|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
loggba.dll Virus prevents removal
|
Original Message
|
Name: keith.donahue
Date: July 21, 2004 at 06:51:08 Pacific
Subject: loggba.dll Virus prevents removal OS: win2k CPU/Ram: P4 256MB
|
Comment: Looks like a new virus that can't be removed by ANY software. I started getting \winnt\system32\loggba.dll backdoor trojan virus alerts from NAV yesterday. NAV can't get rid of it, isolate it or quarantine it! Booting in to safe mode makes no difference, same outcome. Here's the kicker: If you open windows explorer, the file loggba.dll is not shown. Yes, I have show all files, hideen and OS checked. But, if you go to a command pronpt, I can see it @ 50kb ! trying to delete it results in file in use errors. Boot in to safe mode, file does not show in command prompt, but, trying to create a fake file with that name results in File Exists and in use, but, it's not there! Tried several programs on the web to remove it with no luck. Adaware fails also. Mainly because it can't be seen in windows explorer, thus, the scanners miss it. Tried to send it to Symantec using their software but they use a win32 drag and drop util that can't see it either! sure wish they had a file attach function instead. Seems like a new backdoor trojan that can't be removed and NAV and friends need to figure out how to scan files that don't show under typical windows explorer functionality. Any ideas how to get rid of a file like this? Sure hope I'm protected behind my LinkSys router. Keith D
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: Jeruvy
Date: July 21, 2004 at 14:09:38 Pacific
|
Reply: You have: backdoor trojan virus alerts from NAV yesterday. And NAV can't get rid of it? Is this an older version of the NAV engine? NAV2004 should be able to locate the ADS file and remove it or at least quarantine it. Do a google for "LADS" this is a command line tool to list alternative data streams. This should help you find the trojan. Keep in mind many legit apps use ADS so don't delete everything you see. RTFM first. Good luck, J. j e r u v y a t y a h o o d o t c o m
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: keith.donahue
Date: July 24, 2004 at 10:00:17 Pacific
|
Reply: I have the latest 2003 Nav and signature files and it does not catch the virus. But, I figured outhow to do it manually. On Win2000, boot in to command prompt mode, delete the virused file and place a fake one it it's place. mark it read only. reboot and watch it try to load, but now fail! Then, cleanthe registry and run adaware, nav (worthless again) and registry cleaners and bingo, it's history. Thanx to MS for allowing a html page to write files tothe disk with no security in mind.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: Jeruvy
Date: July 25, 2004 at 09:01:08 Pacific
|
Reply: It's not a virus, it's a trojan. Don't get confused. NAV is not a trojan solution. It's not sold as a trojan solution. Preventing trojans really requires smart users not downloading stuff from untrusted sites, and protecting their browsers and email from executing content they shouldn't. There are REAL bugs here also, but stupid user syndrome is biggest one of all. J. j e r u v y a t y a h o o d o t c o m
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
Results for: loggba.dll Virus prevents removal
Torjan Horse : pmkhf.dll Virus Summary: Virus Scan indicates Torjan Horse : pmkhf.dll Virus (can't be removed) HJT Logs are available when requested.Please help. ... www.computing.net/answers/security/torjan-horse-pmkhfdll-virus/20858.html
w32/Alemond.f.dll virus Summary: I think w32/Alemond.f.dll virus has infected my wininet.dll file. (per McAfee virus scan) cannot clean or delete file. I found this after getting an that states the following: "Explorer.EXE-Applicatio... www.computing.net/answers/security/w32alemondfdll-virus-/17793.html
Embedded ads, dll virus Summary: Well basically my problems started when i noticed a popup called HPProductAssistant (i think thats what it was called.) I think i took care of that, but soon after i started getting Symantec Auto-Resu... www.computing.net/answers/security/embedded-ads-dll-virus/22386.html
|
|

|