Travel Fans
Go Back   Computer Juice Computer Software Virus, Spyware & Security

Register

 Default 

Ugh, Spyware.banker/backdoor.bot...AGAIN!




Reply
 
Thread Tools
  #11  
Old 11th Jun 2009, 17:51
Moderator
Posts: 7,561
 
Try this first.

The below is based on original info from http://support.microsoft.com/kb/949377

Important: This task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

How to back up and restore the registry in Windows

* Download and then install SubInACL (SubInACL.exe) file from Microsoft.
* Click Start > Run and type notepad.exe and click OK to bring up Windows Notepad.
* Copy and then paste the following text into Notepad.

Code:
cd /d "%ProgramFiles%\Windows Resource Kits\Tools"
subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose
* Save this Notepad file as Reset.cmd to your desktop. Be sure the Save as type is set to all files.
* Once you have save it properly, double-click the Reset.cmd file to run the script.
** Note: This script file may take a long time to run. Additionally, you have to run this script as an administrator.
* Now reboot your computer! You must do this before the above will take effect.
__________________


  #12  
Old 14th Jun 2009, 09:56
Full Member
Posts: 40
 
Ok, that ran how it should. What now?
  #13  
Old 14th Jun 2009, 10:04
Moderator
Posts: 7,561
 
Try running ComboFix again.
__________________

  #14  
Old 14th Jun 2009, 11:59
Full Member
Posts: 40
 
No luck on combofix but this folder appears in the C: Drive after I run it.
Attached Images
File Type: jpg pmgdk.jpg (47.1 KB, 16 views)
  #15  
Old 14th Jun 2009, 12:07
Moderator
Posts: 7,561
 
Go to Start > Run and type scandisk /f then click OK.

Let it run, you will likely be prompted to restart.
__________________

  #16  
Old 14th Jun 2009, 13:31
Full Member
Posts: 40
 
Ok, ran that. I assume chkdsk was the same thing?
  #17  
Old 14th Jun 2009, 13:39
Moderator
Posts: 7,561
 
It's a little different. Any changes with running CF?
__________________

  #18  
Old 14th Jun 2009, 16:43
Full Member
Posts: 40
 
Nothing yet.


When I download cf it obviously is saved to the desktop, but is it saving anything to system32 or system folders?
  #19  
Old 14th Jun 2009, 17:00
Moderator
Posts: 7,561
 
It should only save a folder in your C drive when you run it.

I'm at a loss as to what's going on.
__________________

  #20  
Old 14th Jun 2009, 17:57
Full Member
Posts: 40
 
I am 90% sure I may have just figured it out. I went to another computer I had and when I pulled up CMD the prompt line read C:\Documents and Settings\username> HOWEVER...when I enter CMD on this computer it reads C:\windows\system32>...I believe that when the programs that we try to run use CMD, they are somehow being routed to system32 folder and not C:\Documents and Settings\username? Is there a way to change this 'route' so to speak for cmd?
Attached Images
File Type: jpg windows.jpg (31.7 KB, 7 views)
Reply

Register

Similar Threads
Thread Thread Starter Forum Replies Last Post
Spyware.Banker Detected in MBAM Scan SevenYears Virus, Spyware & Security 88 28th Apr 2009 18:30
Evqcpq0tc.exe - (Backdoor.Bot) New Virus Not on Google. mursfSmurf Virus, Spyware & Security 2 24th Mar 2009 17:32
Spyware help, please! rkdub Virus, Spyware & Security 2 17th Oct 2008 05:07
Do I have Spyware, and if yes, how do I get rid of it?? Please Help! harvey45 Virus, Spyware & Security 5 6th Oct 2008 15:43
Spyware Q? Daniels2386 Virus, Spyware & Security 4 11th Jan 2008 16:43
Thread Tools



Translations Powered by Powered by Google
Arabic Bulgarian Chinese Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Taiwanese Thai Turkish Ukrainian

Copyright ©2006 - 2010 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2010 Jelsoft Enterprises Ltd. SEO by vBSEO ©2009, Crawlability, Inc.