|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
back door virus is KILLIN ME HELP!!!!!!!
|
Original Message
|
Name: GhOsT
Date: February 23, 2002 at 08:21:48 Pacific
Subject: back door virus is KILLIN ME HELP!!!!!!!
|
Comment: I have nav 2002 npfirewall 2002 . Had c:windows\system 32\systsecure32.exe has backdoor.systsec virus. Deleted the quaranteened file two times scaned pc with nav 2002 no virus found. but when i scanned my pc thru nav's website http://security2.norton.com/ssc/home.asp?j=1&langid=us&venid=sym&plfid=20&pkj=CREJCVGZBZTVOGXFSTZ , it found the virus in my comp I tried to delete it from my registry but cant find it. Can any of you help me with it. I quaranteened the file & deleted it both the times I went thru yahoo & used panda active scan & found 2 viruses thats right not one but 2 !!! I dont know why but when i scanned the infected file with nav it didn't find a virus so i quaranteened the file fl2.exe in c/windows/temp infected with bck/subseven.22.b1 should i delete it? The other virus which nav & panda detected & i have no idea how to get rid of are bck/syst in c:/system volume information\restore{numbere &txt}more no's &txt.exe Any idea how to get rid of the freakin virus & what damage the cause?
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: robert451
Date: February 23, 2002 at 09:24:59 Pacific
|
Reply: (edit)To start with you need to flush the virus out of the restore folder.Ton do this,right click on my computer and select properties.Choose the performance tab,and select file system button.From there choose the troubleshooting tab.You will see a box labled disable system restore.Check this box and reboot.Next clean all files out of temp folder.(show hidden files)Then run live update and rescan your computer.If you have successfully removed virus you should get no warning.Next disable auto protect and go to the norton site to verify scan.If this second scan shows no virus then you are clean.Foolow above directions and re-enable system restore and reboot.This should flush the system out.I have found that if I go to HouseCall.com while Nav's auto protect is active it will read the virus scan as a virus.Let us know how it works.
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: robert451
Date: February 24, 2002 at 07:48:02 Pacific
|
Reply: (edit)Exit all taskes except for systray and explorer,then manually delete contents.I tested my theory of the virus coming back into the temp directory and It is true if you leave the auto protect in NAV active while doing online scan i will pick up virus actvity.I think once you purge sysrestore folder as instructed above you will be clean.
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: Ghost
Date: February 24, 2002 at 12:31:42 Pacific
|
Reply: (edit)thnx fo your reply Rob, but do you Exit all taskes except for systray and explorer,then manually delete contents. By usin alt+ctrl+del & end all the processes except systray and explorer & How do i delete the contents . what contents do you want me to delete is it the contents of c:\windows\temp ?
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: robert451
Date: February 25, 2002 at 06:41:13 Pacific
|
Reply: (edit)delete all the files within that folder(TEMP) manually.May be some in there that wont delete because they are in use.I stil think that you have gotten rid of the virus though.ZA is useful to monitor outgoing net connections.I found a trojan before norton caught it this way.
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: Aniet Guerrero
Date: April 23, 2002 at 09:16:24 Pacific
|
Reply: (edit) I'm going crazy, I opened an email named Internet Explorer wich disable my Norton antivirus , I can not open my quickbooks to be able to run my company, This email subjet was internet Explorer is a _IMVTemp_Show_URL1 with 87 Kb MS-DOS Batch file What can I do??? Please help
Thank you
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
Name: Katie
Date: April 26, 2002 at 17:15:12 Pacific
|
Reply: (edit)I am having the same problem basically but it is a Trojan Horse and I have Windows XP so when I go to do what is suggested, I cannot find the line of procedures as explained above. It has infected 94 files in C:\System Volume Information\restore etc etc etc. It is also in my C:\Windows\Systb.dll, C:\Windows\winobject.dll and C:\Windows\Winserv.exe How do I get it out? Help!!!!!! Katie
Report Offensive Follow Up For Removal
|
|
Response Number 9
|
Name: curioso31
Date: April 30, 2002 at 12:56:56 Pacific
|
Reply: (edit)in portuguese/Brazil ( Brasil ) Eu peguei o vírus Albian , que é tipo o Killin e o Norton/Symantec o detectou , mas não o eliminava , simplesmente o ignorava. Entrei em C > Windows > Temp > e fui descendo até encontrar SystSecure32.exe , foi como o Norton/Symantec o detectou e colocou na quarentena. Tranlate of the portuguese for english.
Report Offensive Follow Up For Removal
|
|
Response Number 10
|
Name: NIKOLA SERBIAN III
Date: May 12, 2002 at 10:04:40 Pacific
|
Reply: (edit)How to delete temporary files. go to Start -> Find -> Files and Programs Click on it, and type *.tmp in the box above and then search for the temporary files everywhere and then delete them. Nikola
Report Offensive Follow Up For Removal
|
|
Response Number 11
|
Name: Joakim
Date: June 4, 2002 at 01:23:31 Pacific
|
Reply: (edit)Solution: One of the new features of Windows Me and Windows XP is System Restore. This feature, which is enabled by default, is used by Windows to restore files on your computer in case they become damaged. Windows Me keeps the restore information in the _RESTORE folder. Windows XP stores this information in the System volume information folder. These folders are updated when the computer restarts. If the computer is infected with a virus, then it is possible that the virus could be backed up in the _RESTORE or System volume information folder. By default, Windows prevents System Restore from being modified by outside programs. Because of this, any repair attempts made by Norton AntiVirus will fail. To work around this, you must disable System Restore, and restart the computer. This will purge the contents of the _RESTORE or System volume information folder. You must then run a full system scan. To disable System Restore: Follow the steps that apply to your operating system: Windows Me: 1. Close all open programs. 2. Right-click My Computer on the Windows desktop, and then click Properties. 3. Click the Performance tab. 4. Click File System. 5. Click the Troubleshooting tab. 6. Check Disable System Restore, click OK, and then click Close. 7. Click Yes to restart. This disables the System Restore feature and will purge the contents of the _RESTORE folder when the system is restarted. 8. Run LiveUpdate and download the latest virus definitions. 9. Make sure that NAV is set to scan all files and all drives, and then scan the computer. 10. After cleaning the infected files, repeat steps 1 through 7, except in step 6, uncheck Disable System Restore. Windows XP: 1. Click Start, and then right-click My Computer. 2. Click Properties. 3. Click the System Restore tab. 4. Check Turn off System Restore. 5. Click Apply, and then click OK. 6. Restart the computer. 7. Run LiveUpdate, and download the latest virus definitions. 8. Verify that NAV is set to scan all files and all drives, and then scan the computer. 9. After cleaning the infected files, repeat steps 1 through 6, except in step 4, uncheck Turn Off System Restore. (Text from NAV)
Report Offensive Follow Up For Removal
|
|
Response Number 12
|
Name: semper fi
Date: July 11, 2002 at 20:43:29 Pacific
|
Reply: (edit)SOMEONE help.....last night i was on gamespy and before i clicked connect something in the cornmer of my eye caught my attetion....it was my Norton Internet Security tellin me i had a hacker but he was blocked....they used backdoor.subseven ......after that they tried to hack me 1098 but were unsuccesfull how do i get rid of this backdoor!??!?!?!?!?!?!
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
|
|
|