 Replies
 
satt fs
 
  1  
Reply Wed 24 Mar, 2004 11:39 pm
If you enter the key word "backdoor.je" in Google search, you can find several pages in languages other than English, but they can be translated.
0 Replies
 
Craven de Kere
 
  1  
Reply Wed 24 Mar, 2004 11:40 pm
Does your AV program have a mechanism to quarantine or delete the file?

If so, quarantine it at least and delete it if you can.

If not, manually delete it, and be careful not to open it while doing so.
0 Replies
 
Craven de Kere
 
  1  
Reply Wed 24 Mar, 2004 11:42 pm
The above instructions are for removal of ONE infected file. Is your puter infected or is this just an infected file you received?
0 Replies
 
neo
 
  1  
Reply Thu 25 Mar, 2004 12:10 am
i'm unable to aqccess Dos mode with WinXP.
As far as i know my comp was infected. All of the other viruses had been healed.(placed in virus vault) the only one active is the one discribed. So i guess it's for a file removal. The anti-virus will not allow me to delete this particular file. how do i manually remove it?
0 Replies
 
satt fs
 
  1  
Reply Thu 25 Mar, 2004 12:24 am
You can disable system restore.

http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 25 Mar, 2004 12:32 am
That's where it gets tricky, as it can have different names. Here is a removal guide for one variant of that trojan and I have some other methods linked and excerpted below.

Do you know how to edit your registry (use Regedit.exe)?

If so, look for this key:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"SystemDLL32"=SYSTEMPATCH.EXE

Also look for a file called: SYSTEMPATCH.EXE

symantec says:

Quote:
The file name of the attachment might vary. When executed, the Trojan horse sets the path and file name of the attachment (usually c:\windows\temp\filename.exe) equal to the "SystemDLL32" value in following registry key:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run


So if you do not find the file, look for that value in the registry key and then look for that name.
0 Replies
 
neo
 
  1  
Reply Thu 25 Mar, 2004 10:46 am
You are absolutely right! This is very complicated. I am still unable to find file or value. Sad
0 Replies
 
Craven de Kere
 
  1  
Reply Thu 25 Mar, 2004 01:25 pm
Perhaps your AV program nabbed it?

Try this online scan:

http://search.able2know.com/Internet/Tools/Trend_Micro_HouseCall_L1294/
0 Replies
 
neo
 
  1  
Reply Fri 26 Mar, 2004 10:40 am
i have found and sucessfully removed the virus, thanks alot.
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » How to get rid of a virus
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 06/26/2024 at 05:16:56