Midtown Computer Systems Enterprise

Convenient web based access to our favorite computer related Usenet groups.
MCSE.MS is not affiliated with Microsoft corporation, Cisco corporation, Oracle, CompTIA or any other vendor.
Check our Computer Hardware forum | Cell Phones reviews

Go Back  MCSE > Microsoft software reviews > Computer Security reviews > Virus
This is Interesting: Free Computer Magazines Now Free shipping to

Virus microsoft.public.security.virus

 
 
Thread Tools Display Modes
  #1  
Old 07-19-04, 08:23 PM
Carolyn
Backdoor.Trojan
I'm getting about 100 Norton Alerts every 30 minutes -
backdoor.trojan found in Windows/System32/sqladmb.dll
Norton will say "can't fix," "can't quarantine", "denied
access".
I'm so frustrated! I've scanned, I've gone to Symantec
and tried their solution, I've just plain hunted it down
and I can't delete it!!
Does anyone have some suggestions, please?
Thanks!!!
  #2  
Old 07-20-04, 05:19 AM
Ron Chamberlin
Re: Backdoor.Trojan
Carolyn,

OK, step back and take a deep breath for a moment. Go back to the Symantec
page for the exact name of the virus that it is reporting, and follow those
instructions. Chances are it will want you to disable System Restore (for
the time being), and will need to have you do a virus scan from Safe Mode.
This is pretty standard fare, and most AV products can't knock out something
that is active in memory, and /or residing in the System Restore files.

Ron Chamberlin
MS-MVP


> I'm getting about 100 Norton Alerts every 30 minutes -
> backdoor.trojan found in Windows/System32/sqladmb.dll
> Norton will say "can't fix," "can't quarantine", "denied
> access".
> I'm so frustrated! I've scanned, I've gone to Symantec
> and tried their solution, I've just plain hunted it down
> and I can't delete it!!
> Does anyone have some suggestions, please?
> Thanks!!!



  #3  
Old 07-22-04, 06:11 PM
wichitajim wichitajim is offline
Junior Member
Join Date: Jul 2004
Re: Re: Backdoor.Trojan
I am working to resolve the same situation only my file is named logboje.dll  When you follow the instructions from Symantec to scan in safe mode, the file does not exist.  I can browse the system32 folder and see that it is not there and run a full scan and finds nothing.  Log back in to Normal mode and its back!   Still working on it.


Quote:
Originally posted by Ron Chamberlin
Carolyn,

OK, step back and take a deep breath for a moment. Go back to the Symantec
page for the exact name of the virus that it is reporting, and follow those
instructions. Chances are it will want you to disable System Restore (for
the time being), and will need to have you do a virus scan from Safe Mode.
This is pretty standard fare, and most AV products can't knock out something
that is active in memory, and /or residing in the System Restore files.

Ron Chamberlin
MS-MVP


> I'm getting about 100 Norton Alerts every 30 minutes -
> backdoor.trojan found in Windows/System32/sqladmb.dll
> Norton will say "can't fix," "can't quarantine", "denied
> access".
> I'm so frustrated! I've scanned, I've gone to Symantec
> and tried their solution, I've just plain hunted it down
> and I can't delete it!!
> Does anyone have some suggestions, please?
> Thanks!!!
  #4  
Old 07-24-04, 04:39 AM
omaen omaen is offline
Junior Member
Join Date: Jul 2004
Backdoor.Trojan
I have the same problem, this is what norton pops up with:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Backdoor.Trojan
File: C:\WINDOWS\System32\winkdp.dll
Location: C:\WINDOWS\System32
Computer: Irrelevant
User: Irrelevant
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Sat Jul 24 17:30:45 2004

It pops up everytime an application is started and the .dll is deleted before norton can respond (i think) - i'm guessing it is a windows service. but i don't know how to terminate it. I also can't find the original file causing the infection.

Any help would be nice. Thanks.
 


Popular forums
A+ (A Plus) Windows 2000 Active directory Exchange 2000 information store
Network+ Windows XP Security Exchange 2000 server administration
MCSE .NET Web services SQL Server
Cisco certification ASP .NET SQL 2000 Programming
Windows 2000 Registry .NET XML Viruses


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 11:30 AM.


Powered by vBulletin Version 3.6.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright MCSE braindumps 2003-2006