1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan BackDoor.Ruledor.D

Discussion in 'Security and Privacy' started by virginia, 2004/09/01.

Thread Status:
Not open for further replies.
  1. 2004/09/01
    virginia Lifetime Subscription

    virginia Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,100
    Likes Received:
    26
    AVG scan revealed subject trojan in C:\Program Files\Clear Search|Loader.EXE. It was not removed or isolated and status is reflected as "Still Infected ". When I searched the AVG database, I got no results. Same on Symantec.

    I did a Google search but didn't find any sites that I trusted enough to use. Does anyone have any information on this trojan and where or how I can get a removal tool? Thaks a lot.
     
  2. 2004/09/01
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi Virginia...

    There is an online trojan scanner site called Trojan Scan. Give it a go.
     
    Last edited: 2004/09/01

  3. to hide this advert.

  4. 2004/09/01
    virginia Lifetime Subscription

    virginia Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,100
    Likes Received:
    26
    Thanks Kent,

    I ran the online scan you suggested and it eiter found no trojan or found it and cleaned it - hard to tell from how the results were posted. Will run AVG again now and see if it still finds it.

    If it's still there I will be back - no, I will be back in any case to let you know.
     
  5. 2004/09/01
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi Virgina...

    EDIT: What version (how old) is your AVG? The version on their web site for download (AVG 6.0 free version) is 732. If your running an older version re-download a newer version from => http://free.grisoft.com/freeweb.php/doc/2/. Make sure you update it right away.

    I would also advise you run some more checks...

    If you are not running the latest versions of Ad-aware SE and Spybot 1.3 you should do so. You can download the latest versions from the following links below and make sure you update before running programs...
    Ad-Aware SE Personal
    Sptbot 1.3 - Tutorial can be found here. Only put checkmark on entries highlighted in RED.

    You should also run an "Online" virus and Trojan scan...I have added some links for those also...
    RAV - AV Scanner
    Panda - AV Scanner
    Trojan Scan - Trojan scanner

    Download and run the latest version of CWShredder from this link. Make sure you have closed all windows before runing program. Start program...Click Fix.

    After completing all scans download HijackThis to a folder on your hard drive. Call the folder, for example, C:\HJT. To post a log => Run the program => Click on "Scan" button => After scan complete click on "Save log" button = > Choose the C:\HJT folder for the save location => Notepad should open => Copy and paste contents into a new post. NOTE: Do not fix anything until someone experienced with the logs advises you to.
     
  6. 2004/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    ClearSearch is a drive-by install, that you don't want. Make sure the Loader.exe process is not running in task manager and then delete the ClearSearch folder in Program Files.
     
  7. 2004/09/01
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    You da man, Dave. :D

    I have learned quite a lot reading your posts. Thanks. :)

    How new is this "ClearSearch "? I just googled it and came up with a few hits for removal. Looks interesting...
     
    Last edited: 2004/09/01
  8. 2004/09/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Well Thank You, Kent. Glad my posts have been helpful. :)

    virginia,

    Still a good idea to follow Kent's suggestions. If ClearSearch got in,other nasties likely did too. ;)
     
  9. 2004/09/01
    virginia Lifetime Subscription

    virginia Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,100
    Likes Received:
    26
    I have 6.0.747 Ver AVG. Don't know how that relates to 632. I ran Housecall and it found the BackDoor.Ruledor.D trojan but said it couldn't be fixed. I then stopped the Loader.EXE process and tried to delete the C:\Program\Clear.... folder in Windoes Explorer but it wouldn't let me delete the folder.

    I'm not on my home computer now - visiting relatives and trying to clean this off. Will download all the tools - Spybot, AdAware, HiJack This, etc as I have time and post back. Also I didn't run Clear Search in my first Google search so I may give that a try as well. Will post back as I progress.
     
  10. 2004/09/01
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Your version of AVG is a little out of date.
     
    Newt,
    #9
  11. 2004/09/02
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi Robert from Virginia...

    - http://www.viruslist.com/eng/viruslist.html?id=815202
    - http://www.doxdesk.com/parasite/ClearSearch.html

    There is also 2 Trojan scanner programs that you can download and install. The first is SwatIT which is a free download and the other is Trojan Hunter. Trojan Hunter is not free but you can download the free 30 day evaluation. Try these programs. Please make sure you update them after installig either program(s)

    - SwatIT => Manual => How to Update near bottom of page
    - TrojanHunter => Manually Updating Your TrojanHunter Rule Files
     
    Last edited: 2004/09/02
  12. 2004/09/05
    virginia Lifetime Subscription

    virginia Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,100
    Likes Received:
    26
    Just a quick update to those of you who are giving me all these tips, we have had a death in the family so my attention has been elsewhere.

    However, I will update the AVG shortly and rerun it. I ran the old version last night and it didn't find any problems - however I think it/they are still there. I downloaded AdAware, installed it, and tried to run it. However, something halts it shortly into the process, warns me that it is stopping the process, and then restarts the computer.

    I will post back as I get some of the suggestions addressed. Thanks so much to all of you and for your patience.
     
  13. 2004/09/09
    virginia Lifetime Subscription

    virginia Geek Member Thread Starter

    Joined:
    2002/01/07
    Messages:
    1,100
    Likes Received:
    26
    Final Note - SwatIt downloaded, installed, updated, and run. Didn't find anything. Recent AVG scans don't reveal anything. But I stil have my doubts. The Clear Search folder is still in Programs and I cant delete it. However, no problems have been noticed. I will not be at this computer after today so thanks to all who have offered up suggestions.

    Side Comment - Early on, I downloaded, installed, and ran the NoAdaware removal tool. It found a number of items that needed to be repaired, and when I clicked on the "Repair" button, a pop-up appeared and wanted $29.95 before it would do the repair action - so much for the "free" download.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.