home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1904
Discussions: 188,470, Posts: 2,244,183, Members: 232,725
Old April 19th, 2004, 12:54 PM   Digg it!   #1 (permalink)
Junior Member
 
Join Date: Apr 2004
Posts: 4
trojan virus, pls help me

hi

I have got a huge problem, i found out some days age that my norton AV 2003 wasnt working, I could only get it open for about 5 seconds and then it crashed, i used several internet virus scanners and one of them(symantec) found out that i had the Backdoor.OptixPro.13 have on my computer.
This is why my NAV didn't work in the first place. I tried everything to get it off my system, but nothing seems to work...

first of all, these are the files symantec say are infected ,46 in total:

C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011587.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011588.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011623.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011624.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011629.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011725.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0011726.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0012722.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0012723.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013722.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013723.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013731.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013732.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013768.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013769.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013813.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013815.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013823.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0013824.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014823.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014824.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014862.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014863.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014908.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014909.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014945.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014946.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014955.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014956.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014961.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0014962.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015046.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015047.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015081.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015082.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015336.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015337.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015382.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015383.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015442.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015443.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015483.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015484.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015520.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015521.dll is infected with Backdoor.OptixPro.13
C:\System Volume Information\_restore{833E7666-D4EE-4EB3-9B76-66948FABFCE9}\RP78\A0015522.dll is infected with Backdoor.Assasin.Gen

it also said somthing about a thing called BKDR_ASSASIN20.B, but its been so long that i started working on this problem, that I don't even remember what it was or what it did

I followed all the instructions they gave me on the NAV site, and did all of them(I have win XP home edition)

they can be found here

http://securityresponse.symantec.com...tixpro.13.html

as you will see they tell you to edit the registery, i did that but somthing was strange, because the second and third thing I needed to change were already changed

what I mean is:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

where i was suposed to delete the value in default, there was nothing there(or in any of the other keys)

same thing for the third, with the first thing i had to change however, their was a directory of some sort in front of the
"%1" %*

i deleted that, but when I went to normal mode again, my NAV still didnt wor(norton anti virus)

I tried to uninstal it, but that wont work either.

I have been working on this now for 2 whole days, withoud any results, I have followed other more simply ways to remove it, but since my NAV doesnt work, they are useles to me.

I realy hope sombudy can help me, or else i may have to format my pc, and mre then a year of hardwork that is on it will be lost...

thanks

koenVDB is offline   Reply With Quote
Old April 19th, 2004, 01:02 PM     #2 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5
you disabled system restore when you did this correct?


i would download this, and run it. one of the best trojan removers

http://www.moosoft.com/

GroundZero3 is offline   Reply With Quote
Old April 19th, 2004, 01:08 PM     #3 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 10,821
also you can try going here www.antivirus.com and running the free virus scan

also, have u simply tried to restore to before u got the virus??
__________________
"Even a fool is thought to be wise if he is silent"

John Prophet is offline   Reply With Quote
Old April 19th, 2004, 01:11 PM     #4 (permalink)
Free Thinker
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Charleston, Illinois
Posts: 4,198
Thumbs up

Stinger has been working pretty well for me.
__________________
You can't fix stupidity.
M_Six is offline   Reply With Quote
Old April 19th, 2004, 01:38 PM     #5 (permalink)
Fossil
 
Theophylact's Avatar
 
Join Date: Oct 2001
Location: inside the Beltway
Posts: 5,234
Blog Entries: 35
HouseCall (free online scan at Trend Micro) is good too.
Theophylact is offline   Reply With Quote
Old April 19th, 2004, 02:26 PM     #6 (permalink)
Junior Member
 
Join Date: Apr 2004
Posts: 4
wow, thank you all for posting so soon, but I tried all of your ideas, and none worked

1. I didnt get restore up and running, because it was never active, you see I haven'd had this system for to long.
2. i tried the cleaner, i realy hoped it would work, but its the same as with norton, just shuts down after just a litle while
3. the stinger i checked to, but thats only for a certain number of trojans, thats still scanning but I dont expect any results from that.
4.the online scans i tryd eralyer, i did symantec, panda, the one you mentioned, en several others, only symantec gave results, but then i trefered to the explenation on the symantec website, wich didnt work

since the virus is constantly active, it shuts down any atempts to remove it, so I should probably focus on getting it shut down for just a litle while, by editing the registry, but as I said earlyr, that didn't work.

still thanks for your efforts, if you have any new ideas, pls let me know verry soon

thanks all
koenVDB is offline   Reply With Quote
Old April 19th, 2004, 02:29 PM     #7 (permalink)
A hero in training
 
GroundZero3's Avatar
 
Join Date: Oct 2001
Location: Norfolk, VA
Posts: 22,774
Blog Entries: 5
try booting into safe mode and run moo
GroundZero3 is offline   Reply With Quote
Old April 19th, 2004, 02:42 PM     #8 (permalink)
Junior Member
 
Join Date: Apr 2004
Posts: 4
ok, I just tryd that to, no affect, it shuts down after a few secs, like NAV
koenVDB is offline   Reply With Quote
Old April 19th, 2004, 03:25 PM     #9 (permalink)
Junior Member
 
Join Date: Apr 2004
Posts: 4
ok, I have decided I don't have the time nor the skill to fix the problem, since i have a big task due to on wednesday, im gonna format and reinstall XP

thanks all anyway for you help
koenVDB is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Most Active Discussions
Is It Just Me? (3002)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
I think I just killed my computer w.. (26)
Recent Discussions
WD Hard drive reading the wrong.. (1)
P4MAM2-V Mobo Support For Dual .. (1)
can't add picture to this forum (1)
NTVDM CPU has encountered an il.. (8)
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 07:40 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28