|
-
April 21st, 2001, 01:45 AM
#1
I got hit with a Virus. I need help
I got hit with a trojan horse virus that currupted my C:\WINDOWS\RUNDLLS.EXE. The Virus was called BackDoor-GK.svr. To get rid of the virus i had to delete the windows file adn i was wondering where I could get another file to replace it? Thanks for your help.
-
April 21st, 2001, 01:59 AM
#2
Off your windows install CD? 
Also please note that backdoors have many variants. Id be curious if that was the only file it infected. After being infected by a trojen I would reccomend a system wipe/re-install... oh the joy the joy of it all.
Never open untrusted files !
-
April 21st, 2001, 02:02 AM
#3
I would do it off of my windows cd buit i can't find it. Having a backdoor on my system dosent bother me all that much but now i am afraid to close down windows because i fear that it may not reboot.
-
April 21st, 2001, 02:05 AM
#4
Okay.... so do you at least have the cab files from the OS?? Either on the hdd or the orignal CD.... You need to use EXTRACT to get the needed file out of the cab file. Since if looks like you have at least a second computer, the current PKZIp for windows (shareware) will also decompress cab files. It will even show you the contents of the cab if you need to search it out...
Don't know how to use EXTRACT??? Go to Microsoft's Knowledgebase and seach for it.... Can't hold your hand all the way...
-
April 21st, 2001, 02:11 AM
#5
What .cab file might the RUNDLLS.EXE be found in?
-
April 21st, 2001, 02:36 AM
#6
-
April 21st, 2001, 12:20 PM
#7
Originally posted by ShadeInTheDark:
Thanks for all of your help you guys/gals. I have fixed the problem or so i think. If not i will be back but till then thanks again.
ShadeInTheDark
It could be very helpful to others if you would post your solution......
-
April 21st, 2001, 05:26 PM
#8
-
April 22nd, 2001, 12:18 AM
#9
Registered User
if you have win98 you can also use the system file checker to restore infected, corrupted or missing files.
-
April 24th, 2001, 09:46 AM
#10
I am infected with q virus which infects my windows files and gives it a .vir ending. what virus is this and how do I clear it.
-
April 24th, 2001, 04:10 PM
#11
The best cure for a virus short of buying a new HDD is Fdisk.exe. Not too many viruses can survive that. Store all Operating Systems and Programs one drive and get another for all your data. (A small 5-10GB is cheap now and it will hold alot of data.) That way you can get back up and running in no time flat. I have had a few viruses in my career and I just run Fdisk and then re-ghost.... problem solved. If you have a lot of data files you worry about periodically burn them to CD.
-
April 25th, 2001, 08:07 AM
#12
Warning,
If Just save your files to another HDD, then when you ghost the image onto the new HDD then you might be copying the virus as well. If you really need to wipe your drive then is best to lose all your data and not to copy any thing, that should teach you a lesson to install antivirus software and keep your DAT files UP TO DATE.
-
April 25th, 2001, 09:07 AM
#13
oops I missed that point. I use Norton AV 2000 and check weekly for new updates. I also check daily on windrivers to see the latest Anti-virus update section. That way I know if something is out between my weekly updates.
-
April 25th, 2001, 10:32 AM
#14
Registered User
Norton and Mcafee both have excellent sites that aid you in manual removal of virii. My suggestion is to take a little bit of time and LEARN about your virus. Read up on and it figure out EXACTLY what it is doing to your system. Only once you understand your virus will you be able to feel safe about your system once you've cleaned it.
Also *note*: If the virus is bad enough to cause a complete system re-load and you do the f-disk thing. Do this command as well-->
fdisk /mbr
/*This command fdisks your Master Boot Record*/ It's a nasty place a virus can hang out and resurface after a perfectly good fdisk/format/clean install.
if(post.eof()){SigBox.setText("Have A Day.");}
-
April 26th, 2001, 05:47 PM
#15
Registered User
If you can't find help at the microsoft site for extracting the cab file or getting rid of the virus, Symantec should have help on their site.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|
Bookmarks