Computing.Net > Forums > Security and Virus > loggba.dll Virus prevents removal

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

loggba.dll Virus prevents removal

Reply to Message Icon

Original Message
Name: keith.donahue
Date: July 21, 2004 at 06:51:08 Pacific
Subject: loggba.dll Virus prevents removal
OS: win2k
CPU/Ram: P4 256MB
Comment:

Looks like a new virus that can't be removed by ANY software. I started getting \winnt\system32\loggba.dll backdoor trojan virus alerts from NAV yesterday. NAV can't get rid of it, isolate it or quarantine it! Booting in to safe mode makes no difference, same outcome. Here's the kicker: If you open windows explorer, the file loggba.dll is not shown. Yes, I have show all files, hideen and OS checked. But, if you go to a command pronpt, I can see it @ 50kb ! trying to delete it results in file in use errors. Boot in to safe mode, file does not show in command prompt, but, trying to create a fake file with that name results in File Exists and in use, but, it's not there! Tried several programs on the web to remove it with no luck. Adaware fails also. Mainly because it can't be seen in windows explorer, thus, the scanners miss it. Tried to send it to Symantec using their software but they use a win32 drag and drop util that can't see it either! sure wish they had a file attach function instead. Seems like a new backdoor trojan that can't be removed and NAV and friends need to figure out how to scan files that don't show under typical windows explorer functionality. Any ideas how to get rid of a file like this? Sure hope I'm protected behind my LinkSys router.

Keith D


Report Offensive Message For Removal


Response Number 1
Name: Jeruvy
Date: July 21, 2004 at 14:09:38 Pacific
Reply:

You have:
backdoor trojan virus alerts from NAV yesterday.

And NAV can't get rid of it? Is this an older version of the NAV engine? NAV2004 should be able to locate the ADS file and remove it or at least quarantine it.

Do a google for "LADS" this is a command line tool to list alternative data streams. This should help you find the trojan. Keep in mind many legit apps use ADS so don't delete everything you see. RTFM first.

Good luck,


J.
j e r u v y a t y a h o o d o t c o m


Report Offensive Follow Up For Removal

Response Number 2
Name: keith.donahue
Date: July 24, 2004 at 10:00:17 Pacific
Reply:

I have the latest 2003 Nav and signature files and it does not catch the virus. But, I figured outhow to do it manually. On Win2000, boot in to command prompt mode, delete the virused file and place a fake one it it's place. mark it read only. reboot and watch it try to load, but now fail! Then, cleanthe registry and run adaware, nav (worthless again) and registry cleaners and bingo, it's history. Thanx to MS for allowing a html page to write files tothe disk with no security in mind.



Report Offensive Follow Up For Removal

Response Number 3
Name: Jeruvy
Date: July 25, 2004 at 09:01:08 Pacific
Reply:

It's not a virus, it's a trojan. Don't get confused.

NAV is not a trojan solution. It's not sold as a trojan solution.

Preventing trojans really requires smart users not downloading stuff from untrusted sites, and protecting their browsers and email from executing content they shouldn't. There are REAL bugs here also, but stupid user syndrome is biggest one of all.


J.
j e r u v y a t y a h o o d o t c o m


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: loggba.dll Virus prevents removal

Torjan Horse : pmkhf.dll Virus
    Summary: Virus Scan indicates Torjan Horse : pmkhf.dll Virus (can't be removed) HJT Logs are available when requested.Please help. ...
www.computing.net/answers/security/torjan-horse-pmkhfdll-virus/20858.html

w32/Alemond.f.dll virus
    Summary: I think w32/Alemond.f.dll virus has infected my wininet.dll file. (per McAfee virus scan) cannot clean or delete file. I found this after getting an that states the following: "Explorer.EXE-Applicatio...
www.computing.net/answers/security/w32alemondfdll-virus-/17793.html

Embedded ads, dll virus
    Summary: Well basically my problems started when i noticed a popup called HPProductAssistant (i think thats what it was called.) I think i took care of that, but soon after i started getting Symantec Auto-Resu...
www.computing.net/answers/security/embedded-ads-dll-virus/22386.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software