Author Topic: Trouble getting rid of a persistent trojan winhdn32.dll  (Read 430 times)

Offline Wolfala

  • Platinum Member
  • ******
  • Posts: 4875
Trouble getting rid of a persistent trojan winhdn32.dll
« on: July 28, 2006, 08:40:31 PM »
Tried Hijack this, tried to manually delete in safe mode since it resides in the sys32 folder, adaware doesn't catch it but trendmicro online scan does and can't delete it.

Ideas?

Wolf


the best cure for "wife ack" is to deploy chaff:    $...$$....$....$$$.....$ .....$$$.....$ ....$$

Offline x0847Marine

  • Silver Member
  • ****
  • Posts: 1412
Re: Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #1 on: July 28, 2006, 10:36:57 PM »
Quote
Originally posted by Wolfala
Tried Hijack this, tried to manually delete in safe mode since it resides in the sys32 folder, adaware doesn't catch it but trendmicro online scan does and can't delete it.

Ideas?

Wolf


Suggestions:
http://www.avast.com home version is free and will scan your HD before booting to Windows. You must watch as it does so, it'll ask you to confirm which files, if any, to delete. The free on line scan might work as well.

Set the infected drive up as a slave 1st, then scan it.

Pick up a new HD on the cheap, or use a spare to fresh install winders and try #2

I'm not sure if the Win restore (to a previous date) works for viri, might be worth looking into.

Nuke & pave, but before doing so google 'slipstreaming xp', you can create a bootable Windows install with all your current drivers and all Win updates included... its basically a 1 time install w/o a dozen re-starts.

Offline ozrocker

  • Gold Member
  • *****
  • Posts: 3640
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #2 on: July 29, 2006, 05:04:02 PM »
http://forum.networktechs.com/archive/topic.php/t-1819112994.html

Hope this link helps.
                                                                    Good luck!
                                                                        Oz
Flying and dying since Tour 29
The world is grown so bad. That wrens make prey where eagles dare not perch.- Shakespeare
 
30% Disabled Vet  US ARMY- 11C2H 2/32 AR. 3rd AD, 3/67AR. 2nd AD, 2/64 AR. 3rd ID, ABGD Command TRADOC, 1/16th INF. 1st ID

Offline Skuzzy

  • Support Member
  • Administrator
  • *****
  • Posts: 31462
      • HiTech Creations Home Page
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #3 on: July 29, 2006, 06:38:06 PM »
Try killing it in safe mode.
Roy "Skuzzy" Neese
support@hitechcreations.com

Offline Ghosth

  • AH Training Corps (retired)
  • Plutonium Member
  • *******
  • Posts: 8497
      • http://332nd.org
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #4 on: July 29, 2006, 10:31:49 PM »
This is where having a dual boot machine is a HUGE help.

Get a bug in XP, boot up into the other side,  run your virus scanner, & your adware killer.  Boot back up into XP and by now it should be so crippled you can finish cleaning it out. Even 2 versions of XP works for this.

Got an old Win98 Start up disk handy? Download a dos virus scanner, boot with the startup disk & run the dos scanner. Then reboot back & double check. Kind of a clunky way of doing the same thing without a second os installed.


IMO AVG still the best FREE virus scanner. The price is right and its not such a resource hog.

Offline Wolfala

  • Platinum Member
  • ******
  • Posts: 4875
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #5 on: July 30, 2006, 01:40:15 AM »
Well I did the next best thing next to a nuclear holocaust on the HD. I keep a pretty lean C drive with basically nothing but the essentials on it, Acrobat, Nero, ya know - replaceable ****. I had a Norton Ghost image I created with a bare bones boot config with stuff working - so I nuked the drive, restored from the image. And did about 3 months worth of patching since that image, and made another image with the latest goodies.

Never did get rid of that trojan - even in safe mode you cannot delete the little ****er. Never showed up in Hijack this or any scanner - so was probally better to nuke the drive anyway.

Restored in 3 minutes, patched up in 10 - good to go.

Frustrating as **** though.

Wolf


the best cure for "wife ack" is to deploy chaff:    $...$$....$....$$$.....$ .....$$$.....$ ....$$

Offline dmf

  • Gold Member
  • *****
  • Posts: 2920
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #6 on: July 31, 2006, 09:12:42 PM »
Ok I'll say it again........................ ............................N OD32 ANTIVIRUS

Offline Silat

  • Gold Member
  • *****
  • Posts: 2536
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #7 on: August 02, 2006, 05:10:15 PM »
Did you turnoff system restore?:)
+Silat
"The first time someone shows you who they are, believe them." — Maya Angelou
"Conservatism offers no redress for the present, and makes no preparation for the future." B. Disraeli
"All that serves labor serves the nation. All that harms labor is treason."

Offline eh

  • Copper Member
  • **
  • Posts: 314
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #8 on: August 02, 2006, 06:43:34 PM »
This is where having a dual boot machine is a HUGE help.

Wow you guys are wizards. I have a dual boot machine (XP x64 on C:\ and XP Home on D:\) and I really like to have it. The only problem is XP 64 was installed first, and I added a D:\ Drive with XP home 32 bit later. When I need to boot into XP Home, it is extraordinarily slow in starting up... it takes about 3 minutes all told. After that, it behaves normally.

Any ideas on how to speed up the Win 32 bit boot process? or is this slowness the penalty I have to pay for a dual boot system? (64 bit Win is as fast as always).

Offline eh

  • Copper Member
  • **
  • Posts: 314
Trouble getting rid of a persistent trojan winhdn32.dll
« Reply #9 on: August 03, 2006, 04:41:30 PM »
Oh dang. I just hijacked a thread. Didn't mean to. Sorry, all.