1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Removing file infected with Trojan.Goldun

Discussion in 'Malware and Virus Removal Archive' started by jamesashburton, 2006/04/21.

  1. 2006/04/21
    jamesashburton

    jamesashburton Inactive Thread Starter

    Joined:
    2006/04/20
    Messages:
    1
    Likes Received:
    0
    I logged on to my computer (runs XP) and Norton Anti Virus reported a file infected with Trojan.Goldun which it couldn't remove. Says it may be in use.

    The file was (is) in the Windows/system32 folder and is called gdiwxp.dll

    I read the info on the Symantec site about starting in safe mode and rescanning then removing the infected file. I have tried that twice - it doesn't get removed. I've even tried removing it from the command prompt.

    Can anyone help please?
     
  2. 2006/04/21
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    jamesashburton - Welcome to the Board :)

    Download HijackThis through Quicklinks in my signature, save it to a folder on your hard drive, say C:\HJT - not to the Desktop or a temporary location. Boot into Safe Mode and run HJT and post the log here.
     

  3. to hide this advert.

  4. 2006/04/21
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Trojan.Goldun is a backdoor trojan that steals passwords. After it has been cleaned out, change your passwords at these sites if you use them:
    1. online banking
    2. stock or investment sites
    3. any other sites where you use a password
     
  5. 2006/05/08
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    I have the same problem as the initial poster, except the only difference is my infected file is 'DIRECTPT.DLL'

    Here's my HJT log from safe mode.

     
  6. 2006/05/08
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Aaaaaaaaaron - Welcome to the Board :)

    Reboot into Safe Mode and scan again with HJT. Place a checkmark against these entries and hit 'Fix Selected' ....

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: directpt - C:\WINDOWS\SYSTEM32\directpt.dll
    O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Stay in Safe mode and navigate to C:\WINDOWS\SYSTEM32 and delete directpt.dll

    Reboot and post another HJT log which I will look at in the morning.

    Take careful note of TonyT's comments about passwords in post #3
     
  7. 2006/05/08
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    Thanks for the welcome.

    When I navigated to the file, directpt.dll, and tried to delete it in safe mode, an error saying it could not be deleted because it currently being used or something to that effect.

     
  8. 2006/05/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    OK, reboot into Safe Mode ....

    Click Start > Run and copy/paste this line into the run box and press Enter ....

    regsvr32 /u C:\WINDOWS\SYSTEM32\directpt.dll

    If you type it in note the space btween the 2 and the forward slash and again between the u and C.

    Scan with HJT and check this line and Fix Selected.

    Stay in Safe mode and navigate to C:\WINDOWS\SYSTEM32 and delete directpt.dll

    Reboot into Normal Mode, scan again with HJT and post the log.
     
  9. 2006/05/09
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    When I copied regsvr32... into the run box it said it loaded, bu the dllunregisterserver entry point wasn't found. Also it said access denied to directpt.dll when I tried to delete it again.

     
  10. 2006/05/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Time for brute force :)

    Download and install MoveOnBoot. It will add a new menu item to the right click menu when you right click on a file.

    Navigate to C:\WINDOWS\SYSTEM32 and right click on directpt.dll and select 'Delete file(s) at next boot'.

    Reboot and see if it is gone.
     
  11. 2006/05/09
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    I can't seem to find directpt.dll in the System32 folder, I went into folder options and turned on 'show hidden files and folders' and still nothing. I'm guessing I need to be in safe mode to do this then?
     
  12. 2006/05/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Well, if you found it before you should be able to find it again, if it is there :) Safe mode is no different from normal mode in this respect. Presumably you had the view menu set as before - as a check go to the View menu and uncheck 'Hide protected operating system files' and look again.

    Post another HJT log and we'll see if the critter is still there.
     
  13. 2006/05/09
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    It still didn't appear for some odd reason, but I booted up in safe mode and it was there.:confused:

     
  14. 2006/05/09
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    OK - you are getting there - the file has gone.

    Scan again with HJT and put a checkmark against this entry ....

    O20 - Winlogon Notify: directpt - directpt.dll (file missing)

    Reboot, scan again, post the log and hopefully that will be the end of it :)
     
  15. 2006/05/09
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    :eek: Big thanks Pete.

     
  16. 2006/05/10
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Your log looks clean to my eye - you're 'good to go' :)

    Turn off System Restore to clear your restore points which may contain the infection, reboot and turn on System Restore.
     
  17. 2006/05/11
    Aaaaaaaaaron

    Aaaaaaaaaron Inactive

    Joined:
    2006/05/08
    Messages:
    7
    Likes Received:
    0
    Alright, thank you.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.