Shoutbox

Are These Genuine System Files? - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: Are These Genuine System Files? (/showthread.php?tid=76933)

Are These Genuine System Files? by M73A on 08-22-2007 at 11:05 AM

well i had a trojan, and i've been on the clean up for the past day...

these files came up in scans, is it safe to delete them (shred them with tune up utilities)...

i think i read that the trojan created them, so they shouldn't brake my pc if i do delete them... but just wanted to check they're nothing vital... they are:

c:\windows\system32\ntcvx32.dll

c:\windows\system32\ntswrl32.dll

thanks

EDIT: i have googled them and they come up with a lot of forums about spyware and trojans etc.... but i wanted to know if they are part of windows. thanks


RE: Are These Genuine System Files? by andrewdodd13 on 08-22-2007 at 11:13 AM

I have neither on my XP installation, they sound dodgy to me.


RE: Are These Genuine System Files? by M73A on 08-22-2007 at 11:21 AM

shredding time:P

found this

quote:
Originally posted by sophos website


This section is for technical experts who want to know more.

Troj/Bdoor-YP is a Trojan for the Windows platform.

When first run Troj/Bdoor-YP copies itself to <System>\vssms32.exe and
creates the following files:

<Windows>\hkr32.asm
<System>\ldapi32.exe
<System>\ntcvx32.dll
<System>\ntswrl32.dll

The following registry entry is created to run vssms32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
vssms32
<System>\vssms32.exe

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\List\
<Windows>\System32
vssms32.exe
<System>\vssms32.exe:*:Enabled:Dnode

Registry entries are created under:

HKCU\Software\

Troj/Bdoor-YP also attempts to install the Trojans Troj/Mpass-B and
Troj/LdPinch-IP.



RE: Are These Genuine System Files? by Pyro on 08-25-2007 at 04:40 AM

also go to run and type MSCONFIG
make sure that they arnt in the startup tab. if u arnt sure about files in the startup tab then just google them


RE: Are These Genuine System Files? by M73A on 08-25-2007 at 09:40 AM

ah that was the first thing i did... the dodgy startup entry of vssms32.exe is what led me to find the .dll's!