Member Panel


Sponsors and Ads

Live Tag Cloud

[Fixed] Hijackthis! Logs - backdoor help posted in the Security & Safety forums; [IMG]file:///C:/Users/Johannly/AppData/Local/Temp/moz-screenshot-2.jpg[/IMG] BitDefender Log File !!!!! Product : BitDefender Total Security 2008 Version : BitDefender UIScanner v.11 Log date : 10:15:23 29/12/2007 Log path : C:\ProgramData\BitDefender\Desktop\Profiles\Logs\d eep_scan\1198941323_1_02.xml Scan Paths: Path0000: C:\ ...

JOIN US NOW to remove these Ads

pc help forum number one in the search engines
Post New Thread  Reply
  #1  
Old 12-30-2007
johannly's Avatar
Bronze Member
My PC
 
Join Date: Dec 2007
Posts: 41
PC Experience: Some Experience
johannly - See this Members User comments on their Profile page
Unhappy backdoor help

[IMG]file:///C:/Users/Johannly/AppData/Local/Temp/moz-screenshot-2.jpg[/IMG] BitDefender Log File !!!!!
Product : BitDefender Total Security 2008 Version : BitDefender UIScanner v.11 Log date : 10:15:23 29/12/2007 Log path : C:\ProgramData\BitDefender\Desktop\Profiles\Logs\d eep_scan\1198941323_1_02.xml

Scan Paths: Path0000: C:\ Path0001: D:\

Scan Options: Scan for viruses : Yes Scan for adware : Yes Scan for spyware : Yes Scan for applications : Yes Scan for dialers : Yes Scan for rootkits : Yes

Target selection options: Scan registry keys : Yes Scan cookies : Yes Scan boot sectors : Yes Scan memory processes : Yes Scan archives : Yes Scan runtime packers : Yes Scan emails : Yes Scan all files : Yes Heuristic Scan : Yes Scanned extensions :
Excluded extensions :


Target Processing Default action for infected objects : Disinfect Default action for suspicious objects : None Default action for hidden objects : None

Scan engines summary Number of virus signatures : 962683 Archive plugins : 41 Email plugins : 6 Scan plugins : 12 Archive plugins : 41 System plugins : 4 Unpack plugins : 7

Overall scan summary Scanned items : 136328 Infected items : 1 Suspicious items : 0 Resolved items : 0 Individual viruses found : 1 Scanned directories : 13271 Scanned boot sectors : 6 Scanned archives : 1581 Input-output errors : 55 Scan time : 00:06:32:22 Files per second : 5

Scanned processes summary Scanned : 56 Infected : 0

Scanned registry keys summary Scanned : 377 Infected : 0

Scanned cookies summary Scanned : 0 Infected : 0

Remaining issues: Object Name Threat Name Final Status D:\$RECYCLE.BIN\S-1-5-21-574533234-3886537389-1924437317-1000\$RN93J4F.exe=](CAB Sfx r)=]setup1.exe Backdoor.Bot.3365 Delete Failed (file was in an archive)

Resolved issues: Object Name Threat Name Final Status

the antivirus cant delete it, i try to get access to the folder n it doesnt let me, how can i get rid of that virus ?


  #2  
Old 12-31-2007
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 2,299
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: backdoor help

Please download HijackThis to your desktop.. http://www.trendsecure.com/portal/en...HJTInstall.exe
Alternate link
http://download.bleepingcomputer.com...HJTInstall.exe
This program will help us determine if there are any spyware/malware on your computer. Double-click on the file you just downloaded.
Click on the "Unzip" button to install. It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Upon install, HijackThis should open for you.
Should it not open, navigate to C:\Program Files\Trend Micro\HijackThis and double click on HijackThis.exe
1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Post the hijackthis.log file here. Do not fix anything in HijackThis since they may be harmless.

=====================================
Download SDFix from here and save it to your desktop.

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
In Safe Mode, right click the SDFix.zip folder and choose Extract All,
Open the extracted folder and double click RunThis.bat to start the script.
Type Y to begin the script.
It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
Finally paste the contents of the Report.txt back on the forum.

=========================================
This will help to identify malware on your system.
Please download Combofix from any of these locations:

Here
or
Here

Save ComboFix to the desktop and please ensure that you disable realtime security/virus programs that monitors your PC while CF is running.
1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Copy and Paste the contents of that log in your next reply with a new hijackthis log. Do not use Code or html unless asked for.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
Caution...Never run and remove files using ComboFix without being supervised by a security analyst.

=========================================

Go to Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #3  
Old 01-14-2008
johannly's Avatar
Bronze Member
My PC
 
Join Date: Dec 2007
Posts: 41
PC Experience: Some Experience
johannly - See this Members User comments on their Profile page
Default Re: backdoor help

pancake thx but this reply is not really useful first i know where the virus is located so i dnt see a reason to do a new hijack log nor to do a new scan i know what i have i only wanna know how to delete it, second those tools u give to use cant b used in vista last time u said this to me i tried n i had to end up formating my laptop
thx for ur concern
ps. dahli gave me a good solution


  #4  
Old 01-14-2008
Pancake's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Victoria, Australia
Posts: 2,299
PC Experience: Elite PC Guru
Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page Pancake - See this Members User comments on their Profile page
Default Re: backdoor help

I cant even remember replying to this thread...ummm.Anyway the programs do run on Vista without a problems.It must have been someting on your system that fouled things up. Ok.as long as you have a solution for it thats great...


__________________
  • An Australian Member of
  • and
My real name is Eddy
  #5  
Old 01-14-2008
johannly's Avatar
Bronze Member
My PC
 
Join Date: Dec 2007
Posts: 41
PC Experience: Some Experience
johannly - See this Members User comments on their Profile page
Wink Re: backdoor help

Originally Posted by Pancake View Post
I cant even remember replying to this thread...ummm.Anyway the programs do run on Vista without a problems.It must have been someting on your system that fouled things up. Ok.as long as you have a solution for it thats great...
i dunno it didnt work in mine, n well that time dahli offered to help me solve the problem cuz my laptop stopped working after using sdfix n combofix but as i work in my laptop i needed it soon so i formatted
i really appreciate ur concern
thx
n continue with ur good job

plse if u can check my new thread
http://www.pchelpforum.com/windows-v...e-what-do.html
i would appreciate any advice

if u wanna check the old issue with combofix
http://www.pchelpforum.com/hijackthi...ete-virus.html



Last edited by johannly; 01-14-2008 at 07:04 AM.

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 11:59 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top