What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » Are These Genuine System Files?

Are These Genuine System Files?
Author: Message:
M73A
Veteran Member
*****

Avatar


Posts: 3213
Reputation: 37
34 / Male / Flag
Joined: Jul 2004
O.P. Are These Genuine System Files?
well i had a trojan, and i've been on the clean up for the past day...

these files came up in scans, is it safe to delete them (shred them with tune up utilities)...

i think i read that the trojan created them, so they shouldn't brake my pc if i do delete them... but just wanted to check they're nothing vital... they are:

c:\windows\system32\ntcvx32.dll

c:\windows\system32\ntswrl32.dll

thanks

EDIT: i have googled them and they come up with a lot of forums about spyware and trojans etc.... but i wanted to know if they are part of windows. thanks

This post was edited on 08-22-2007 at 11:06 AM by M73A.

[Image: lost7ru.gif]
08-22-2007 11:05 AM
Profile E-Mail PM Find Quote Report
andrewdodd13
Senior Member
****

Avatar
Oh so retro

Posts: 870
Reputation: 16
34 / Male / Flag
Joined: Jan 2005
RE: Are These Genuine System Files?
I have neither on my XP installation, they sound dodgy to me.
[Image: AndrewsStyle.png]
08-22-2007 11:13 AM
Profile E-Mail PM Web Find Quote Report
M73A
Veteran Member
*****

Avatar


Posts: 3213
Reputation: 37
34 / Male / Flag
Joined: Jul 2004
O.P. RE: Are These Genuine System Files?
shredding time:P

found this
quote:
Originally posted by sophos website


This section is for technical experts who want to know more.

Troj/Bdoor-YP is a Trojan for the Windows platform.

When first run Troj/Bdoor-YP copies itself to <System>\vssms32.exe and
creates the following files:

<Windows>\hkr32.asm
<System>\ldapi32.exe
<System>\ntcvx32.dll
<System>\ntswrl32.dll

The following registry entry is created to run vssms32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
vssms32
<System>\vssms32.exe

The following registry entries are set, affecting internet security:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\List\
<Windows>\System32
vssms32.exe
<System>\vssms32.exe:*:Enabled:Dnode

Registry entries are created under:

HKCU\Software\

Troj/Bdoor-YP also attempts to install the Trojans Troj/Mpass-B and
Troj/LdPinch-IP.



[Image: lost7ru.gif]
08-22-2007 11:21 AM
Profile E-Mail PM Find Quote Report
Pyro
Full Member
***

Avatar
The Frog Is Back!

Posts: 152
Reputation: -6
32 / Male / –
Joined: Jun 2005
RE: Are These Genuine System Files?
also go to run and type MSCONFIG
make sure that they arnt in the startup tab. if u arnt sure about files in the startup tab then just google them
[Image: angusl.png]
/!\5793 days, 11 hours, 46 minutes, 13 seconds ago Until Xmas!!/!\
08-25-2007 04:40 AM
Profile PM Web Find Quote Report
M73A
Veteran Member
*****

Avatar


Posts: 3213
Reputation: 37
34 / Male / Flag
Joined: Jul 2004
O.P. RE: Are These Genuine System Files?
ah that was the first thing i did... the dodgy startup entry of vssms32.exe is what led me to find the .dll's!

[Image: lost7ru.gif]
08-25-2007 09:40 AM
Profile E-Mail PM Find Quote Report
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On