Help w/ Backdoor.Spyboter.gen

Discussion in 'Malware Help (A Specialist Will Reply)' started by mick1064, Oct 15, 2005.

  1. mick1064

    mick1064 Private E-2

    OK, I'm dumber than dumb. Have run MS AntiSpyware, Windows registry repair Pro, Norton, AdAware, CCCleaner, AntiVir Xp, have followed directions on Symantec site to disable sys restore, run norton and restore, norton does not find it, nor do any of the others. I get the High risk alerts that it has located/attempted to repair & then deleted, but this is a constant pop up. three days running, I try to run a search on this, it shows up and then is gone, just that quick. I am at best a novice, but directions I can follow. Any help is greatly appreciated!! Please e-mail at (edit by chaslang: email address deleted). Thanks in advance.
     
    Last edited by a moderator: Oct 15, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry Mick! We work here in the threads! Not in emails! In fact it is a very bad idea to put your email into a forum like that. It is a great way to get yourself added to thousands of spammer's lists. I deleted your email address from your message for your protection.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    .
     
  3. mick1064

    mick1064 Private E-2

    I guess the first line of my question says it all !!! Thank you sir, I will review and get back later tonite.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is no need to feel that way. We all have to learn some how. If no one ever made a mistake, there would never be anything to learn. ;) Post back when you finish all the steps. I know you may have done some already but make sure you follow all of the steps given anyway and follow them in the order given and in safe mode (as directed).
     
  5. mick1064

    mick1064 Private E-2

    OK, so far so good, seems like the online virus scans take forever!! Started RAv @ 9:30 PM, still scanning, it's now 10:49PM. What gives? I have to work in the morning!! Tried my Norton scan, they all take hours,, what could this mean, if anything? Thanks, I am going to restore system, and log off for the night. Will be back tomorrow late afternoon. Thanks again for the help.
     
  6. mick1064

    mick1064 Private E-2

    Had to stay up, took 2 hours!!!! Will do the other tomorrow.


    Objects: 108705
    Directories: 4068
    Archives: 3454
    Size(Kb): 2069234
    Infected files: 0

    Found
    ============================
    Viruses found: 0
    Suspicious files: 0
    Disinfected files: 0
    Mail files: 75
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the online scanners can take awhile to run. If you have a lot of files and a slow internet connection it does take a long time. Also if you do any other surfing (which is not recommended) while doing the scans, it takes even longer. Yes, your antivirus scan can take a long time to complete too. What do you mean you are going to restore system? The first step of the cleaning process was to disable system restore. That means there is nothing to restore.
     
  8. mick1064

    mick1064 Private E-2

    I meant to say I was going to enable sysem restore. I have a dsl line and wasn't surfing at all. I never do, afraid I'll pick up something else. It picked up no viruses at all and the spybot seems to be gone. The only other problem now is the system is still very slow to open programs, and even upon inital start up, it takes a few minutes to open. Is there any program to show me what I may be able to get rid of that is slowing me down?

    I am going back to disable system restore and run a second scan like Trend micro, I'll update you as soon as that is finished. Thanks for all the help so far.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be enabling system restore until we have verified that your system is clean!

    Complete all of what I gave you in message # 2.
     
  10. mick1064

    mick1064 Private E-2

    Ok, here is the last of the program !! I could not run the scans online in safe mode. I did run ad aware, ccleaner, spybot & MS windows anti spy in safe mode. The only one to find anything was ad aware. deleted all. System seems to have deleted the backdoor spyboter but still slow on start up and upon loading programs. Please advise as to any fixes for this, & thanks again & again, you come to Cleveland I'll buy the steak & beer. You guys saved the computer from a deadly " suicide by cop" here. it was close to the 2nd floor window!!!
     

    Attached Files:

    Last edited: Oct 16, 2005
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First observation is a violation of step 3 in the READ ME. Chosse which antivirus you want and uninstall any others. This is a huge waste of system resources. You have three AVs running.

    Second observation: you did not follow the steps in: Downloading, Installing, and Running HijackThis
     
  12. mick1064

    mick1064 Private E-2

    Are you referring to Norton? I believe that is the only one I have. I had Zone Alarm just for the firewall as it was recomended. Should that be deleted?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Third observation which is a big no no and is covered in the How to Protect yourself from malware! sticky thread step 3. Only use one firewall. You have ZoneAlarm, Norton, and possibly the one in Win XP SP2 all running.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You have Symantec/Norton, Yahoo's Antivirus, and AV Personal all running.

    And did you see my message about firewalls?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds