backdoor.trojan

backdoor.trojan

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
backdoor.trojan dennis.pong 04-25-2006
Posted by on April 25, 2006, 1:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I realize my computer is infected with backdoor.trojan. The sympton is
I do get virus alert windows popped up once in awhile saying a .exe
file generated by backdoor.trojan has been quarantined (after failing
to clean it by the default action). I tried all the suggested removal
instructions posted on
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.trojan.html#removalinstructions
But I do not see anything was registered in my registry, win.ini, and
system.ini that is pertained to the virus. So I'm guessing my problem
right now is really the nagging .exe file generator hidden in my
computer / remotely away from my computer.
Any suggestions as to how to remove it or block it from being
activated/run ?

Some background info:
I've Symantec Antivirus installed in my computer and the real-time scan
is turned on.
My virus definition update is current as of now.
Full system scan has been performed and nothing has been detected as
viral.
I always deleted those .exe files immediately as soon as they were
detected by the real-time scan.

Any help / advice is appreciated.

Thanks,
Dennis


Posted by David H. Lipman on April 25, 2006, 1:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi,
|
| I realize my computer is infected with backdoor.trojan. The sympton is
| I do get virus alert windows popped up once in awhile saying a .exe
| file generated by backdoor.trojan has been quarantined (after failing
| to clean it by the default action). I tried all the suggested removal
| instructions posted on
|
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.trojan.html#removalinstructions
| But I do not see anything was registered in my registry, win.ini, and
| system.ini that is pertained to the virus. So I'm guessing my problem
| right now is really the nagging .exe file generator hidden in my
| computer / remotely away from my computer.
| Any suggestions as to how to remove it or block it from being
| activated/run ?
|
| Some background info:
| I've Symantec Antivirus installed in my computer and the real-time scan
| is turned on.
| My virus definition update is current as of now.
| Full system scan has been performed and nothing has been detected as
| viral.
| I always deleted those .exe files immediately as soon as they were
| detected by the real-time scan.
|
| Any help / advice is appreciated.
|
| Thanks,
| Dennis


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on April 26, 2006, 2:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi David,

I've done all that you have instructed and have successfully had McAfee
deleted some of the Trojan files. However, as i rebooted into windows
again, I still saw "backdoor.trojan virus found" alert by my Norton
Antivirus program.

I'm guessing that is probably because when I ran the scan in normal
mode, some of the files were in use/protected that the scanner simply
couldn't have done anything to it.

And when I ran it in safe mode, since the windows that I have which is
affected by trojan is in f: drive, by default, the scanner ran would
ONLY be scanning C:. So I got an error when I tried to run it from f:
drive in the command line.

I am guessing there must be a way to go around this. Otherwise, the
scanner is of no use if trojan existed in drive other than the default
C.

Thanks,
Dennis



David H. Lipman wrote:
>
> | Hi,
> |
> | I realize my computer is infected with backdoor.trojan. The sympton is
> | I do get virus alert windows popped up once in awhile saying a .exe
> | file generated by backdoor.trojan has been quarantined (after failing
> | to clean it by the default action). I tried all the suggested removal
> | instructions posted on
> |
>
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.trojan.html#removalinstructions
> | But I do not see anything was registered in my registry, win.ini, and
> | system.ini that is pertained to the virus. So I'm guessing my problem
> | right now is really the nagging .exe file generator hidden in my
> | computer / remotely away from my computer.
> | Any suggestions as to how to remove it or block it from being
> | activated/run ?
> |
> | Some background info:
> | I've Symantec Antivirus installed in my computer and the real-time scan
> | is turned on.
> | My virus definition update is current as of now.
> | Full system scan has been performed and nothing has been detected as
> | viral.
> | I always deleted those .exe files immediately as soon as they were
> | detected by the real-time scan.
> |
> | Any help / advice is appreciated.
> |
> | Thanks,
> | Dennis
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot
the PC.
>
> You can choose to go to each menu item and just download the needed files or
you can
> download the files and perform a scan in Normal Mode. Once you have downloaded
the files
> needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to
run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file. http://www.ik-cs.com/multi-av.htm
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm


Posted by David H. Lipman on April 26, 2006, 2:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi David,
|
| I've done all that you have instructed and have successfully had McAfee
| deleted some of the Trojan files. However, as i rebooted into windows
| again, I still saw "backdoor.trojan virus found" alert by my Norton
| Antivirus program.
|
| I'm guessing that is probably because when I ran the scan in normal
| mode, some of the files were in use/protected that the scanner simply
| couldn't have done anything to it.
|
| And when I ran it in safe mode, since the windows that I have which is
| affected by trojan is in f: drive, by default, the scanner ran would
| ONLY be scanning C:. So I got an error when I tried to run it from f:
| drive in the command line.
|
| I am guessing there must be a way to go around this. Otherwise, the
| scanner is of no use if trojan existed in drive other than the default
| C.
|
| Thanks,
| Dennis

Dennis:

Please post the fully qualified name and path to the file identified as being
infected.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on April 26, 2006, 4:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David,

I think the problem is not really the generated .exe files that were
detected by Norton AntiVirus, as I mentioned in the very first email.
The problem lies in the area where a hidden self-automated file or an
unknown entry in registry or a line in win.ini or system.ini, which I
highly doubt, would just occasionally generate some .exe files that
will be detected as virus. And partially due to the scaning environment
is under f:\ where my windows is running, some of the files were in use
/ protected such that the scanner has no avail in touching those files
even they might potentially be the "Source Virus"

The McAfee scanner did delete a total of 3 files that were considered
as viruses. But I am not sure if it's the "restore" by Windows (I
guess I've to turn it off it's the case) or whatever reason that there
seem to be still a continual automated generation of those .exe files,
which are viruses.

Dennis



David H. Lipman wrote:
>
> | Hi David,
> |
> | I've done all that you have instructed and have successfully had McAfee
> | deleted some of the Trojan files. However, as i rebooted into windows
> | again, I still saw "backdoor.trojan virus found" alert by my Norton
> | Antivirus program.
> |
> | I'm guessing that is probably because when I ran the scan in normal
> | mode, some of the files were in use/protected that the scanner simply
> | couldn't have done anything to it.
> |
> | And when I ran it in safe mode, since the windows that I have which is
> | affected by trojan is in f: drive, by default, the scanner ran would
> | ONLY be scanning C:. So I got an error when I tried to run it from f:
> | drive in the command line.
> |
> | I am guessing there must be a way to go around this. Otherwise, the
> | scanner is of no use if trojan existed in drive other than the default
> | C.
> |
> | Thanks,
> | Dennis
>
> Dennis:
>
> Please post the fully qualified name and path to the file identified as being
infected.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm


Similar ThreadsPosted
Backdoor Trojan? March 2, 2007, 11:12 am
irc backdoor trojan May 9, 2008, 8:28 am
Strange trojan (?) Backdoor.Graybird September 16, 2005, 10:24 am
trojan horse backdoor irc/sdbot.myx December 15, 2005, 5:29 pm
trojan horse IRC/backdoor.sdbot.myx December 15, 2005, 5:35 pm
Trojan horse BackDoor.Generic3.EKW September 9, 2006, 10:14 pm
W32/Backdoor.KPI May 25, 2006, 7:22 pm
Backdoor.HackDefender July 14, 2005, 10:56 pm
Need help with backdoor.prorat October 20, 2005, 6:13 am
Anybody got a fix for BackDoor.Generic3.LRT? October 27, 2006, 11:44 pm

The site map in XML format XML site map

Contact Us | Privacy Policy