knowledge-database (beta)

Current group: comp.security.firewalls

mysterious dll

mysterious dll  
Siddharam Shingshetty
 Re: mysterious dll  
Jeff Gaines
From:Siddharam Shingshetty
Subject:mysterious dll
Date:24 Jan 2005 00:21:38 -0800
Hello,


There seems to some adware/malware/spyware/ etc being installed. I have
eradicated many of those using ad-aware and other similar softwares.

I am using Windows XP professional (SP1)

But all these anti-spywares, are not able to remove a particular
spyware process, which is in the form of dll. I tried to manually
delete the dll, but access was denied as it was in use.

The mysterious part is, now if I am in pure DOS mode (using a bootable
diskette) in an attempt to delete the dll, it is not there at all. And
next time I boot my XP, that particular dll is not there, but another
dll with some other name is present, and again I cannot delete it as it
is in use.

Any idea to eradicate it????? The ad-aware is showing it is from some
VX vendor.


Help very much appreciated.

Regards,
Siddharam S
From:Jeff Gaines
Subject:Re: mysterious dll
Date:24 Jan 2005 08:59:43 GMT
On 24/01/2005 Siddharam Shingshetty wrote:

> Hello,
>
>
> There seems to some adware/malware/spyware/ etc being installed. I
> have eradicated many of those using ad-aware and other similar
> softwares.
>
> I am using Windows XP professional (SP1)
>
> But all these anti-spywares, are not able to remove a particular
> spyware process, which is in the form of dll. I tried to manually
> delete the dll, but access was denied as it was in use.
>
> The mysterious part is, now if I am in pure DOS mode (using a bootable
> diskette) in an attempt to delete the dll, it is not there at all. And
> next time I boot my XP, that particular dll is not there, but another
> dll with some other name is present, and again I cannot delete it as
> it is in use.
>
> Any idea to eradicate it????? The ad-aware is showing it is from some
> VX vendor.


Often the best thing to do with stuff like this is to Google for the
name or search for it on Symantec's site, which may lead to removal
instructions. Some of it is very clever at re-producing.


--
Jeff Gaines
Posted with XanaNews 1.17.1.2
   

Copyright © 2006 knowledge-database   -   All rights reserved