IPB

Welcome Guest ( Log In | Register )

2 Pages V  < 1 2  
Closed TopicStart new topic
> Backdoor.Win32.Rbot.gay
Lucian Bara
post 11.01.2008 22:51
Post #21


True legend
***************

Group: Moderators
Posts: 52487
Joined: 28.01.2006
From: Timisoara, Romania




read post 5 please. it's probably autodownlaoded by something undetected on your pc.

This post has been edited by Lucian Bara: 11.01.2008 22:51


--------------------
Go to the top of the page
 
+Quote Post
dawgg
post 12.01.2008 01:51
Post #22


Forum Elite
**************

Group: Moderators
Posts: 6828
Joined: 6.04.2006
From: London




jeeeezzzzzzz! dash2.gif
Go to the top of the page
 
+Quote Post
nenolovesopera
post 12.02.2008 16:51
Post #23


Member
**

Group: Members
Posts: 15
Joined: 3.01.2008




I am so desperate.
After, maybe 1 month, the virus came back in to my lap top sad.gif
I am worried.
I don't know how to do this from the post 5 ???
Please help me!

And why the virus is called:.gay ?
Go to the top of the page
 
+Quote Post
Lucian Bara
post 12.02.2008 16:54
Post #24


True legend
***************

Group: Moderators
Posts: 52487
Joined: 28.01.2006
From: Timisoara, Romania




i already explained why it's .gay, in post 5.

QUOTE
no "gay" is simply a 3 letter variant designation (starts at a, b,c, then aa and so on, now it's at ggx). unfortunatly gay is a 3 letter word, that's why: http://www.kaspersky.com/viruswatchlite?se...amp;x=0&y=0


how to do it.
1 you download and save it to your desktop: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
2 you execute it
3 you follow the steps, it should be straight forward.
4 when it's done it will probably want to reboot, after the reboot you will find a file called c:\combofix.txt, open it with notepad, copy the contents and post it here.


--------------------
Go to the top of the page
 
+Quote Post
nenolovesopera
post 14.02.2008 17:22
Post #25


Member
**

Group: Members
Posts: 15
Joined: 3.01.2008




and sp what should I aspect from this?
what will be the results?
Go to the top of the page
 
+Quote Post
Don Pelotas
post 14.02.2008 18:13
Post #26


Global Moderator
***************

Group: Global moderators

Posts: 25601
Joined: 7.04.2005




QUOTE(nenolovesopera @ 14.02.2008 15:22) *
and sp what should I aspect from this?
what will be the results?

I think this is where you ask yourself if you really want any help, you don't have to do what is suggested, but on the other hand if you don't then most will probably just ignore after a while.


--------------------
Go to the top of the page
 
+Quote Post
mr_goh
post 27.02.2008 06:35
Post #27


Member
**

Group: Members
Posts: 10
Joined: 9.02.2008




Hey.. i need help on this.. i realized i got this problem yesterday!! and kaspersky can't seemed to delete it or something else is playing tricks!!

anyway.. i ran ComboFix and I attached the file here.. hope someone can help check if I still need to do anything else to get rid of this stupid rbot.gay!!

thanks!!!
Attached File(s)
Attached File  ComboFix.txt ( 23.43K ) Number of downloads: 9
 
Go to the top of the page
 
+Quote Post
mr_goh
post 27.02.2008 13:24
Post #28


Member
**

Group: Members
Posts: 10
Joined: 9.02.2008




QUOTE(mr_goh @ 27.02.2008 11:35) *
Hey.. i need help on this.. i realized i got this problem yesterday!! and kaspersky can't seemed to delete it or something else is playing tricks!!

anyway.. i ran ComboFix and I attached the file here.. hope someone can help check if I still need to do anything else to get rid of this stupid rbot.gay!!

thanks!!!


looks like nobody's interested to help...

but anyway.. i scanned my laptop using CounterSpy and managed to detect Bifrost
http://research.sunbelt-software.com/threa...;threatid=29428

and deleted the problem already..hopefully it's related and my laptop is trojan free!!!
Go to the top of the page
 
+Quote Post
Baz^^
post 27.02.2008 13:58
Post #29


Wrestling Champion
**************

Group: Moderators
Posts: 8026
Joined: 9.03.2007
From: London




Posted by mr_goh Today, 03:35


Unfortunately, we do not read posts at 3AM local time. Remember that we are in different timezones and we also have other responsibilites so it may take a while for a reply. Be patient smile.gif

This post has been edited by MAPKOBKA^^: 27.02.2008 13:59


--------------------
Kind Regards,

Baz (Volunteer Moderator aka I don't work for Kaspersky ;)
)

Get 10% off all Kaspersky products!
Go to the top of the page
 
+Quote Post
mr_goh
post 28.02.2008 09:21
Post #30


Member
**

Group: Members
Posts: 10
Joined: 9.02.2008




QUOTE(MAPKOBKA^^ @ 27.02.2008 18:58) *
Posted by mr_goh Today, 03:35
Unfortunately, we do not read posts at 3AM local time. Remember that we are in different timezones and we also have other responsibilites so it may take a while for a reply. Be patient smile.gif


oh.. hahaha.. sorrie then.. i was expecting people from somewhere.. anywhere that can give me an answer.. thanks for the reminder though.. b_punk.gif

anyway.. looks like the CounterSpy didn't solve the problem!! sigh... the trojan is still around ...

This post has been edited by mr_goh: 28.02.2008 09:22
Go to the top of the page
 
+Quote Post
dawgg
post 28.02.2008 13:25
Post #31


Forum Elite
**************

Group: Moderators
Posts: 6828
Joined: 6.04.2006
From: London




Where does Kaspersky detect the backdoor?... where is it located and what is its file name?
Where did CounterSpy detect Bitfrost?... location and file name...
Please submit the BitFrost which CounterSpy detected to Kaspersky's VirusLab... instructions shown here: http://forum.kaspersky.com/index.php?showtopic=13881


Click Start>Run>regedit
... navigate to HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ and delete that key/folder

Click Start>Search>File&Folder>AllFilesAndFolders... where it says "all or part of the filename", search for autoregistry.exe and autorun.exe. Submit them to Kaspersky's VirusLab

Also submit the following files to Kaspersky's Viruslab
C:\QooBox\Quarantine\C\WINDOWS\system32\nsprs.dll
C:\QooBox\Quarantine\C\WINDOWS\system32\prsgrc.dll
C:\QooBox\Quarantine\C\WINDOWS\system32\prsrvk.dll
Go to the top of the page
 
+Quote Post
mr_goh
post 29.02.2008 04:36
Post #32


Member
**

Group: Members
Posts: 10
Joined: 9.02.2008




QUOTE(dawgg @ 28.02.2008 18:25) *
Where does Kaspersky detect the backdoor?... where is it located and what is its file name?
Where did CounterSpy detect Bitfrost?... location and file name...
Please submit the BitFrost which CounterSpy detected to Kaspersky's VirusLab... instructions shown here: http://forum.kaspersky.com/index.php?showtopic=13881
Click Start>Run>regedit
... navigate to HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\ and delete that key/folder

Click Start>Search>File&Folder>AllFilesAndFolders... where it says "all or part of the filename", search for autoregistry.exe and autorun.exe. Submit them to Kaspersky's VirusLab

Also submit the following files to Kaspersky's Viruslab
C:\QooBox\Quarantine\C\WINDOWS\system32\nsprs.dll
C:\QooBox\Quarantine\C\WINDOWS\system32\prsgrc.dll
C:\QooBox\Quarantine\C\WINDOWS\system32\prsrvk.dll


Hi, I had already deleted the registry but once in a while i still get the prompt for the trojan.
I searched for autoregistry.exe and autorun.exe and found 2, but i'm quite sure they are not the problem because 1 of them is actually fires SQL2000 install menu and the other fires my USB Camera's driver.

I'm using Kaspersky 6.0 and i do not have the "send" option. So how do i submit the files?

thanks for your prompt reply though.. b_punk.gif

copied from CounterSpy, sorrie.. i can't find the log file...
QUOTE
Bifrost Backdoor more information...
Details: Bifrost is an advanced remote administration tool that allows users to remotely control computers that are behind firewalls and routers.
Status: Deleted

Registry entries detected
HKEY_USERS\S-1-5-21-4079698638-1517994909-2720848000-500\SOFTWARE\WGET
Go to the top of the page
 
+Quote Post
dawgg
post 29.02.2008 12:42
Post #33


Forum Elite
**************

Group: Moderators
Posts: 6828
Joined: 6.04.2006
From: London




Dont wory about sending it if you're sure its clean.

Send the files using instructions shown here: http://forum.kaspersky.com/index.php?showtopic=13881

CounterSpy just found a registry entry, not a malicious file... (nothing to do with something which Kaspersky would have detected)


Open Kaspersky, click "computer protection status" and then the "detected" tab. Please post a screenshot of that. (Make sure we can see everything in the "Object" column; (full directory and filename)
Go to the top of the page
 
+Quote Post
mr_goh
post 3.03.2008 04:17
Post #34


Member
**

Group: Members
Posts: 10
Joined: 9.02.2008




QUOTE(dawgg @ 29.02.2008 17:42) *
Dont wory about sending it if you're sure its clean.

Send the files using instructions shown here: http://forum.kaspersky.com/index.php?showtopic=13881

CounterSpy just found a registry entry, not a malicious file... (nothing to do with something which Kaspersky would have detected)
Open Kaspersky, click "computer protection status" and then the "detected" tab. Please post a screenshot of that. (Make sure we can see everything in the "Object" column; (full directory and filename)


hi there... i'd emailed the suspected virus files already... hope you guys got it..

the screen shot you requested is as follows... thanks!



This post has been edited by mr_goh: 3.03.2008 04:19
Go to the top of the page
 
+Quote Post
dawgg
post 3.03.2008 14:40
Post #35


Forum Elite
**************

Group: Moderators
Posts: 6828
Joined: 6.04.2006
From: London




QUOTE(mr_goh @ 29.02.2008 01:36) *
Hi, I had already deleted the registry but once in a while i still get the prompt for the trojan.

Has this happened recently again?... If it has, what trojan was it and where was it located?
Go to the top of the page
 
+Quote Post
mr_goh
post 4.03.2008 11:44
Post #36


Member
**

Group: Members
Posts: 10
Joined: 9.02.2008




QUOTE(dawgg @ 3.03.2008 19:40) *
Has this happened recently again?... If it has, what trojan was it and where was it located?


hi... i sent another 2 files to the kaspersky team,
2k3.exe and eq

currently.. yes... i still have the problem.. kaspersky still prompts the message every once in a while...



if you notice.. the list is getting longer... i'm not sure if the
trojan-downloaded.bat.ftp.ab virus is downloading the files..

for you info, the files renamed as *.vir are done by me... i was compiling the virus to be sent to kaspersky for investigation... anyway.. i deleted all the *.vir files already..

This post has been edited by mr_goh: 4.03.2008 11:51
Go to the top of the page
 
+Quote Post
dawgg
post 4.03.2008 12:44
Post #37


Forum Elite
**************

Group: Moderators
Posts: 6828
Joined: 6.04.2006
From: London




Can you please post another Combofix log.

Also post a link to your PC's GSI Parser here.
Instructions shown here: http://gsi.kaspersky.fr/
Scroll down and read the following links on the page for instructions
"How to create a GetSystemInfo report file using GetSystemInfo utility"
"Video : How to create and upload a GetSystemInfo report?)
Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 22.11.2009 02:51