Computing.Net > Forums > Security and Virus > Norton detected a virus backdoor.d

Norton detected a virus backdoor.d

Reply to Message Icon

Original Message
Name: Chrissie
Date: June 22, 2003 at 08:50:08 Pacific
Subject: Norton detected a virus backdoor.d
OS: Windows 2000 pro
CPU/Ram: Pent. II
Comment:

I received a message when I sat down at the computer this AM that Norton found the backdoor.dvldr virus in windows\systems32\inst.exe and could not repair the file. I ran a virus scan and Norton did not detect the virus. How do I resolve this issue? I have updated Norton and hit there web page with no success. Also I read a prior posting about iexplore.exe running but there was not a solution provided. I also have this running. Do I have a problem and if so what next?



Report Offensive Message For Removal


Response Number 1
Name: EC
Date: June 22, 2003 at 10:10:19 Pacific
Subject: Norton detected a virus backdoor.d
Reply: (edit)

Sounds like deloder backdoor.
Visit:
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.dvldr.html


Report Offensive Follow Up For Removal

Response Number 2
Name: michael2
Date: June 22, 2003 at 10:30:30 Pacific
Subject: Norton detected a virus backdoor.d
Reply: (edit)

According to Symantec, this Trojan can deny you control of the PC. Blocking websites may be one of these denials.
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.dvldr.html

This is what Symantec report for Win2000....

1. Update the virus definitions.
2. Windows NT/2000/XP: End the Trojan process.
3. Run a full system scan and delete all the files detected as Backdoor.Dvldr.
4. Reverse the changes that the Trojan made to the registry.

Windows NT/2000/XP
To end the Trojan process:
a. Press Ctrl+Alt+Delete once.
b. Click Task Manager.
c. Click the Processes tab.
d. Double-click the Image Name column header to alphabetically sort the processes.
e. Scroll through the list and look for the following:
explorer.exe

NOTE: If the Trojan is running, you will see two explorer.exe entries in the list. To find which is the AT&T VNC server for each explorer.exe entry, look at the values for PID and Mem Usage. The AT&T VNC server disguised as explorer.exe will have a higher PID number and lower Mem Usage than the legitimate explorer.exe.

rundll32.exe

f. For each one that you find, click it, and then click End Process.
g. Exit the Task Manager.

4. Reversing the changes made to the registry

CAUTION: Symantec strongly recommends that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.

a. Click Start, and then click Run. (The Run dialog box appears.)
b. Type regedit

Then click OK. (The Registry Editor opens.)

c. Navigate to the key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

d. In the right pane, delete these values:

Explorer %windows%\Fonts\explorer.exe
TaskMan %windows%\Fonts\rundll32.exe

e. Exit the Registry Editor.


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Norton detected a virus  backdoor.d

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 3 Days.
Discuss in The Lounge