backdoor.coreflood (x-posted in security/virus discussion)

L

Liz

hey there,

i'm at my parent's house, they're running Windows XP on a
wireless home network. they have symantec 8.1 virus
protection.

they've been infected by a backdoor.coreflood virus (as
indicated by symantec scans). i've found the name of the
file (windows/system32/ipxwafkd.dll) but i am unable to
delete it because it's in "use by another user or
program". i've also tried deleting it in DOS with no
luck.

i've also gone into the registry to look for the file in
the "run" directory and didn't see the file indicated by
symantec in the virus report.

i've turned off system restore and restarted in safe mode
and i still can't delete or get symantec to quarantine
this file.

i've also tried (in safe mode) terminating expolorer.exe
and attempting to delete the file through dos and
symantec (as per:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?
VName=BKDR_AFCORE.D) to no avail.

:( any advice? time to reformat?

thanks in advance,

-liz
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top