Forum Moderators: phranque

Message Too Old, No Replies

Virus Backdoor CGZ

I can not eliminate

         

angiolo

6:55 pm on May 18, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I have the last version of MC Afee antivirus and the las dat file.

Browsing the net I encountered a malicious site that tried to install a trojan horse.

The antivirus seemed to intercept it, giving me a message like:

the program scvhost2.exe has a virus calle backdoor - cgz and it has been deleted.

I run the antivirus and everything seemed in order.

Unfortunately this virus seems to be persistent; often it is intercepted by the antivirus program.
Unfortunaly at any interception the Dial up connection close and I loose the Net dialup configuration. Every time I have to reconfigure.

I run Windows XP professional ( it is updated).
I found another svchost.exe file and svchost.dll file in a directory were they were not supposed to be: c:\windows\ ; I think that svchost.exe should be in :\windows\system32\

I renamed those file and other "new" files of 51 kb and now it seems that everything is in order...

Mc Afee seems unable to delete it in an automatic way ( I disabled the system restore...): i had to manually delete it.

But, if you have news about this trojan, please reply!

jdMorgan

11:34 pm on May 18, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The best place to go for information about virus removal is mcafee.com or symantec.com. They have extensive databases detailing each exploit and its variants.

Also, download and run Ad-Aware and Spybot Search and Destroy - both free malware removers.

Jim