Welcome to SecurityForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Unable to remove dlls placed by Trojan

 
   Security Forums (Home) -> General Discussions RSS
Next:  Which free trojan scanner can remove "target..  
Author Message
Llew Williams

External


Since: Oct 05, 2004
Posts: 2



(Msg. 1) Posted: Tue Oct 05, 2004 6:17 am
Post subject: Unable to remove dlls placed by Trojan
Archived from groups: alt>comp>virus (more info?)

I have been wrestling with a Trojan on my venerable old Win 98
machine. I have removed the Trojan using Norton. Ran Hijack This and
ADWare and it all looks clean. I am still getting a "No internet
connection available" dialog when I boot. Killing RunDll seems to
stop it.

Today's specific problem: I has identified a couple of dlls in
c:\windows\system\ that were placed there at the time when we got the
Trojan. One is NtNDI.DLL produced by NicTech. When I try to delete
them in Windows I get a message that Windows is using them. I boot in
Dos and I can't see them. So I run attrib. They are set to rsh. I
cannot delete them. It try to use attrib to turn off the hidden
attribute -h. I get a message saying Attribute not set on NdNDI.dll.
Now what ?

Maybe I should check the file date on attrib? Could it have been
replaced?

I tried booting from a floppy but I can't get it to load.

Llew

 >> Stay informed about: Unable to remove dlls placed by Trojan 
Back to top
Login to vote
Skorpion

External


Since: Oct 06, 2004
Posts: 4



(Msg. 2) Posted: Tue Oct 05, 2004 11:04 am
Post subject: Re: Unable to remove dlls placed by Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Llew Williams regaled us with the following:

> I have been wrestling with a Trojan on my venerable old Win 98
> machine. I have removed the Trojan using Norton. Ran Hijack This and
> ADWare and it all looks clean. I am still getting a "No internet
> connection available" dialog when I boot. Killing RunDll seems to
> stop it.
>
> Today's specific problem: I has identified a couple of dlls in
> c:\windows\system\ that were placed there at the time when we got the
> Trojan. One is NtNDI.DLL produced by NicTech. When I try to delete
> them in Windows I get a message that Windows is using them. I boot in
> Dos and I can't see them. So I run attrib. They are set to rsh. I
> cannot delete them. It try to use attrib to turn off the hidden
> attribute -h. I get a message saying Attribute not set on NdNDI.dll.
> Now what ?
>
> Maybe I should check the file date on attrib? Could it have been
> replaced?
>
> I tried booting from a floppy but I can't get it to load.
>
> Llew

Remove the system attribute on that file before trying to remove the hidden
or readonly attributes...

Yes, attrib *could* have been replaced but I would try the above before
worrying about that.

Also, be certain to choose "safe mode command prompt only" so that *nothing*
is loaded at boot and you are dropped immediately to the command prompt.

- --
Skorpion [skorpion at suespammers dot org]
"Don't attribute to malice that which can be adequately explained by
stupidity."

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBYsYPcTBCVvf50kkRApB5AKDDEkPwIvNTI0/18a35As7kjMTR/gCZAfEB
P6AXEL1WoaD+VdvMQjh/NnY=
=+vGm
-----END PGP SIGNATURE-----

 >> Stay informed about: Unable to remove dlls placed by Trojan 
Back to top
Login to vote
Llew Williams

External


Since: Oct 05, 2004
Posts: 2



(Msg. 3) Posted: Wed Oct 06, 2004 1:46 pm
Post subject: Re: Unable to remove dlls placed by Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Skorpion wrote in message ...
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Llew Williams regaled us with the following:
>
> > I have been wrestling with a Trojan on my venerable old Win 98
> > machine. I have removed the Trojan using Norton. Ran Hijack This and
> > ADWare and it all looks clean. I am still getting a "No internet
> > connection available" dialog when I boot. Killing RunDll seems to
> > stop it.
> >
> > Today's specific problem: I has identified a couple of dlls in
> > c:\windows\system\ that were placed there at the time when we got the
> > Trojan. One is NtNDI.DLL produced by NicTech. When I try to delete
> > them in Windows I get a message that Windows is using them. I boot in
> > Dos and I can't see them. So I run attrib. They are set to rsh. I
> > cannot delete them. It try to use attrib to turn off the hidden
> > attribute -h. I get a message saying Attribute not set on NdNDI.dll.
> > Now what ?
> >
> > Maybe I should check the file date on attrib? Could it have been
> > replaced?
> >
> > I tried booting from a floppy but I can't get it to load.
> >
> > Llew
>
> Remove the system attribute on that file before trying to remove the hidden
> or readonly attributes...
>
> Yes, attrib *could* have been replaced but I would try the above before
> worrying about that.
>
> Also, be certain to choose "safe mode command prompt only" so that *nothing*
> is loaded at boot and you are dropped immediately to the command prompt.
>
> - --
> Skorpion [skorpion at suespammers dot org]
> "Don't attribute to malice that which can be adequately explained by
> stupidity."
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.2.4 (GNU/Linux)
>
> iD8DBQFBYsYPcTBCVvf50kkRApB5AKDDEkPwIvNTI0/18a35As7kjMTR/gCZAfEB
> P6AXEL1WoaD+VdvMQjh/NnY=
> =+vGm
> -----END PGP SIGNATURE-----

I did try to remove the -s. Same deal not changed.

Then I borrowed a copy of Knoppx linux on a cd. Booted from the cd
and removed the offending dlls.
 >> Stay informed about: Unable to remove dlls placed by Trojan 
Back to top
Login to vote
Gabriele Neukam

External


Since: Sep 14, 2004
Posts: 462



(Msg. 4) Posted: Thu Oct 07, 2004 6:08 pm
Post subject: Re: Unable to remove dlls placed by Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On that special day, Llew Williams, (llew.williams@es3.titan.com)
said...

> I did try to remove the -s. Same deal not changed.

Change all at once. Do

attrib -shr badfile.nam

This should work. HTH,


Gabriele Neukam

Gabriele.Spamfighter.Neukam RemoveThis @t-online.de


--
Ah, Information. A good, too valuable these days, to give it away, just
so, at no cost.
 >> Stay informed about: Unable to remove dlls placed by Trojan 
Back to top
Login to vote
Teresa Fair

External


Since: Oct 15, 2004
Posts: 3



(Msg. 5) Posted: Fri Oct 15, 2004 8:28 pm
Post subject: Re: Unable to remove dlls placed by Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

The trojan/virus is called 'look4me' and apparently is quite new. Most
antivirus/adware/spyware programs do not know what to look for because most
of the files are in the windows/system folder with the attributes of
hidden/read-only/system. The only way I figured it out, after the second
formatting in 2 weeks, was by installing Kerio Firewall.
I have tracked down the person(s)/corporations involved. By the way,
one of them is a large ISP company in Texas. I am sending the virus files
to the antivirus companies and the information on these culprets to the
proper authorities for prosecution.
I hope this information helps.

"Gabriele Neukam" wrote in message

> On that special day, Llew Williams, (llew.williams@es3.titan.com)
> said...
>
> > I did try to remove the -s. Same deal not changed.
>
> Change all at once. Do
>
> attrib -shr badfile.nam
>
> This should work. HTH,
>
>
> Gabriele Neukam
>
> Gabriele.Spamfighter.Neukam.RemoveThis@t-online.de
>
>
> --
> Ah, Information. A good, too valuable these days, to give it away, just
> so, at no cost.
 >> Stay informed about: Unable to remove dlls placed by Trojan 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Trojan Horses - Unable to Remove - Hello, Norton has detected two viruses on my system: 1) backdoor trojan (didn't specify which exactly) 2) bllodhound.exploit.6 It hasn't removed them and when I tried follozing the instructions for manual removal, the registry parameters indictaed in....

How to remove Trojan.Mitglieder.C? - Does anyone know how to remove Trojan.Mitglieder.C? Any tools for removing the above virus? Thank you.

How to remove Trojan WebDL-K - on Windows Xp Professional... file infected is c:\windows\system32\aupdate.exe I don't have floppy disk.

How do I remove trojan.vundo - How do I remove trojan.vundo without paying an expensive program. Helge

HELP - Wimad. E Trojan, HOW REMOVE? -
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]