Re: Need help removing Backdoor.ProRat virus

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 06/03/05


Date: Thu, 2 Jun 2005 19:04:41 -0400

From: <Mitch@this_is_not_a_real_address.com>

| Thanks for your help!
|
| Ok, I printed your instructions and followed them step-by-step.
| Everything extracted and downloaded successfully.
|
| But when I ran Clean.bat in Safe Mode, the report generated is simply:
|
| "Virus Scan Report File
| Virus Scan Information
|
| McAfee VirusScan for Win32 v4.40.0
| Copyright (c) 1992-2004 Networks Associates Technology Inc. All rights
| reserved.
| (408) 988-3832 LICENSED COPY - Sep 23 2004
| "
|
| That's all.

The program just stopped running ? Hmmm, I wonder if it knew the name of the executable and
shut it down ?

I re-programmed the script to thwart shutting down the scanner and updated the web site with
a new version of the CLEAN.EXE self extracting ZIP file.

Go back and download CLEAN.EXE again from the URL --
http://www.ik-cs.com/programs/virtools/clean.exe

Execute; CLEAN.EXE
Choose; Unzip
Choose; Close

The file...
C:\mcafee\clean.kix should now have the date of 6/2/2005 @ 6:50 PM
{ If it doesn't, clear the Browser cache and then download and execute CLEAN.EXE again }

Then... execute; c:\mcafee\CLEAN.BAT
{ or Double-click on 'Clean Link' in c:\mcafee }

If it runs OK, then reboot and run it in Safe Mode.

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: SP3 potential problem
    ... Enquire, plan and execute ... download the Net framework updates. ... Net Framework items from my machine. ...
    (microsoft.public.windowsxp.basics)
  • RE: File extensions spoofable in MSIE download dialog
    ... notepad.exe (as a file with the usual ".log" extension would be) ... In no instance was I able to "silently" download and execute an executable ... These are the two browsers I tested with: ...
    (Bugtraq)
  • Re: Trojan Horse
    ... NewCrapNet is not classified as a virus, ... > Download and install Ad-aware SE ... > signature files and install them before performing the scan. ... > Execute; CLEAN.EXE ...
    (microsoft.public.windowsupdate)
  • Re: New Patch Fixes 43 Flaws In OS X, Many Serious
    ... Process *ids* aren't tied to user ids; ... Try it yourself; download a text file ... Evil code, and execute. ... have to hand-install the widgets, ...
    (comp.sys.mac.advocacy)
  • Re: Trojan Horse
    ... Download and install Ad-aware SE ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ... It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML ...
    (microsoft.public.windowsupdate)