1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Is RBOT part of microsoft Anti Spy

Discussion in 'Security and Privacy' started by Mark Hasenbein, 2005/08/21.

  1. 2005/08/21
    Mark Hasenbein

    Mark Hasenbein Inactive Thread Starter

    Joined:
    2005/07/19
    Messages:
    43
    Likes Received:
    0
    I was advised that rbot was a back door worm and rewrites it self.
    Also found "Trojan /CWS combo.
    any ideas!
    Mark :confused:
     
  2. 2005/08/21
    sparrow

    sparrow Inactive

    Joined:
    2004/03/21
    Messages:
    2,282
    Likes Received:
    0
    Definately a problem. See this web page. if you haven't, check out the stickies at the top of this forum for advice, and wait for a secutity expert to answer your post.
     

  3. to hide this advert.

  4. 2005/08/21
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    MS re-issued this month's Malicious Removal Tool to cover rbot and some variants - download from here ....

    http://www.microsoft.com/downloads/...E0-E72D-4F54-9AB3-75B8EB148356&displaylang=en
     
  5. 2005/08/28
    oshwyn5

    oshwyn5 Inactive

    Joined:
    2005/08/25
    Messages:
    736
    Likes Received:
    0
    Often one spyware renmover,antivirus , or trojan detector will detect the definition files in a competitiors product and identify them as an infestation.
    So this could well be a false positive if you downloaded from an official site.
    Often it is just as important to know where something is as to know what it is called.
     
  6. 2005/08/31
    Mark Hasenbein

    Mark Hasenbein Inactive Thread Starter

    Joined:
    2005/07/19
    Messages:
    43
    Likes Received:
    0
    Startup Inspector found "c program filesmicrosoft anti spywaregcas Sevr.exe "
    Startup identifies gcas sevr.exe as a RBOT worm.
    Microsoft anti spy was corrupted I had to uninstall and download it again.
    Gcas sevr.exe is back on startup but my antispy works.
    Don't know what to do. :confused:
    Mark
     
  7. 2005/08/31
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Mark,

    gcasServ.exe is a legitimate exe for MS AS - will insert itself into the startups even if you don't run it with the resident protections. Are you running it with the real time protection running? Do you want it to run real time? If not, right click on the tray icon and disable it.

    If that doesn't do the trick, and If msconfig can't keep it out of the startup, use autoruns to disable it http://www.sysinternals.com/Utilities/Autoruns.html

    Regards - Charles
     
  8. 2005/08/31
    Mark Hasenbein

    Mark Hasenbein Inactive Thread Starter

    Joined:
    2005/07/19
    Messages:
    43
    Likes Received:
    0
    Yes I run it in real time if it's part of anti spy no worries.
    thanks for the help. :)
    Mark
     
  9. 2005/08/31
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    Mark Hasenbein--You talk about "gcas sevr.exe ". A file with that name is not part of MSAntiSpyware. On the other hand I can find no mention of it elsewhere, so do not know if it is some new baddie or whether you have misspelled it. (I also looked for "gcassevr.exe" since a space in a file name is a little unusual.)
    As charlesvar has said "gcasServ.exe" is a legitimate exe for MS AS.
     
    Last edited: 2005/08/31
  10. 2005/09/01
    Mark Hasenbein

    Mark Hasenbein Inactive Thread Starter

    Joined:
    2005/07/19
    Messages:
    43
    Likes Received:
    0
    Welshjim "gcasServ.exe" is correct.
    Startup inspector identifies it as an "RBOT" not to be confused with Microsoft anti spy of the same name. Deleted the entry in my startup and my anti spy ware would not load and said to uninstall and download it again. GcasServ.exe was back in startup and Microsoft anti spy is working.
    I am posting my Hijackthis log to see if anyone knows about "gcasServ.exe ".
    Mark
     
  11. 2005/09/01
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Mark
    The path for a legitimate version of gcasServ.exe is C:\Program Files\Microsoft AntiSpyware\gcasServ.exe. Do you have another 'copy' in another location?
     
  12. 2005/09/01
    Mark Hasenbein

    Mark Hasenbein Inactive Thread Starter

    Joined:
    2005/07/19
    Messages:
    43
    Likes Received:
    0
    Yes found "gcasDtServ.exe "
     
  13. 2005/09/01
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    Mark Hasenbein-- gcasDtServ.exe is a different file from gcasServ.exe. Both are legitimate MSAntiSpyware files.
    (gcas sevr.exe (or gcassevr.exe) is not.)
    Did you find gcasServ.exe in the directory mentioned by PeteC?
    I think Startup Inspector is giving you a false positive if the spelling is gcasServ.exe.
    Your other thread
    http://www.windowsbbs.com/showthread.php?t=47633
    does not show gcassevr.exe as running.
     
    Last edited: 2005/09/01

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.