Author Topic: I need help to remove backdoor.bot  (Read 16049 times)

0 Members and 1 Guest are viewing this topic.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: I need help to remove backdoor.bot
« Reply #15 on: December 15, 2010, 01:37:06 AM »
well I checked the infected PC each day and seems all good now

last thing I needed was an infection on a PC that was not in everyday use - it may not have been fully protected
and so silly to let person continue to use after removing a threat and without first running full check

so very rushed keeping up
I have inserted the link above that shows a relation between sdra64.exe and Sality (I forgot it at the time)
here it is again   http://www.threatexpert.com/files/palma.exe.html

Damn tough! - was other nasties bundled in the malware package so it seems -

http://www.threatexpert.com/report.aspx?md5=d751fbeae92ebb65b641bfdfba3e03ea

though only bits and pieces left, so I dont really know - I would say the infection did not have time to spread
possibly bootkit behavior in the short time that I was watching it as active entity

usually have a bit more time to play with and removal procedure is not so pressing - this time nearly got bombed!

I have sent the files to avast


« Last Edit: December 15, 2010, 01:39:55 AM by mkis »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

nsm0220

  • Guest
Re: I need help to remove backdoor.bot
« Reply #16 on: December 15, 2010, 05:07:26 AM »
you meant rootkit not bootkit

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: I need help to remove backdoor.bot
« Reply #17 on: December 15, 2010, 06:50:00 AM »
That was a version of Zeus so it was keylogging.  It can be removed but not automatically, manual removal is needed for some elements

sdra64.exe is one of the key files.  Although I gather the Zeus author has now come up with a better version, that will start relying on bootkits like whistler   

the PC was no longer in front line use, mainly for other people, lend-out, etc....so that and because busy with other important things meant unfortunately a rush disinfection where i couldn't record and document as I was going
- but I am still doing brief check each day so can reply post here if anything else comes up

and btw, the nasty bugger also changed settings in Internet Options > Connections > LAN settings  - from Automatic Configuration It changed the setting to Proxy Server
- this is a common behavior for malware and something that should always be checked when internet settings are not functioning as they should


Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I need help to remove backdoor.bot
« Reply #18 on: December 15, 2010, 09:05:54 PM »
Another area to check is the router as they change the DNS settings in there as well - nice people

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: I need help to remove backdoor.bot
« Reply #19 on: December 15, 2010, 10:42:33 PM »
hahaha yes so nice that I'd like to get my hands on them

I will make sure to ring my local ISP (slingshot.co.nz) and run through the router settings with them
- from what I can gather all seems okay on the sheets, but there is a few things there that I dont understand, so will be a good exercise to get to know my gateway a bit better.

At the time I was using a Netgear switch and I had I think it was four computers running at once as stand-alone units (no software LAN setup as such)
Do you think it possible for the malware to infect the switch and so the other computers under these condition? myself I think maybe yes

like, I think the switch has an individual ARP for each computer linking it to the router, I guess - and then on to the internet
I suppose if the infection creeps outward from one computer to the router, then each computer on the other side of the switch will also come under threat
- even tho there is no real intranet as such, directly linking them all together (so each has its own ARP list rather than sharing one)

I'm not using the switch at the moment because its too noisy - and also I've put some of my LAN ideas to one side for the moment
I think maybe look at some protection at the router location - I may have been lucky not to get a fully blown breakout on all four computers

bad enough as it was anyway - I had to reset the Services this morning as they were all reading 'disabled'
in fact lots of little bits and pieces to tidy up amongst the tools and utilities - still, a nice learning curve in this little experience  :)
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I need help to remove backdoor.bot
« Reply #20 on: December 15, 2010, 11:08:01 PM »
The problem with these type of file infectors is not so much the removal, but more of repairing the damage that they do to the sytem files 

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: I need help to remove backdoor.bot
« Reply #21 on: December 16, 2010, 01:21:02 AM »
yes its usually small fry that I come across

this thing left quite a trail of behind it
I'm thinking of doing a repair anyway to tidy up the Windows config,though it has come up quite good
I've got it unhooked from the internet at the moment and avast uninstalled
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.