S
Slashed Zero
Hello,
I seem to have catched a nasty worm through opening a .scr-file I got
through e-mail (from someone who thought to be a friend - I know, how stupid
can you be...). Anyways, I am totally unable to remove it from my system.
What it does is: it starts itself up in the registry and creates two
instances of itself in memory. When you terminate one of these processes,
the remaining instance re-instantiates the other in memory, so that there is
always at least one of these two running. What these files do is try to
access the internet and probably send all sorts of info to someone, but this
has been blocked by ZoneAlarm. The other thing that happens is that they
constantly check the registry, so that if you want to deleted the keys that
start them up, they immediately re-appear. When using a registry activity
monitor, you can see the bad processes constantly accessing the registry.
The bad files are:
winnt/system.dli
winnt/system32/services.dli
winnt/system32/tasks/explorer.exe
and all of these are ran in memory. System.dli and services.dli seem to be
identical files.
TDS-3 is powerless against this, or so it seems to me.
I have tried booting using a win98-bootdisk and manually deleting the bad
files from the command prompt (luckily my harddisk is still fat32-formatted)
and this works, but after win2000 reboot, the processes and files are back
there! This could be because I am unable to delete one file, called
explorer.exe, and placed in winnt./system32/tasks. I don't know what sort of
directory this is, it shows up when doing a dir, but I am unable to access
it at the command prompt.
So, there seems to be a circular thing going on, with processes constantly
covering each others backs. Neither (fully updated) AVG nor McAfee detect
anything.
Can anyone help me to get rid of this trojan?
Thanks VERY MUCH in advance!
I seem to have catched a nasty worm through opening a .scr-file I got
through e-mail (from someone who thought to be a friend - I know, how stupid
can you be...). Anyways, I am totally unable to remove it from my system.
What it does is: it starts itself up in the registry and creates two
instances of itself in memory. When you terminate one of these processes,
the remaining instance re-instantiates the other in memory, so that there is
always at least one of these two running. What these files do is try to
access the internet and probably send all sorts of info to someone, but this
has been blocked by ZoneAlarm. The other thing that happens is that they
constantly check the registry, so that if you want to deleted the keys that
start them up, they immediately re-appear. When using a registry activity
monitor, you can see the bad processes constantly accessing the registry.
The bad files are:
winnt/system.dli
winnt/system32/services.dli
winnt/system32/tasks/explorer.exe
and all of these are ran in memory. System.dli and services.dli seem to be
identical files.
TDS-3 is powerless against this, or so it seems to me.
I have tried booting using a win98-bootdisk and manually deleting the bad
files from the command prompt (luckily my harddisk is still fat32-formatted)
and this works, but after win2000 reboot, the processes and files are back
there! This could be because I am unable to delete one file, called
explorer.exe, and placed in winnt./system32/tasks. I don't know what sort of
directory this is, it shows up when doing a dir, but I am unable to access
it at the command prompt.
So, there seems to be a circular thing going on, with processes constantly
covering each others backs. Neither (fully updated) AVG nor McAfee detect
anything.
Can anyone help me to get rid of this trojan?
Thanks VERY MUCH in advance!