Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Trojan Horse Infection

Posted on 2002-07-29
9
Medium Priority
?
646 Views
Last Modified: 2013-12-28
I'm running Win98SE and Norton Antivirus tells me that windows\system\wnmngm1.exe is infected with a Trojan Horse, but is unable to repair the situation.
How do I proceed?
0
Comment
Question by:davereynolds
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +1
9 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 7185927
I would rename the file, ( use *.old ) and see if it affects anything.

Other option is to do a
start-run - sfc
and have if replace that particular file ( if it is a system file at all ).

If not, then simply delete it since it is not needed.

I hope this helps !
0
 
LVL 12

Expert Comment

by:guidway
ID: 7186068
Try running this free virus scanner on your computer and see if it helps.

http://housecall.antivirus.com

Kind of like getting a second opinion. ;-)

guidway
0
 
LVL 12

Expert Comment

by:guidway
ID: 7186075
Strange, if that is a windows file there is no mention of it anywhere on the net (that I can find). Usually you can find a little info about any file on the net. This one isn't even listed.

guidway
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 3

Author Comment

by:davereynolds
ID: 7186127
Explorer will not let me delete the file, and sfc says "You do not have permission to open this file- see the owner of the file or an admin to obtain permission".
Does this indicate it is a system file or just a virus payload? What's next?
0
 
LVL 12

Expert Comment

by:guidway
ID: 7186144
did you try running that other virus scanner on it? That would eliminate the idea of it being a virus if it doesn't detect anything.

guidway
0
 
LVL 12

Expert Comment

by:guidway
ID: 7186151
Does NAV say what virus it is infected with or does your computer do anything weird as a result of this problem?

guidway
0
 
LVL 4

Accepted Solution

by:
jpanderson earned 400 total points
ID: 7186424
Restart in safe mode (hit F8 repeatedly or hold down Ctrl button when starting.  Start > run > msconfig > startup tab > find any reference to the file being loaded and uncheck the box.  Restart again in safe mode and look in the win.ini file for any reference to this file being loaded and delete it.

Search registry: Start > run > regedit > delete any reference to the file.

Restart the computer and do another virus scan and see if its gone.

Please note:
Back up the file and any files that you modify, also back up the registry before you edit it.
0
 
LVL 4

Expert Comment

by:jpanderson
ID: 7186433
Forgot to mention that you should be able to delete the file now in safe mode.  If you can't just make note of where its located and then use a boot disk to start the computer and navigate to the file and delete it in dos mode. del wnmngm1.exe
0
 
LVL 3

Author Comment

by:davereynolds
ID: 7186557
Thanks JP. After deleting the regisry entry, Norton was able to delete the exe file and everything seems to be working well.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes clients can lose connectivity with the Lotus Notes Domino Server, but there's not always an obvious answer as to why it happens.   Read this article to follow one of the first experiences I had with Lotus Notes on a client's machine, my…
IF you are either unfamiliar with rootkits, or want to know more about them, read on ....
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question