Has Microsoft started sending out an infected file? KB896727 bak.dll

M

M Skabialka

In trying to get rid of spyware called WinFixer or Virtumonde I have tracked
it down to a file on the PC called:

C:\WINDOWS\$N72CA~1\bak.dll

This folder is also the $NtUninstallKB896727$ folder.

If I uninstall the Microsoft patch 896727 the spyware goes away. If I
download it again from Microsoft and reinstall it, it comes back. The date
on it is 28 Aug 05.

Has Microsoft started sending out an infected file?

I am unable to remove this spyware with everything I have found at
majorgeeks.com, short of doing the Hijack this report. Under Safe mode with
command prompt I cannot get to the folder.

cd\windows
cd $N72CA~1
The system cannot find the path specified.

Under safe mode or normal mode I can get to the folder the cannot delete the
file because it is in use.

When I uninstall KB896727 I get a message that many programs (including
anti-virus ones) will no longer run, which is why I reinstalled it.

I have spent two days now trying everything under the sun to clear this
monster from this machine.

Please help,
Thanks,
Mich
 
M

M Skabialka

That is a godd analysis, but is there a fix for this?
Can I just delete all of the files, folders, registry entries, etc shown and
it will go away?

Ad-Aware is supposed to clean it but it doesn't.

Mich
 
V

Vanguard \(NPI\)

M Skabialka said:
That is a godd analysis, but is there a fix for this?
Can I just delete all of the files, folders, registry entries, etc shown
and it will go away?

Ad-Aware is supposed to clean it but it doesn't.

Mich


You expect good behavior on an infected machine? You deleted a directory.
The file goes away. You recreate the directory and it reappears. So how do
you know that the virus isn't the one copying itself there when the
directory reappears?

Did you try rebooting into Safe Mode and then using Ad-Aware, Spybot, MSAS,
Spyware Doctor, or whatever to get rid of it when it is more likely not to
be running?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top