Forum Moderators: phranque
Browsing the net I encountered a malicious site that tried to install a trojan horse.
The antivirus seemed to intercept it, giving me a message like:
the program scvhost2.exe has a virus calle backdoor - cgz and it has been deleted.
I run the antivirus and everything seemed in order.
Unfortunately this virus seems to be persistent; often it is intercepted by the antivirus program.
Unfortunaly at any interception the Dial up connection close and I loose the Net dialup configuration. Every time I have to reconfigure.
I run Windows XP professional ( it is updated).
I found another svchost.exe file and svchost.dll file in a directory were they were not supposed to be: c:\windows\ ; I think that svchost.exe should be in :\windows\system32\
I renamed those file and other "new" files of 51 kb and now it seems that everything is in order...
Mc Afee seems unable to delete it in an automatic way ( I disabled the system restore...): i had to manually delete it.
But, if you have news about this trojan, please reply!