Forum Home
Press F1
 
Thread ID: 47246 2004-07-20 11:05:00 HELP VIRUS backdoor.trojan taking over Codex (3761) Press F1
Post ID Timestamp Content User
253823 2004-07-20 11:05:00 i'm running windows xp pro, and i've got nortan systemworks 2003 and today it picked up a virus backdoor.trojan(C:\WINDOWS\SYSTEM32\CTLKNFM.DLL), so i went into safe mode and deleted it in nav but when i started the computer back to normal it came up with the virus again, so can someone please help me get rid of this annoying virus?? Codex (3761)
253824 2004-07-20 11:15:00 Go to Control Panel > System Properties > Advanced and turn of XP's restore function (just check where exactly restore is please, I don't use XP & I'm in nix at the mo) > boot to safe mode, scan and delete. Re-boot and all should be fine. Go to Symantics website and see if they have any further instruction for this particular beastie to make sure you've got it all.

Cheers Murray P
Murray P (44)
253825 2004-07-20 11:18:00 symantic removal info here (securityresponse.symantec.com) johnboy (217)
253826 2004-07-20 11:19:00 i disabled system resotore a long time ago, so it isnt system restore thats keeping the virus, there's also ad-ware/spyware that does the same thing Codex (3761)
253827 2004-07-20 11:28:00 i've done that, and yet it still happens Codex (3761)
253828 2004-07-20 12:06:00 Could I make the suggestion that you get a more specialised program for the trojan. Maybe a2 from here (www.emsisoft.com) the free version which scans only or TDS-3 trial (tds.diamondcs.com.au) which ranks about hte best. Pheonix (280)
253829 2004-07-20 19:45:00 The link from johnboy has full removal instructions including how to make the registry changes to prevent it starting up again. Jim B (153)
253830 2004-07-21 05:30:00 yea i've done all that and thew registry thing and the win.ini thing ect but it still came back Codex (3761)
253831 2004-07-21 05:47:00 :O i decided that i wouldnt loose anything important when i formatted my computer......... just games and junk, all my photos were saved by my trusty Cd burner. Jamesioitron (4133)
253832 2004-07-21 06:03:00 well isnt that just dandy, i cant format my computer Codex (3761)
1 2