Computing.Net > Forums > Windows XP > Backdoor.Trojan and NAV

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Backdoor.Trojan and NAV

Reply to Message Icon

Name: Telemachus
Date: July 22, 2004 at 02:21:20 Pacific
OS: winxp home
CPU/Ram: 1,4 ghz/512 mb ddr
Comment:

I have the Backdoor.Trojan virus on my computer and I went to Symantec.com to get removal instructions. It informed me to do the live update and to update my virus definitions, run my computer in safe mode, and it should find it and detect it. I did all of this and my computer completed the scan without finding anything. I know I have the virus because my Norton virus finder pops up every minute or so to day that it found the backdoor.trojan virus but couldn't quarantine it or delete it. I was wondering if anybody knows what I should do to get rid of this annoyance.I also used the latest Ad Aware and Spybot wihout much help
Please help me get rid of this nuisance Thanks in advance

sbasti01



Sponsored Link
Ads by Google

Response Number 1
Name: radical_monster
Date: July 22, 2004 at 05:01:24 Pacific
Reply:

To be sure if your computer is still infected with the virus or not you can do an online virus scan at http://housecall.antivirus.com


0

Response Number 2
Name: Telemachus
Date: July 22, 2004 at 05:28:00 Pacific
Reply:

But my problem is the NAV pop up message which pops every one minute
Please help


sbasti01


0

Response Number 3
Name: RussellR
Date: July 22, 2004 at 05:28:04 Pacific
Reply:

if your virus scanner quarantines a virus when system restore is turned on, then it can cause problems ... sometime, norton AV detects ghost viruses. as the above post suggests, try running an online scan to double-check


0

Response Number 4
Name: heschg
Date: July 22, 2004 at 08:26:37 Pacific
Reply:

I have the smae problem. Have used Symantec's recommendations to no avail. continue to get Backdoor Trojan as a norton pop up.... but can't find in any scan. The file is supposedly a Windows system 32 file wdmb.dll.... It also turns off auto protect and e:mail scanniing on my Norton system. Any one have any ideas?


0

Response Number 5
Name: VerilySo
Date: July 22, 2004 at 08:28:07 Pacific
Reply:

I just struggled with this problem. Here is how I got rid of this trojan.
Turn off System Restore.
Do a Housecall free virus scan at http://housecall.antivirus.com, then go to...
http://forums.spywareinfo.com/index.php?&act=
ST&f=30&t=10469
Read the blue text from acomputerpro.
(If this does not work then google: AppInit_Dlls registry, and select the link SWI Forums - Successful removal of CWS.Search.X and read the blue text from acomputerpro.
Goodluck and let me know if it works.


0

Related Posts

See More



Response Number 6
Name: Telemachus
Date: July 22, 2004 at 21:20:11 Pacific
Reply:

The pop up window called "Virus Alert" from Norton Antivirus is persisting ;
Any other way to get rid of this??
Thanks

sbasti01


0

Response Number 7
Name: JohnFZ
Date: July 22, 2004 at 23:06:54 Pacific
Reply:

Alright I was able to figure out how to get rid of this pesky bug through all of your help (Windows XP only). So here is the fix. Close out any unecessary service/app that is running by using task manager. Go to the registry and clear not delete the AppInit_DLLs string. Reboot your system in safemode command prompt. Delete the file that has been giving you problems (this varies from system to system) ex: c:\windows\system32\del comjgfn.dll Restart and all should be fine.


0

Response Number 8
Name: Telemachus
Date: July 23, 2004 at 01:24:20 Pacific
Reply:

Dear all
The problem still persists;
John FZ i tried to delete using c:\windows\system32\del log.dll
The name of my object in the NAV pop up is
c:\windows\system32\log.dll
Any other ideas to kill this NAV pop up called Virus Alert??
Thanks in advance

sbasti01


0

Response Number 9
Name: VerilySo
Date: July 23, 2004 at 09:20:35 Pacific
Reply:

Telemachus,
Try these instructions. They worked for me.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
You have to remove this key. This key tells Windows to load the Trojan DLL every time ANY application is run. You need to remove it so that the Trojan DLL cannot load and keep re-infecting your PC.
If you just delete it from RegEdit, it will re-add itself. (Try it. Delete the AppInit_DLLs key and hit F5. Notice it immediatly reappears).
Do the following:
1. Rename the HLM\Software\Microsoft\Windows NT\CurrentVersion\Windows folder to Windows2 (select Windows folder and RT click, rename).
2. Now delete the AppInit_DLLs key under the Windows2 folder.
3. Hit F5 and notice that AppInit_DLLs doesn't come back.
4. Rename the Windows2 folder back to Windows.
Now that AppInit_DLLs is gone, run the latest AdAware 6 and Housecall to remove any Trojan remnants for good. Reboot your machine. Check the registry and make sure AppInit_DLLs is still gone. Your computer should be free of this for good now.
On this computer, there was an infected .dll file in the Windows\System32 directory called comojgl.dll which was detected by Norton, but could not delete. Norton reported the infection as BackDoor.Agent.A. The file, comojgl.dll, was the Trojan. Until I deleted the file using the rename Windows folder trick, Norton continued to report it with the annoying NAV Alert. After reboot, the NAV reported it had deleted it. I was just happy it was gone.
Goodluck


0

Response Number 10
Name: Telemachus
Date: July 23, 2004 at 10:59:18 Pacific
Reply:

Dear Verily Slow
I shall try and let you know the result
Thanks very much


sbasti01


0

Response Number 11
Name: jaymelee
Date: July 24, 2004 at 09:07:20 Pacific
Reply:

thank you thank you thank you!

I have been struggling with this virus for the past couple of days and followed above directions. I just rebooted my computer and Norton told me that the virus is gone. (they took credit for deleting it, but whatever).
Thank you so much


0

Response Number 12
Name: Telemachus
Date: July 25, 2004 at 04:39:57 Pacific
Reply:

Dear Verily Slow
Thanks One Million
It worked at last
Finally the nagging window is gone
All credits to you Veryily Slo
Cheers
Telemachus


sbasti01


0

Response Number 13
Name: ebman74
Date: July 26, 2004 at 06:04:43 Pacific
Reply:

Can someone explain this removal process in "For Dummies" form? Were do I start? Please help a non IT guy out! I have to get rid of this virus!!
Thank You in advance,
Greg


0

Response Number 14
Name: oneoverzero
Date: July 26, 2004 at 13:10:58 Pacific
Reply:

VerilySo,

Thank you very much, you made my headache went away.

Ebman74,

Go to START, > RUN (type REGEDIT) > a registry editor will come up > click on folder called HKEY_LOCAL_MACHINE > Then folder SOFTWARE > then MICROSOFT > WINDOWS NT > Then CURRENT VERSION >WINDOWS > Then look to the right panel there should be a file called "AppInit_DLLs". Now go back to the left panel and highlight the WINDOWS folder > then right click on the mouse > go to RENAME > you need to rename WINDOWS to WINDOWS2 > then go to the right panel and delete the file called "AppInit DLLs". Once it's deleted, back to the folder that you renamed to WINDOWS2, right click and rename it back to WINDOWS. After that reboot your computer, you should be on your way of free Back Door Trojan virus. Hope this help!


0

Response Number 15
Name: oldhokie
Date: July 27, 2004 at 05:45:18 Pacific
Reply:

I'm wrestling with this same trojan on a Windows 2K Pro box. I tried the regedt trick renaming the Windows subtree and that won't work as W2K doesn't have a rename option (no rightclick menu). I also tried booting into safemode to edit the registry and delete the file but that doesn't work because the file's not there and while the key exists there is no value set. There must be some startup task that creates/renames the file and sets the key. My next attempt is to run NAV from safemode but I'm open to suggestions....

Thanks,

Dan


0

Response Number 16
Name: DickRowland
Date: August 10, 2004 at 07:09:41 Pacific
Reply:

I have an emachine with XP, and the same backdoor problem. My questionable file is resd.dll, reported as infected, but can not be found anywhere on the machine.
Searching the complete registry, I can't find any entry for Applnit, anywhere.
Meanwhile, I continue to get popups stating that I am infected with the backdoor virus, and then I get a lot of ads, trying to sell me the programming to get rid of it.
Is it possible that the people who sell the product, also created a fake infection, just to make a sale?
I AM FRUSTRATED!!!!

Dick Rowland
dickrowland@sbcglobal.net


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: Backdoor.Trojan and NAV

LOGNM.dll > Backdoor.Trojan www.computing.net/answers/windows-xp/lognmdll-backdoortrojan/110601.html

Backdoor Trojan virus www.computing.net/answers/windows-xp/backdoor-trojan-virus/57957.html

Backdoor trojan/help www.computing.net/answers/windows-xp/backdoor-trojanhelp/68940.html