Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

PWS.Hooker.Trojan in CAB file

889 Views 5 Replies 3 Participants Last post by  Mosaic1
I have installed Norton Anti Virus and it detected a virus (pws.hooker.trojan) in a CAB file in what looks like an archive I have made.

It says it cant quarantine, repair or remove this file -
The exact message I get is :

Source: A0065004.CPY
Description: The compressed file A0065004.CPY within G:\_RESTORE\ARCHIVE\FS3.CAB is infected with the PWS.Hooker.Trojan virus.


Any suggestions - I cant find the CAB file - it mus be in some system directory that I cant access..

THANKS
Status
Not open for further replies.
1 - 2 of 6 Posts
Hi, That file would be in your System Restore Volume...and your'e correct, no program can modify things there. The trick is to flush the infected Restore Points off the computer, you do this following these steps:

http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam

Follow steps for ME or XP (your operating system)

Then, here is the short step by step to turn it off, back on, and create a new Restore Point:

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.Wait for hourglass to stop and it says
"Turned Off"

Restart your computer, turn System Restore back on and create a restore point.

To create a restore point:

Single-click Start and point to All Programs.
Mouse over Accessories, then System Tools, and select System Restore.
In the System Restore wizard, select the box next the text labeled "Create a restore point" and click the Next button.
Type a description for your new restore point. Something like "After trojan/spyware cleanup". Click Create and you're done.

BUT> Are you certain you are malware free now?

If we take a look at a Hijackthis log> though it is not a 100% guarantee that you do not have something, it's a good tool that does show a lot of them.

There are directions here to do it: There are .zip form and .exe form, take your pick.

Download it here:

http://radiosplace.com/

Or here.

It's a direct download so be ready with the folder for it.

Basically, you create a new folder, the desktop is OK provided you make a folder, name it something like HJT, and download TO that folder, run hijackthis.exe from there. If there are users of the computer who might start HJT and use it, hide the program in a folder elsewhere!

When it is done scanning> the Save log button will become available, save the log as hijackthis.txt which will open with Notepad. Go back to TSG, open your post, and copy and paste the entire logfile into a reply in your thread (here) and wait for advice.

Please do NOT use HJT yourself to remove anything, most of what it shows is good and needed by the system.
See less See more
Hi, Run Hijackthis again, put check next to this item, and click "Fix Checked":

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

In Windows Explorer, delete the file:

C:\WINDOWS\ALCXMNTR.EXE <file to delete

Restart. You should be all set.
See less See more
1 - 2 of 6 Posts
Status
Not open for further replies.
Top