| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
Help Me to Remove the Trojan
|
Original Message
|
Name: Bala
Date: June 22, 2007 at 01:06:35 Pacific
Subject: Help Me to Remove the TrojanOS: WinXPCPU/Ram: AMD Athlon(64-Bit)/512MDModel/Manufacturer: AMD |
Comment: Everytime when i boot the system i receive the message in AVG. "Threat Detected While opening file:C:\WINDOWS\System32\mmc.exe Trojan Horse BackDoor.Generic3.YHC" This started right from when i opened a MS Word document in internet. I tried healing and moving it to the vault as suggested by AVG.But the thing happens is just the Trojan Horse adds up in the vault and it again appears when i boot the system. I also experience another problem where a folder reappears when i delete it permanently by pressing Shift+Del in a particular Drive. Please Help.
Report Offensive Message For Removal
|
|
Response Number 2
|
Name: Bala
Date: June 22, 2007 at 11:19:04 Pacific
|
Reply: (edit)After trying to disable the system restore option i found that no system restore points are shown other than the one in the current month i.e. June and i'm sure that i had two restore points last month and i never deleted those or even disabled the option before.Is it because of that trojan???.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: Bala
Date: June 22, 2007 at 11:27:50 Pacific
|
Reply: (edit)I couldn't find the effect of this trojan since it is not available in any of the virus encyclopedia(s) i searched...
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: Bala
Date: June 22, 2007 at 12:32:36 Pacific
|
Reply: (edit)And is it safe to delete that file mmc.exe which is affected by that trojan horse since i read somewhere that removing the file affected removes the trojan but i suspect that it is a system file.Help.
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: Derek
Date: June 23, 2007 at 13:39:45 Pacific
|
Reply: (edit)It is quite normal for mmc.exe to be located in c:\windows\system32 Unless this has been replaced by a "nasty" then it should be safe enough. Type sfc /scannow in the Run box, which will replace any original system files that are corrupted. DerekW
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: Bala
Date: June 24, 2007 at 10:24:01 Pacific
|
Reply: (edit)No changes using SFC.I installed a Firewall yesterday which detected a file SVCHOST.EXE as a Word Document present in C:\Recycled which is not same as the System File.Some other solution please.Thanx In Advance.
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home