Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » Trojan program Backdoor.Win32.Rbot.eib

[Fixed] Hijackthis! Logs - Trojan program Backdoor.Win32.Rbot.eib posted in the Security & Safety forums; did you install this? C:\Program Files\Do It Again Regardless, let's try an online scanner: Using Internet Explorer, visit Free Virus Scan - Kaspersky Lab Answer Yes, when prompted to install ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 11-07-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,629
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Trojan program Backdoor.Win32.Rbot.eib

did you install this?

C:\Program Files\Do It Again

Regardless, let's try an online scanner:

Using Internet Explorer, visit Free Virus Scan - Kaspersky Lab

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • -Scan using the following Anti-Virus database:
      • --Extended
    • -Scan Options:
      • --Scan Archives
      • --Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Last edited by valis; 11-07-2007 at 01:12 PM.
  #9  
Old 11-08-2007
Gold Member
My PC
 
Join Date: Nov 2007
Location: Sweden
Posts: 232
PC Experience: Experienced
lyxell - See this Members User comments on their Profile page
Send a message via Skype™ to lyxell
Default Re: Trojan program Backdoor.Win32.Rbot.eib

yes i did install that
ok here it is
Attached Files
File Type: html kasperskyonlinelog.html (100.5 KB, 1 views)



Last edited by lyxell; 11-08-2007 at 09:42 AM.
  #10  
Old 11-08-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,629
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default Re: Trojan program Backdoor.Win32.Rbot.eib

nothing's showing in the log......how's the machine running?


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #11  
Old 11-08-2007
Gold Member
My PC
 
Join Date: Nov 2007
Location: Sweden
Posts: 232
PC Experience: Experienced
lyxell - See this Members User comments on their Profile page
Send a message via Skype™ to lyxell
Default Re: Trojan program Backdoor.Win32.Rbot.eib

It is running very slow
and kaspersky finds a virus when running combofix that keeps showing up


  #12  
Old 11-08-2007
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: Trojan program Backdoor.Win32.Rbot.eib

Hi lyxell,

Valis is away for a couple days. It will take me a little while to catch up on what is happening here. I am "guessing" that what you see in Kaspersky is a "false/positive" - that means that some of the internal programs being used by combofix are sometimes mistaken as malware. While I get familiar with your problem, please do the following:

Download WinPFind3U.exe to your Desktop and double-click on it to extract the files.

It will create a folder named WinPFind3u on your desktop.
Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.

In the Files Created Within group click 30 days
In the Files Modified Within group select 30 days
In the File String Search group select Non-Microsoft
In the Additional Scans click Select All
Now click the Run Scan button on the toolbar.


When the scan is complete Notepad will open with the report file loaded in it.
Click the Format menu and make sure that Wordwrap is not checked. If it is, then click on it to uncheck it.

Please post the resulting log here as an attachment.

Thanks.


__________________
Steve
  #13  
Old 11-09-2007
Gold Member
My PC
 
Join Date: Nov 2007
Location: Sweden
Posts: 232
PC Experience: Experienced
lyxell - See this Members User comments on their Profile page
Send a message via Skype™ to lyxell
Default Re: Trojan program Backdoor.Win32.Rbot.eib

ok then I don't have to worry about that.

but the file size is to big:
WinPFind3.Txt:
Your file of 1.04 MB bytes exceeds the forum's limit of 97.7 KB for this filetype.

should i zip it?


  #14  
Old 11-09-2007
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 545
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: Trojan program Backdoor.Win32.Rbot.eib

Yes, that should work.


__________________
Steve

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 02:24 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top