Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » Anti-Virus » [FIXED] Vbsys2.dll Trojan Found

Anti-Virus - [FIXED] Vbsys2.dll Trojan Found posted in the Security & Safety forums; Hiya everyone x I was wondering if I could get some more advice about a Trojan Horse I have found on my PC. Its under the file name of vbsys2.dll ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 10-21-2005
Bronze Member
 
Join Date: Jun 2005
Posts: 12
Lucie Ann - See this Members User comments on their Profile page
Default [FIXED] Vbsys2.dll Trojan Found

Hiya everyone x

I was wondering if I could get some more advice about a Trojan Horse I have found on my PC.

Its under the file name of vbsys2.dll

Ive tried to delete the file, but it wont allow me to, and my antivirus software cant do it either. Ive had a look under processes to see if it is running, but its no use because its not an exe file if you know what I mean?

I searched the registry and I found the following keys under HKEY_CURRENT_USER under a folder Software/Microsoft/Search Assistant/ACMru/5603

000 REG_SZ vbsys2.dll
001 REG_SZ banner.aspx
(default) REG_SZ value not set

I also found vbsys2.dll in other parts of the registry.

Now, Im not too clued up on the registry but it seems to me that I need to delete these keys but I just wanted to check if I can do this or if it will help get rid of the file that is stuck in my Windows/System32 folder and wont budge because it keeps telling me its write protected or in use.

I tried to launch in safe mode, but my PC wont let me for some reason. It just automatically restarts again normally when I get to the log on screen.

Id be grateful if you could help out with this. Thanks

Lucie


  #2  
Old 10-21-2005
Silver Member
 
Join Date: Oct 2005
Location: St Ives, Cornwall
Posts: 114
PC Experience: PC Illiterate
Mere_Mortal - See this Members User comments on their Profile page
Default

Hello

The Registry entries you found appear to be the result of, maybe you searching for the file? They are MRUs (most recently used, which includes searches) and are not a threat, although security scans could well target them.

What you do need to locate and remove are the following. Copy the text to notepad and save it as a Registry (REG) file and execute the script so as to merge into the Registry, automatically removing the offending items...
Code:
REGEDIT4
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
SystemCheck2=-
 
[-HKEY_CLASSES_ROOT\CLSID\{54645654-2225-4455-44A1-9F4543D34545}]
Also locate the file itself, which will be in either the C:\WINDOWS or C:\WINDOWS\System32 directory. You could always try using [Pocket Killbox] to attempt its removal.

HTH,
M_M



Last edited by Mere_Mortal; 10-21-2005 at 03:34 PM.
  #3  
Old 10-21-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

You might also want to follow the instructions in the "Prework" link below in my sig and post the resulting logs to see if there is more malware on youre pc.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 10-27-2005
Bronze Member
 
Join Date: Jun 2005
Posts: 12
Lucie Ann - See this Members User comments on their Profile page
Default

Hi guys

thanks for your advice...i tried the killbox and it removed the trojan so great stuff thank you!!

It was pretty straightforward actually! I just wondered why I couldnt kill the process myself?

ive done an antivirus scan and there isnt anything else present...my antivirus is the one that detected it in the first place but for some reason couldnt remove it,

is that what viruses and trojans do..run a process which you cant seem to find so it can stay on your pc?

Anyways thanks for your help i appreciate it x


  #5  
Old 10-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,046
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Originally Posted by Lucie Ann
is that what viruses and trojans do..run a process which you cant seem to find so it can stay on your pc?

Yup , and alot more im afraid.. Good to hear you got rid of it.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:25 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top