PC Review


Reply
Thread Tools Rate Thread

Is dssoundi.dll a valid OS file?

 
 
=?Utf-8?B?cG9nIHRoZSBwb290bGU=?=
Guest
Posts: n/a
 
      10th Feb 2006
I am having trouble getting rid of a virus on my home PC which my security
software (Trend Micro's PC-cillin 14) has IDed as TROJ_AGENT.AMV located in
the file C:\WINDOWS\system32\dssoundi.dll. My OS is XP Pro.

Is this file a valid OS .dll file or a fake one created by malware to
host the virus? If it is a valid OS file what does it do & what effect would
deleting it have?

I have tried running a Microsoft digital signature verification scan and the
name of the file did not come up as invalid (altho' for some reason the scan
didn't scan all the C drive files altho' that's what I specified). However
several people have suggested to me that such virus' often create fake files
to hang out in.

Any advice would be appreciated!

--
in winter
the seven stars
walk upon a crystal forest
 
Reply With Quote
 
 
 
 
Malke
Guest
Posts: n/a
 
      10th Feb 2006
pog the pootle wrote:

> I am having trouble getting rid of a virus on my home PC which my
> security software (Trend Micro's PC-cillin 14) has IDed as
> TROJ_AGENT.AMV located in the file C:\WINDOWS\system32\dssoundi.dll.
> My OS is XP Pro.
>
> Is this file a valid OS .dll file or a fake one created by malware to
> host the virus? If it is a valid OS file what does it do & what effect
> would deleting it have?
>
> I have tried running a Microsoft digital signature verification scan
> and the name of the file did not come up as invalid (altho' for some
> reason the scan didn't scan all the C drive files altho' that's what I
> specified). However several people have suggested to me that such
> virus' often create fake files to hang out in.
>
> Any advice would be appreciated!
>

Asked and answered in the other newsgroup to which you posted. Please do
not multipost - it wastes everyone's time. Here is a link explaining
that:
http://www.blakjak.demon.co.uk/mul_crss.htm

If you cannot find your original post, go to Google Groups Advanced
Search and search for your name.

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 
Reply With Quote
 
=?Utf-8?B?R3VudGFua2VyIFg=?=
Guest
Posts: n/a
 
      10th Mar 2006
I had the same problem. This is the nastiest virus I have ever had to deal
with. Somehow it infected internet explorer and explorer. It starts off as
"dssoundi.dll" then it creates another DLL file with a random name. It also
creates a randomly named EXE file with a clone OCX file of about 140KB in the
system32 folder. These are next to impossible to delete. The EXE file runs
constantly in the background, and as soon as explorer or another program
finds that the EXE file has been deleted, it deletes the OCX file and makes
another randomly named EXE and OCX file. Download these programs to help you
delete and detect the files:

WinPatrol
Unlocker

Also, learn how to use your command prompt in safe mode. You are going to
have to kill the EXE file and it doesn't always come up in task manager and
it also fools with your task manager too. Delete the registry files
(http://www.trendmicro.com/vinfo/viru...%2EAMV&VSect=T)
using regedit (START->RUN type in regedit and hit enter) and then find,
unlock, and delete the DLL files.

Here comes the tough part...

Restart the computer, and as soon as you see a black screen with a small
blinking white bar, start pressing F8 until the options come up. Select
"Safe Mode with Command Prompt." Let it boot up, and then close explorer and
task manager. In the command prompt (START->RUN type in cmd and hit enter if
you already closed it by accident) type in...


CD C:\WINDOWS\system32

tasklist

TASKKILL /F /T /IM file.exe

del file.exe

del file.ocx


You may have to unlock the OCX file before you delete it, so using the task
manager, go to FILE->RUN->BROWSE and then find the file, right click, and
unlock it. Also, tasklist will only tell you what tasks are running
regardless of what task manager says.

After all this, get a flash drive or floppy and put explorer.exe and
iexplore.exe on it from another PC and replace those files on your computer.


Fun huh? Actually, I am not even sure if this works fo really. That is
what I did so far. I still have yet to test it out.
 
Reply With Quote
 
=?Utf-8?B?R3VudGFua2VyIFg=?=
Guest
Posts: n/a
 
      13th Mar 2006
Woops. I lied about the second part. That was another virus:
Backdoor.ppdoor. I actually ended up using Ewido and Avast! anti-virus
programs in safe mode to get rid of that virus. And it didn't actually
infect explorer and iexplorer...so you didn't have to delete them. For some
reason, eTrust didn't detect it.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
file format or file extension is not valid...error message Ballun Microsoft Excel Misc 0 7th May 2009 09:06 PM
validating if a file is a true valid xml file that fits a certain schema Andy B Microsoft VB .NET 5 2nd Jul 2008 03:01 AM
Excel 2007 file format file extension not valid error =?Utf-8?B?TWF0dCBQaWVyY2U=?= Microsoft Excel Crashes 0 17th May 2007 04:41 PM
excel file 5.9MB trying 2 open but error "File format is not valid =?Utf-8?B?c2hlaHphZA==?= Microsoft Excel Crashes 0 3rd Aug 2006 03:01 PM
The selected file is not a valid VS solution file-error message Lance Geeck Microsoft VB .NET 2 9th May 2004 01:15 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 04:33 PM.