Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Need tech help - backdoor bla trojan.

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 02:15 PM
Original message
Need tech help - backdoor bla trojan.
My virus scan popped up for the first time ever today and said that the bla trojan had been found. It made some mention of unable to clean file or delete file or something (wish I hadn't closed that box). There was a "delete" and "clean" and I clicked both but nothing happened. I found it on my C drive and deleted it. I have not yet emptied my recycle bin. I looked it up at this site: http://securityresponse.symantec.com/avcenter/venc/data/pf/backdoor.bla.trojan.html and read through it but am not exactly clear what further steps I should take. It mentions that the trouble starts once the computer is turned off. I have run AdAware and Spybot, though not sure they would deal with this one. Anything else I need to do?
Printer Friendly | Permalink |  | Top
havocmom Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 02:18 PM
Response to Original message
1. Might wanna post in computer forum too
It's way cool. You might get some help from 'puter whiz who don't hang in the lounge

http://www.democraticunderground.com/discuss/duboard.php?az=show_topics&forum=242
Printer Friendly | Permalink |  | Top
 
trotsky Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 02:23 PM
Response to Original message
2. What exactly were you doing when the vscan popped up?
If you were opening an e-mail or a web page, or maybe launching a program or file, your anti-virus successfully interrupted the installation of the trojan, and your system is still clean.

You should do a complete system scan of your hard drive to see if it still finds anything.
Printer Friendly | Permalink |  | Top
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 02:31 PM
Response to Reply #2
4. I had programs from work running
but I had spent about 10 minutes downloading pictures from my camera when it popped up.
Printer Friendly | Permalink |  | Top
 
Padraig18 Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 02:25 PM
Response to Original message
3. Run your virus scan IMMEDIATELY.
See if it finds anything, first, and if it does, use the lcean/quarantine feature. Do NOT turn your comp off.
Printer Friendly | Permalink |  | Top
 
PoohStuff Donating Member (46 posts) Send PM | Profile | Ignore Sun Nov-21-04 02:44 PM
Response to Original message
5. Let's get started...
Edited on Sun Nov-21-04 02:49 PM by PoohStuff
I'm assuming you have windows XP, which is slightly easier to deal with. Go step by step to remove the virus via Symantec's recommendations:

If you are networked, disconnect from the network by unplugging all other Ethernet cables from the back of those computers.

1. Try closing all your un-needed services Click on Start, Control Panel, Administrative Tools, Services.

You'll get a list in alphabetical order, Start with Windows Messenger (it's not the IM Service). Double click on it, and click the Stop Button then you'll see a drop down box click on that and disable it, click apply then OK.

Do the same with Telnet. You don't need those, they are for advanced networking and won't interfere with your network, and plus leaves you open for these types of attacks.


Turn on Windows XP firewall, if you download something new you'll have to restart the computer for it to take effect and that's what we don't want. Click on Start, Control Panel, Network Connections. You see your connections there, Local Area Connection, or Dial UP whatever is enabled, just right click on it and Click Properties.

Click the Advanced Tab then enable firewall. Click OK.

Then Run Live Update, do another system scan.

Scroll down symantec's website and Print out and follow the instructions on how to back up and restore the system registry (the entire one) then follow the instructions on how to remove the infected keys.

After that re run the system scan.

Spybot, Adaware are neat programs, but it wont help only detect.

If none of symantec's removal instructions help then you want to back up all files and restore the system (worst Case)

If it does work I can suggest two sites. www.pcpitstop.com and grc.com (no www. on grc.) Sign up for the free account on PC Pitstop and run full tests. Then follow the instructions if you don't get a checkered flag. They have automated repairs. Then grc.com click on sheilds up then click on it again and click common ports. This will test if you still have open ports on your system. You want to have stealth when the results come back.

Hope this helps, I couldn't post in the Techie group cause I can't afford to donate. Sorry. Let me know if you need any additional help.
Printer Friendly | Permalink |  | Top
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 02:55 PM
Response to Reply #5
6. I have Windows 2000.
Do I do the same thing?
Printer Friendly | Permalink |  | Top
 
PoohStuff Donating Member (46 posts) Send PM | Profile | Ignore Sun Nov-21-04 02:57 PM
Response to Reply #6
7. Yes you can do the same thing
Edited on Sun Nov-21-04 03:04 PM by PoohStuff
Windows XP and 2000 is based on the Windows NT OS. They're almost mirrors. You might have to skip the firewall step though. In fact if it saves you time do the single registry key backup, it might be in your favor. Be Careful and back up the right key it's EXTREMELY important.
Printer Friendly | Permalink |  | Top
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-21-04 03:15 PM
Response to Reply #7
8. Thanks.
I have printed out your directions and will try it in a little bit. I'll let you know how it goes. Thanks for all the detailed help!
Printer Friendly | Permalink |  | Top
 
PoohStuff Donating Member (46 posts) Send PM | Profile | Ignore Sun Nov-21-04 03:21 PM
Response to Reply #8
9. Anytime!
:hi: Please let me know how it goes, I hate to hear how someone's waste of time (virus programmers) bother good people! :toast:
Printer Friendly | Permalink |  | Top
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Nov-22-04 10:25 AM
Response to Reply #9
10. I guess you don't get e-mail without a star.
I tried to send you one and it didn't work. We did all the stuff you said but I have yet to reboot my computer but I guess I need to. I am afraid to do internet banking right now. How will I know for sure the virus is not lurking somewhere in the computer?
Printer Friendly | Permalink |  | Top
 
PoohStuff Donating Member (46 posts) Send PM | Profile | Ignore Mon Nov-22-04 01:13 PM
Response to Reply #10
11. Run another final virus scan....
Edited on Mon Nov-22-04 01:22 PM by PoohStuff
And if it comes out clean, reboot. :D I have faith you did well! Lemme Know! As for my email, I checked everything I dunno why I didn't get one. :shrug:

Oh btw... go to www.zonelabs.com and download the free version of Zone Alarm. It's a great firewall and easy to use. You'll know exactly which programs on your computer are trying to access the internet and can block them accordingly or allow them. It comes with a tutorial too.
Printer Friendly | Permalink |  | Top
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Nov-22-04 02:20 PM
Response to Reply #11
12. Thanks again.
What does having a star allow you to do? Can you not post in some of the forums or what?
Printer Friendly | Permalink |  | Top
 
PoohStuff Donating Member (46 posts) Send PM | Profile | Ignore Mon Nov-22-04 03:28 PM
Response to Reply #12
13. aah, found that in the faq...
means that you donated! I have yet to do so, hopefully it'll be a xmas prezzie for me :party:!
Printer Friendly | Permalink |  | Top
 
TNDemo Donating Member (1000+ posts) Send PM | Profile | Ignore Mon Nov-22-04 03:29 PM
Response to Reply #13
14. If you are not able to donate I could make a donation
in your name as a thanks for the help.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 04:49 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC