Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I have the Backdoor.Trojan virus on my computer and I went to Symantec.com to get removal instructions. It informed me to do the live update and to update my virus definitions, run my computer in safe mode, and it should find it and detect it. I did all of this and my computer completed the scan without finding anything. I know I have the virus because my Norton virus finder pops up every minute or so to day that it found the backdoor.trojan virus but couldn't quarantine it or delete it. I was wondering if anybody knows what I should do to get rid of this annoyance.I also used the latest Ad Aware and Spybot wihout much help
Please help me get rid of this nuisance Thanks in advancesbasti01

To be sure if your computer is still infected with the virus or not you can do an online virus scan at http://housecall.antivirus.com

if your virus scanner quarantines a virus when system restore is turned on, then it can cause problems ... sometime, norton AV detects ghost viruses. as the above post suggests, try running an online scan to double-check

I have the smae problem. Have used Symantec's recommendations to no avail. continue to get Backdoor Trojan as a norton pop up.... but can't find in any scan. The file is supposedly a Windows system 32 file wdmb.dll.... It also turns off auto protect and e:mail scanniing on my Norton system. Any one have any ideas?

I just struggled with this problem. Here is how I got rid of this trojan.
Turn off System Restore.
Do a Housecall free virus scan at http://housecall.antivirus.com, then go to...
http://forums.spywareinfo.com/index.php?&act=
ST&f=30&t=10469
Read the blue text from acomputerpro.
(If this does not work then google: AppInit_Dlls registry, and select the link SWI Forums - Successful removal of CWS.Search.X and read the blue text from acomputerpro.
Goodluck and let me know if it works.

The pop up window called "Virus Alert" from Norton Antivirus is persisting ;
Any other way to get rid of this??
Thankssbasti01

Alright I was able to figure out how to get rid of this pesky bug through all of your help (Windows XP only). So here is the fix. Close out any unecessary service/app that is running by using task manager. Go to the registry and clear not delete the AppInit_DLLs string. Reboot your system in safemode command prompt. Delete the file that has been giving you problems (this varies from system to system) ex: c:\windows\system32\del comjgfn.dll Restart and all should be fine.

Dear all
The problem still persists;
John FZ i tried to delete using c:\windows\system32\del log.dll
The name of my object in the NAV pop up is
c:\windows\system32\log.dll
Any other ideas to kill this NAV pop up called Virus Alert??
Thanks in advancesbasti01

Telemachus,
Try these instructions. They worked for me.HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
You have to remove this key. This key tells Windows to load the Trojan DLL every time ANY application is run. You need to remove it so that the Trojan DLL cannot load and keep re-infecting your PC.
If you just delete it from RegEdit, it will re-add itself. (Try it. Delete the AppInit_DLLs key and hit F5. Notice it immediatly reappears).
Do the following:
1. Rename the HLM\Software\Microsoft\Windows NT\CurrentVersion\Windows folder to Windows2 (select Windows folder and RT click, rename).
2. Now delete the AppInit_DLLs key under the Windows2 folder.
3. Hit F5 and notice that AppInit_DLLs doesn't come back.
4. Rename the Windows2 folder back to Windows.
Now that AppInit_DLLs is gone, run the latest AdAware 6 and Housecall to remove any Trojan remnants for good. Reboot your machine. Check the registry and make sure AppInit_DLLs is still gone. Your computer should be free of this for good now.
On this computer, there was an infected .dll file in the Windows\System32 directory called comojgl.dll which was detected by Norton, but could not delete. Norton reported the infection as BackDoor.Agent.A. The file, comojgl.dll, was the Trojan. Until I deleted the file using the rename Windows folder trick, Norton continued to report it with the annoying NAV Alert. After reboot, the NAV reported it had deleted it. I was just happy it was gone.
Goodluck

thank you thank you thank you!
I have been struggling with this virus for the past couple of days and followed above directions. I just rebooted my computer and Norton told me that the virus is gone. (they took credit for deleting it, but whatever).
Thank you so much

Dear Verily Slow
Thanks One Million
It worked at last
Finally the nagging window is gone
All credits to you Veryily Slo
Cheers
Telemachus
sbasti01

Can someone explain this removal process in "For Dummies" form? Were do I start? Please help a non IT guy out! I have to get rid of this virus!!
Thank You in advance,
Greg

VerilySo,
Thank you very much, you made my headache went away.
Ebman74,
Go to START, > RUN (type REGEDIT) > a registry editor will come up > click on folder called HKEY_LOCAL_MACHINE > Then folder SOFTWARE > then MICROSOFT > WINDOWS NT > Then CURRENT VERSION >WINDOWS > Then look to the right panel there should be a file called "AppInit_DLLs". Now go back to the left panel and highlight the WINDOWS folder > then right click on the mouse > go to RENAME > you need to rename WINDOWS to WINDOWS2 > then go to the right panel and delete the file called "AppInit DLLs". Once it's deleted, back to the folder that you renamed to WINDOWS2, right click and rename it back to WINDOWS. After that reboot your computer, you should be on your way of free Back Door Trojan virus. Hope this help!

I'm wrestling with this same trojan on a Windows 2K Pro box. I tried the regedt trick renaming the Windows subtree and that won't work as W2K doesn't have a rename option (no rightclick menu). I also tried booting into safemode to edit the registry and delete the file but that doesn't work because the file's not there and while the key exists there is no value set. There must be some startup task that creates/renames the file and sets the key. My next attempt is to run NAV from safemode but I'm open to suggestions....
Thanks,
Dan

I have an emachine with XP, and the same backdoor problem. My questionable file is resd.dll, reported as infected, but can not be found anywhere on the machine.
Searching the complete registry, I can't find any entry for Applnit, anywhere.
Meanwhile, I continue to get popups stating that I am infected with the backdoor virus, and then I get a lot of ads, trying to sell me the programming to get rid of it.
Is it possible that the people who sell the product, also created a fake infection, just to make a sale?
I AM FRUSTRATED!!!!Dick Rowland
dickrowland@sbcglobal.net

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |