PC Review


Reply
Thread Tools Rate Thread

Backdoor.proratD trjan and registry

 
 
RMB
Guest
Posts: n/a
 
      5th Apr 2004
I have this virus which shuts down Norton antivirus and
firewall. I have 6 corrupted files: windows\winlogon.exe,
windows\system\service.exe, windows\systme32\fservice.exe
wincom.exe wininv.dll and winkey.dll. I cannot delete
the .dll files, even in safe mode as I am denied access.
I am told that the virus exists in the winkey.dll file.
I can delete the fservice and sservice, but they are
regenerated inmmediately(not so under safe mode, but once
reboot normal and they are there again). Registry changes
noted by norton and sophos I have found and deleted, but
they too are immediately replaced upon exiting registry,
again even under safe mode. Have noted no infestation (or
odd changes) of win.ini or system.ini files. In the
registry I notice that the HK
Root\htafile\shell\open\command is modified with a
mshta.exe file as is the
HKLM\software\classes\htafile\shell\open\command key and I
have read that these are 2 common places for virus
startup.

My questions are (and excuse the small list):

How do I delete the .dll files?
What is the mshta.exe file that exists in the WIN system
32 file and would deleting its reference from the registry
hurt?
How can this virus monitor reg changes and fix
immediately, even in safe mode and can I overcome.

I have windows XP pro with all updates. I appreciate
anyones assistance on this as Norton to date has not been
any help.
 
Reply With Quote
 
 
 
 
Juan
Guest
Posts: n/a
 
      8th Apr 2004
Greetings:

Go to one or both sites and perform scan(s) to find and delete the virus.

http://security.symantec.com/ssc/not...enid=sym&plfid
=23&pkj=AFQVPJUIYCZRWEJGSSK


http://www.pandasoftware.com/home/



Hope this helps.


-------------------Original Message------------------------
"RMB" <(E-Mail Removed)> escribió en el mensaje
news:186cb01c41b40$a23d74d0$(E-Mail Removed)...
> I have this virus which shuts down Norton antivirus and
> firewall. I have 6 corrupted files: windows\winlogon.exe,
> windows\system\service.exe, windows\systme32\fservice.exe
> wincom.exe wininv.dll and winkey.dll. I cannot delete
> the .dll files, even in safe mode as I am denied access.
> I am told that the virus exists in the winkey.dll file.
> I can delete the fservice and sservice, but they are
> regenerated inmmediately(not so under safe mode, but once
> reboot normal and they are there again). Registry changes
> noted by norton and sophos I have found and deleted, but
> they too are immediately replaced upon exiting registry,
> again even under safe mode. Have noted no infestation (or
> odd changes) of win.ini or system.ini files. In the
> registry I notice that the HK
> Root\htafile\shell\open\command is modified with a
> mshta.exe file as is the
> HKLM\software\classes\htafile\shell\open\command key and I
> have read that these are 2 common places for virus
> startup.
>
> My questions are (and excuse the small list):
>
> How do I delete the .dll files?
> What is the mshta.exe file that exists in the WIN system
> 32 file and would deleting its reference from the registry
> hurt?
> How can this virus monitor reg changes and fix
> immediately, even in safe mode and can I overcome.
>
> I have windows XP pro with all updates. I appreciate
> anyones assistance on this as Norton to date has not been
> any help.




 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan.Backdoor.Small.FB(backdoor) =?Utf-8?B?d2ZtMzE2?= Security and Anti-Spyware Community 5 25th Apr 2006 12:11 PM
Trojan.backdoor.small FB. backdoor =?Utf-8?B?UGV0ZXI=?= Spyware Discussion 2 15th Mar 2006 01:01 AM
Registry Question and Fending Off w32.korgo.v+Backdoor.berbew.g W. Watson Microsoft Windows 2000 3 8th Jul 2004 03:10 PM
I have 2 Trojans, "Trjan Downloader and Optimize, help! Tracker Anti-Virus 8 15th Jan 2004 05:48 PM
Backdoor Trojan affects registry Jenice Windows XP Basics 1 12th Dec 2003 02:34 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:45 AM.