1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

BackDoor Blues

Discussion in 'Malware and Virus Removal Archive' started by getteraye, 2006/06/22.

  1. 2006/06/22
    getteraye

    getteraye Inactive Thread Starter

    Joined:
    2006/06/22
    Messages:
    3
    Likes Received:
    0
    BackDoor Trojan, Collected 5.L

    I have Avast antivirus software which detected Trojan horse(s), BackDoor generic.ofp, IRC BackDoor.SdBot.BN2, Collected 5.L, I removed them (w/Avast) and ran another scan, no virus,yesterday. I also use Secretmaker which should block the virus from loading to the start menu and did yesterday. However, a scan today discovered them again. :confused: How do I zap em' for good?
     
  2. 2006/06/22
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    getteraye - Welcome to the Board :)

    Let see what we can do for you .....

    Please download the trial version of Ewido. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu ". Once installed please update it by clicking on the Update button. Do not run it yet.

    Please download HijackThis through Quicklinks in my signature and save it to a folder on your hard drive, say C:\HJT - not to the Desktop or a temporary location. When entries are fixed with HJT a backup is made to the folder from which HJT is run and this must be in a permanent location.

    Boot into Safe Mode and log onto your usual account.
    Run Ewido ....

    Click on Scanner and select a 'Complete System Scan'.
    If anything is found during scanning you will be prompted to clean the files.
    Select "Remove" and check the boxes "Perform action with all infections" and "Create encrypted backup" and then click on OK

    Once the scan has completed save the report to a known location.

    Stay in Safe mode

    Open the folder in which you placed HJT and double click on hijackthis.exe and select Scan and save a log file - this will be saved in the folder from which you ran HJT.

    Reboot into Normal mode and post the Ewido and HJT logs here.
     

  3. to hide this advert.

  4. 2006/06/23
    getteraye

    getteraye Inactive Thread Starter

    Joined:
    2006/06/22
    Messages:
    3
    Likes Received:
    0
    I followed the instructions ie: post BackDoor Trojan, Collected 5.L dated 6/22/06 as best I could. I was not given the option to uncheck the options as per instructions re:Ewido install. So, I have been unable to proceed further. However, I am encountering an irritating side effect of the BackDoor Intruder. It seems it has enabled the dialup connection dialog box. The process rasauto.exe is in C:/windows/system32 which cannot be deleted. I can at times shut if off by ending the process in the Task Manager. But sometimes this doesn't help and windows start popping and exploding ;) and I must reboot. How do I inactivate the enabled autodial from my registry?
     
  5. 2006/06/24
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Hi getteraye.

    We need for you to keep all your replies in your original thread. In this manner we can keep a more concise and easier to read\follow thread of instructions.

    A mod will likely merge this into that thread.
     
  6. 2006/06/24
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    getteraye

    Yes, please stick with the original thread - each time you reply all posters in the thread get an email notification to that effect - as you started a new thread I did not receive a notification of your reply.
    :confused: - any ideas TeMerc?
     
  7. 2006/06/24
    getteraye

    getteraye Inactive Thread Starter

    Joined:
    2006/06/22
    Messages:
    3
    Likes Received:
    0
    Getting in deeper

    Sorry Pete, I musta got lost. I lost my AVG anti-virus too...somehow the language support interface cannot be initialized, another BackDoor violation? :eek:
     
  8. 2006/06/24
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    No problem

    Sorry about the confusion re. Ewido - I was not aware that they had updated the program this week and the install routine and interface has changed significantly. Here are the 'new' instructions - please uninstall the version of Ewido you have installed and start over ....

    Please download and install the 30 day trial version of Ewido Anti-Spyware

    Run the program either from the Desktop icon if you chose to install one or from Start > Programs. On the main screen select the Update icon followed by the "Update now" link and click on the Start Update button. The update will start and a progress bar will show the updates being installed.

    When the update has completed select the Scanner icon at the top of the window and click on the Settings tab.

    On the Settings screen click on Recommended actions and then on Quarantine.

    Under Reports select Automatically generate report after every scan and deselect Only if threats were found.

    Close Ewido Anti-spyware. Do not run a scan just yet.

    Boot into Safe Mode and log onto your usual account.
    Do not open any other windows or programs while Ewido is scanning as this may interfere with the scanning proccess.

    Start Ewido Anti-spyware by double-clicking the icon on your desktop or from Start > Programs and select the Scanner icon at the top of the window followed by the Scan tab and click on Complete System Scan. The scanning process will start and may take some time.

    When the scan is complete if any infections were detected you will prompted for an action - select Apply all actions.

    Then select the Reports icon at the top of the window and click on the Save report as button in the lower left hand corner of the screen and save it as a text file (be sure to remember where you saved that file, this is important).

    Close Ewido and reboot your system back into Normal Mode and post the Ewido scan report here.

    AVG - I thought you were running Avast? If you are running both av's this is unwise - and no safer, as they are likely to conflict.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.