wdmlehh.dll trojan

Discussion in 'malware problems & news' started by RATTLER, Jul 29, 2004.

Thread Status:
Not open for further replies.
  1. RATTLER

    RATTLER Guest

    Hi all!

    I have the following problem:
    Scan type: Realtime Protection Scan
    Event: Virus Found!
    Virus name: Backdoor.Agent.B
    File: C:\WINNT\system32\wdmlehh.dll
    Location: C:\WINNT\system32
    Computer: *****
    User: *******
    Action taken: Clean failed : Quarantine failed : Access denied
    Date found: 28 August 2004 11:37:21

    Please help!
     
  2. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Hi RATTLER. :)

    Did u try to scan and clean in safe mode?



    snowbound
     
  3. RATTLER

    RATTLER Guest

    Of course I did, but it disappeared in safe mode. By "disappeared" I mean it wasnt even in C:\WINNT\system32 directory.
     
  4. oneforty

    oneforty Registered Member

    Joined:
    Jun 22, 2004
    Posts:
    4
    I also have the Backdoor.Agent.B virus and have tried many ways to rid my computer of it. All have failed. I have tried to delete the winigni.dll file, which is referenced in the Symantic AV notification window, however no luck. Did you every find a way to get rid of it?
     
  5. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    There are removal instructions here

    After this you may also like to try the instructions found here just to be sure your system is clean and to see what you may need to do to strengthen your security...

    Hope this helps...

    Let us know how you go...

    Cheers :D
     
  6. oneforty

    oneforty Registered Member

    Joined:
    Jun 22, 2004
    Posts:
    4
    thanks much... so far so good... the trojan B has not returned.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.