Help Remove Trojan Please

Discussion in 'Software' started by paradox2379, Jun 11, 2008.

  1. paradox2379

    paradox2379 Private E-2

    I have a corp edition of Norton Antivirus and it will not allow me to clean the below trojan. Any help to remove this would be greatly appreceiated. I have attached my log file as requested.

    Scan type: Realtime Protection Scan
    Event: Virus Found!
    Virus name: Trojan Horse
    File: C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP607\A0045473.exe
    Location: Quarantine
    Computer: D4P8R9
    User: SYSTEM
    Action taken: Clean failed : Quarantine succeeded : Access denied
    Date found: Wed Jun 11 03:23:20 2008
     

    Attached Files:

  2. wildwolf220

    wildwolf220 Oracle of Doom

    :wave and welcome to MG's..

    Please go through the steps here first READ & RUN ME FIRST

    Then start NEW thread in the Malware Forum

    Dont forget to attach the logs of the scans in your post

    Good Luck.
     
  3. dlb

    dlb MajorGeek

    Wildwolf's advice and link is highly recommended, however, the malware seems to be in the system restore cache. To easily emtpy the cache: right click My Computer > Properties > System Restore > check the box next to "Turn off system restore". You'll get a warning, click OK or Yes. Close the open dialog box and reboot. Run a full scan after rebooting to make sure everything is clean. Keep in mind, when you turn off system restore and empty the cache, ALL the restore points will be gone. To start establishing new restore points after cleansing the cache, go back to the System Restore window and uncheck the box you checked earlier, and reboot. This is a 'quick-n-dirty' way to clean out the system restore folder, but you really should follow all the steps in the link provided above to ensure that your PC is 100% clean. Malware that hides in the system restore folder can be hard to completely remove sometimes, so follow the steps at the link completely and carefully.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    It is NOT advisable to flush the System Restore points as these even when infected maybe your only course to restore your PC back IF malware removal steps are not fully followed or something is accidently deleted, if the Restore Points are deleted and you have issues then only course of action is a complete re-install of the OS, so do please follwo the Malware Read Me and attach your logs in a new thread in the Malware part of the forum.

    The malware experts only advise deleting the restore points when all traces of malware are not on your PC ( other than the restore points ) as malware has great habit of hiding some components unless you know what your looking for.
     
  5. scott_hayes89

    scott_hayes89 Corporal

    both ways are ok to me,but when i worked on my neighbors computer i noticed it had many virusis and spyware and malware,it made the computer fuction very poorly.so what i did was,set back system restore to an earlier time.then the computer worked quite a bit better.so i downloaded a couple of virus programs one a time.and ad-adware did the trick,luckly they kept a couple of restore points where i can work with the computer.the computer is working like a charm now,i delete all the restore points and created and new one.but believe it or not this computer had least 200 virusis and 200 or 300 spywares and malware in it.
     
  6. dlb

    dlb MajorGeek

    LOL I totally believe it! I have seen PC's with over 3000 infections! Yes, that's three-thousand! And that's not counting 700+ tracking cookies. In extreme cases like this, I usually end up being to forced to reformat the hard drive as it is simply quicker and more efficient and the best way to be sure that all the malware is gone.
    Anyway- I'm glad to hear all is well! :highfive Good job!
    And welcome to Major Geeks!

    :major
     
  7. Shadowninja

    Shadowninja Private E-2

    Hey Scott, although it worked THIS time I must warn you that from my experience (living in China where 2/3 of the world's hackers are located and largely unpunished or even encouraged if they work for the government or don't hack government computers) some of the newer viruses will not let system restore work or sometimes even start so try to convince your neighbor to buy Norton's anti virus or something similar it's better to stop the viruses from getting in than to pick up the pieces afterwards.Also many of the newer viruses are loaded into CMOS . Don't get me wrong what you did was totally cool but I'm saying at least from my experience it has not always worked.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds