Computing.Net > Forums > Security and Virus > Backdoor.Trojan in SYSTEM\logon.exe

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Backdoor.Trojan in SYSTEM\logon.exe

Reply to Message Icon

Original Message
Name: Troubled Novice
Date: September 18, 2003 at 16:22:07 Pacific
Subject: Backdoor.Trojan in SYSTEM\logon.exe
OS: Windows 98 SE
CPU/Ram: IBM Aptiva 2270 63MB
Comment:

Help. We've got the Backdoor.Trojan on a file called WINDOWS\SYSTEM\logon.exe it was detected by Norton Antivirus, but we can't find a way to remove it as the program is running all the time the computer is on.

Can anyone tell us i) is it an essential program; ii) how to close it and repair/delete/quarantine the trojan?

Please bear in mind we are complete novices when it comes to computers.

Also can I add a thanks to the posts re: msinfo.exe We followed the advice on that thread and sorted out THAT problem.


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: September 18, 2003 at 17:58:02 Pacific
Reply: (edit)

When you start your computer tap the F8 key while the computer is booting up. This will take you into the safe mode. When you get into the safe mode, run your virus scan and delete the files that Norton finds.


Report Offensive Follow Up For Removal

Response Number 2
Name: Troubled Novice
Date: September 19, 2003 at 00:12:02 Pacific
Reply: (edit)

Capt.

After one failed attempt (we pressed F8 at the wrong time) we finally got rid of the file.

I assume rebooting following the deletion takes us out of safe mode, if not please let us know.

Do we do need to find an uninfected copy of the file to re-install (the computer seems to be working normally now)?

We are very grateful for your help.

Many thanks. Maybe we can get some sleep now!!

Troubled Novice


Report Offensive Follow Up For Removal

Response Number 3
Name: capt
Date: September 19, 2003 at 07:50:18 Pacific
Reply: (edit)

Thanks for letting me know how things went. By now you will know that shutting down the computer will take you back to the regular startup. The file only contained the Trojan Packet, which is why Norton could not clean it, as there was nothing to clean. No file needs to be replaced. Just make sure that you do not open attachments that come with your email, even from frieds without scanning them before openening, "you have no friends on the internet". Friends do stupid things and virus/trojan/worm packets are automatically sent out to anyone listed in their address book, which is why you must be careful when you get things from a "friend". In Outlook Express set your email setting in View>Layout, so the preview pane is disabled. Set the security setting to not allow attachments that might have a virus, etc. Get a firewall, Sygate, if you do not have one. Take care and all the best!


Report Offensive Follow Up For Removal

Response Number 4
Name: Troubled Novice
Date: September 21, 2003 at 12:33:41 Pacific
Reply: (edit)

Capt

Can we impose on your knowledge again, please?

We are having trouble with Internet Explorer. After using for a while it locks up. The message is that it cannot connect to the site requested as it may be busy, being repaired...

We've tried the refresh as it suggests, but that doesn't seem to work. At first we thought it was the site we were trying to reach, but changing the address to another brings similar results. AOL items (mail, news, etc) still work when IE jams.

Any suggestions? I did read a thread called Internet Explorer Broken, but wasn't clear on the solutions there, or if they applied in our situation.

Any advice gratefully received.

Troubled Novice


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software