Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91681 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Trojan - Service.exe - issue/virus


  • This topic is locked This topic is locked
1 reply to this topic

#1 cnorton

cnorton

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 23 September 2009 - 12:00 PM

Hello - My Symantec anti-virus has detected a Backdoor.Trojan issue. (service.exe file). I've attempted (unsuccessfully) to follow Symantec's instructions for removal. The scan process quarantines it, but it just keeps coming back. After researching this to the best of my ability ad comparing files to my laptop (which is not infected) files, there is a new directory under my windows system32 drivers directory called imonagent. My other computer does not have this directory at all: C:\WINDOWS\system32\drivers\imonagent The contents of this directory contain several files (exe's and dlls). I tried attached the printscreen of the directory - but it is too big. The service.exe file gets removed with antivirus, but when I re-connect to the internet - it gets re-added. I can remove all of the the files in this directory with the exception of the netconfig.dll file. However, I can move the entire contents of the directory to another directory and then delete the directory. When I do this, everything boots up OK, but when I open my browser (either Iexplorer or Firefox) it is unable to load any URLs at all ??????? I've run combofix, and have attached the log. Any help, advice, or assistance would be much appreciated. Thanks ! Carter

Attached Files


    Advertisements

Register to Remove


#2 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 26 September 2009 - 01:28 PM

Take a read through this and then start a fresh thread in this forum and post accordingly. Please don't forget to include a brief description of your problem, and somebody will be along as soon as.
Helpers look for posts with zero replies which is why you need to start afresh and why i'll lock this one.
Death to the salad eaters!

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users