1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Need Help With Nasty Trojan

Discussion in 'Security and Privacy' started by Steve R Jones, 2004/06/24.

Thread Status:
Not open for further replies.
  1. 2004/06/24
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Backdoor.Prorat

    Symantec’s removal instructions have always worked for me in the past. But this little sucker has me stumped.

    Running Win2k server w/NTFS. This is a machine my Company leases and hosts sql databases for our clients. (luckily all can access the databases) (someday maybe well install a firewall – long story)

    Bootup the machine and Norton finds and quarantines the two dll files that are part of the Trojan. Then Norton gets shut down by the Trojan and the two dll files get recreated. Norton or hardly any exe file will run in normal or safe mode. There are two files: Sservice.exe and Fservice.exe that get recreated as soon as you delete or rename them.

    Bootup in Safe mode – follow the removal instructions – I zap one of the offending reg entries & hit the F5 refresh key, the entry comes back…..

    In safe mode, there are only about 4 or 5 services running and stopping them doesn’t help.

    Thinking I need to be able to boot with a DOS startup disk and zap the files but am using NTFS. I have a DOS disk that will let me view & copy an NTFS drive but not delete…

    Any thoughts or suggestions would be most welcomed.
     
  2. 2004/06/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Steve :)

    Maybe try marking all four files with Move-on-Boot, search the registry for and delete any references with RegSeeker or similar and reboot. Gotta go right now. Will check in later as well as do a bit of research on the files. Any links would be appreciated. ;)
     

  3. to hide this advert.

  4. 2004/06/24
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Thanks Dave,

    Guess I've lead a shelted life. I did a search for Move-on-Boot and found:

    Set of utilities that provide many useful services (copying/moving/renaming/deleting files and folders on the next system boot by gibinsoft.com


    Do you use one that you'd recommend?
     
  5. 2004/06/24
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Wow Steve :eek:
    All I've got for you on this one is a huge amount of sympathy. :eek: The closest I came to a solution was that A squared has the definitions for:
    Backdoor.Prorat.10.a
    Backdoor.Prorat.10.b
    Backdoor.Prorat.10.c
    Backdoor.Prorat.10.d
    Backdoor.Prorat.10.f
    Backdoor.Prorat.11.a
    Backdoor.Prorat.13
    Backdoor.Prorat.14
    Backdoor.Prorat.15
    Backdoor.Prorat.16

    May be worth a shot?

    *edit*
    But then, pest patrol also says it can rid you of it. :confused:
     
  6. 2004/06/24
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Thanks also.

    Was downloading it when I came to check your reply.
     
  7. 2004/06/24
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
  8. 2004/06/24
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Thanks Mark.
    That's the one I downloaded while ago from gibinsoft.com. Tested the rename function and it works like a charm. Have high hopes... It's a bugger bear shuting clients down while we work on this stuff....
     
  9. 2004/06/24
    Alman

    Alman Inactive

    Joined:
    2004/06/24
    Messages:
    2
    Likes Received:
    0
  10. 2004/06/24
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Thanks. We've tried a few of these. So far, either they won't run or they don't find anything. But, will give this one a try too.

    Tried Stinger, the stand a lone .exe and it couldn't find anything.


    This was highly recommened but didn't detect anything.
    Download our picks:
    · a² (a-squared) personal 1.1
    Protects the PC against malicious software: Trojans, Dialers, Worms, Spyware
     
  11. 2004/06/24
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    If you know the file locations, boot from the CD to Recovery Console and you should be able to delete the critters.
     
  12. 2004/06/24
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    That would be too darn easy. Besides, I nor my IT guy didn't think of that.
     
  13. 2004/06/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
  14. 2004/06/24
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Oh! that's just freaking like you, Newtness!! Start throwing logical answers at the problem. :rolleyes:

    And here I had a few hundred more wild goose-chases planned for Steve yet. :D
     
  15. 2004/06/24
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    :( Sniff, sob. Sorry Daizy. Can you ever forgive me? :eek: :eek:
     
  16. 2004/06/24
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0

    Got coffee? :)

    edit note: Gal, that's like asking if a bear living in the woods has fleas. Newt
     
  17. 2004/06/25
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Just read my office mail. My IT guy in California, who was up till the wee hours working on the machine via pcanywhere, reports that he killed the machine. (after getting the client's data off it)

    Pretty embarassing......It's been a few weeks. Is it FORMAT C: or Format C:eek:

    Thanks to ALL that replied ;)
     
  18. 2004/06/25
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I'd start with fdisk, then format C: /u.

    Good stuff here.
     
  19. 2004/06/25
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Ooops sorry.

    The embarrasing part is the need to format which we know how to do ;)
     
  20. 2004/06/25
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    You sure?! :D
    Cause we're here for ya! We got ideas! We're ALL about the format. :p
    If we keep his Newtness out f it...we can make this into a month long project.
     
  21. 2004/06/25
    Steve R Jones

    Steve R Jones SuperGeek Staff Thread Starter

    Joined:
    2001/12/30
    Messages:
    12,314
    Likes Received:
    252
    Way way way way back when in the IBM XT days, the super geeks at Corp downtown made a cute cartoon:

    NEED MORE HARD DRIVE SPACE? (remember when ibm xts's came with a 10 MEG drive)

    Anyway, Need More hard drive space?

    Try: FORMAT C:

    I thought the cartoon was so cute, I made several copies of it and past them out. Past them out to people that didn't know it was a joke....(nothing bad ever happened)
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.