Thanks Clint I'll check it out. I didn't write down the vi*us name but it was a backdoor. This is the darnest thing I've run across. I managed to delete the file but every time I reboot the file is back and it is loading resident (although I shut it off). I did delete every reference in the registry to that file.
The file was scanned (it was maphack for Diablo 2 so beware) but nothing was detected until the .exe was executed. If anyone has a clue how to get rid of this please advise. Thanks Mike -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of [EMAIL PROTECTED] Sent: Saturday, March 22, 2003 12:10 PM To: [EMAIL PROTECTED] Subject: Re: PCWorks: Backdoor Vi*us Help Please What was the name of the vir*s? If Norton caught it, then you should not be having any problems. I can't find that file name anywhere, so it must be some randomly created name by the v*rus. I'd scan your PC here, http://housecall.trendmicro.com/ and also boot off the Norton AV floppy disk. Let those methods see if they can clean it up. I do find a winexec32 file and looks yours might be a back door Trojan, at least it appears to be in this case: http://www.megasecurity.org/trojans/m/mosucker/Mosucker3.0a.html See if you can find any keys in the registry with winexec32 in them. What OS is this? You need to be sure Norton is running AT ALL TIMES, except for when you scandisk, defrag, or install something. Before anything is installed and you're not familiar with the software, it should be scanned. All AV programs should be set to "scan ALL files" and not just program files. Most are set to ONLY scan program files by default with their "real time scanner". Most are set to 'scan all files' by default for manual scanning (like when you right click and scan the file). -Clint God Bless Us All Clint Hamilton, Owner Want to exchange links with us? http://OrpheusComputing.com � ============= PCWorks Mailing List ================= Don't see your post? Check our posting guidelines & make sure you've followed proper posting procedures, http://pcworkers.com/rules.htm Contact list owner <[EMAIL PROTECTED]> Unsubscribing and other changes: http://pcworkers.com =====================================================
