also @ TechSpot: Xbox Live bans prompt class action lawsuit
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Windows OS

Backdoor Virus

Closed Thread
Bookmark Thread Tools
  #1  
Old 07-29-2005
nEO's Avatar
nEO nEO is offline
Newcomer, in training
 
Member since: Jun 2005, 15 posts
Backdoor Virus

Please help!, i found a vir, in a sistem i made like a year ago for a friend, the spech's,,, winxp pro, norton systemwoks 2004 upgrade to jul 20 2005, norton anti vir detected but when you say fix it,, it can't ,,, quarentine,, it can't ,,, delete it and IT CAN'T!!!! and do nothing.!!!!

BackDoor Trojan Detected in "hwclock.exe" on system32 folder!!!

some suggest!!, some experience in this!!!

Please help!!!
Thnx again :bounce:
  #2  
Old 07-29-2005
TechSpot Evangelist
 
Location: has left the building
Member since: Aug 2003, 8,160 posts
Download Ewido Security Suite (trial) from http://www.ewido.net/en/download/
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

Start Ewido. When you run it the first time, you get a warning "Database could not be found!". Click OK.
On the main screen, click on Update in the left menu, then click the Start Update button.
After the Update finishes, the status bar at the bottom will display "Update successful".
-- If you have problems updating see here: http://www.ewido.net/en/download/updates/
Once the updates are installed do the following:
Click on Scanner
Make sure the following boxes are checked before scanning:
- Binder
- Crypter
- Archives
Click on Start Scan and let Ewido scan the PC.
While the scan is in progress, you will be prompted to 'Clean files', click OK
When the scan is done, you'll find a Save report button at the bottom of the screen.
Click 'Save report' and save it to your desktop.
Reboot your PC and post back the Ewido Scanlog as a .txt attachment
To remove this ad, sign in. To register for a new account, click here.