ConHook Trojan Horse

Duckjake

LEGACY MEMBER
LEGACY MEMBER
Joined
Jun 10, 2002
Posts
32,190
Reaction score
317
Location
Texas
My wife's laptop has picked up this Trojan Horse. Avast can't get rid of it.

Any suggestions on how to get rid of it.

There's not much on that computer so I could just use the restore disks and start all over.
 

Mulli

...
Supporting Member
Joined
Jul 16, 2004
Posts
52,529
Reaction score
4,601
Location
Generational
My wife's laptop has picked up this Trojan Horse. Avast can't get rid of it.

Any suggestions on how to get rid of it.

There's not much on that computer so I could just use the restore disks and start all over.
You could put the laptop in the garbage, throw it off a cliff, leave it out in the street, or leave it sitting in Starbucks. You have a lot of options really.
 
OP
OP
Duckjake

Duckjake

LEGACY MEMBER
LEGACY MEMBER
Joined
Jun 10, 2002
Posts
32,190
Reaction score
317
Location
Texas
You could put the laptop in the garbage, throw it off a cliff, leave it out in the street, or leave it sitting in Starbucks. You have a lot of options really.

I left it sitting in Starbucks last week. Now I have two laptops.
 

UncleChris

Shocking, I tell you!
Supporting Member
Joined
Mar 24, 2003
Posts
31,598
Reaction score
15,896
Location
Prescott, AZ
First, see if a boot scan will remove the virus, if not, try this (from http://www.sophos.com/security/analyses/trojconhookb.html):

Windows XP/2003
You will first need to prevent use of the following registry entry, if it is present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. Select 'My Computer'. On the 'File' menu, click 'Export'. Save your registry as Backup.

Select HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

Right-click '<Trojan_entry>'

Select 'Permissions'

In the 'Permissions for...' dialog, click 'Advanced'

In the 'Advanced Security Settings for...' dialog, deselect 'Inherit from parent the permission entries that apply to child objects.'

In the Security dialog, click 'Remove'

Click 'OK'

Click 'Yes' to deny everyone access to the key

Click 'OK'

Close the registry editor.

Follow the Safe Mode with Command Prompt instructions for removing Trojans. \

Re-open the registry editor to delete the Trojan registry entries.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Select HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

Right-click '<Trojan_entry>'

Select 'Permissions'

In the 'Permissions for...' dialog, click 'Advanced'

In the 'Advanced Security Settings for...' dialog, select 'Inherit from parent the permission entries that apply to child objects.'

Click 'OK' twice

Right-click '<Trojan_entry>'

Select 'Delete'

Click 'Yes' to delete the key

Close the registry editor.
 
Last edited:
Top