PDA

View Full Version : Trojan Horse Removal


GRUNT
04-06-2004, 07:28 PM
Hey all, long time no see. Anyone know how to remove a trojan horse from a system. I have the name of the file but Norton Anti-Virus can't repair it.

Jason

TotalCarnage
04-06-2004, 11:00 PM
GEt me the file name and we can go through the removal process.

GRUNT
04-07-2004, 11:14 AM
TC, this is one of the filenames.

Dear Jason Pope,

We have analyzed your submission. The following is a report of our findings for each file you have submitted:

filename: C:\WINDOWS\SYSTEM32\msconfd.exe
machine: JASON
result: This file is infected with Trojan.StartPage

Developer notes:
C:\WINDOWS\SYSTEM32\msconfd.exe is non-repairable threat. Please delete this file and replace it if necessary. Please follow the instruction at the end of this email message to install the latest beta definitions.


Another:
filename: C:\WINDOWS\78810fckt2.exe
machine: JASON
result: This file is infected with Trojan.StartPage

Others id'd by Norton
backdoor.jeem, located in msdos.exe
Download.Trojan located in mssys.exe
Trojan.StartPage located in precontrol.exe

Basically, everytime I open IE one of these is changing my cnn.com homepage to about:blank.
I guess I should have laid off that one porn site.

Thanks for the help.

Jason

GRUNT
04-13-2004, 11:39 AM
TC or anyone else,

I have tried everything, removing the files from the registry in safe mode and so forth. Norton can't delete or repair the files.

I have XP with remote assistance if someone would be willing to help.

Thanks,

Jason

TotalCarnage
04-13-2004, 03:53 PM
we can try tonight. Remember, you have to shut off system restore when you do this.

GRUNT
04-14-2004, 09:53 AM
Hey TC, was working last night sorry I did not get your message. I will look to see if you are available later tonight

I did disable system restore to no avail.

Jason