Emergency Help Needed!
Viruses got you down? Spyware making your system sluggish? Post here for support on all your security needs.

Moderators: Management, Forum Experts

Postby Yappinator on Fri Jan 10, 2003 2:54 pm

ok guys
Backdoor.OptixPro.11

is what our poor Rip has



[url]http://securityresponse.symantec.com/avcenter/venc/data/backdoor.optixpro.11.html
[/url]

he needs to get the computer back upto B4 I Sent him to that site
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 10:12 pm
Location: On. Canada

Postby Yappinator on Fri Jan 10, 2003 4:07 pm

BUMP
help guys
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 10:12 pm
Location: On. Canada

Postby SCgone on Fri Jan 10, 2003 4:22 pm

Have you checked to see if it will do a repair install. I've done 4 or 5 of those without a hitch. If the repair install works, then you won't lose any settings. You'll need to boot to the CD though.
SCgone
PRO ELITE
PRO ELITE
 
Posts: 12847
Joined: Thu Mar 14, 2002 6:59 pm
Location: South Carolina, USA

Postby Yappinator on Fri Jan 10, 2003 4:25 pm

TX bell

Me mind was disgomvobulated :blink
To err is human, to really foul things up requires a computer.
Failure is not an option. It comes bundled with the software
Quoting one is plagiarism; Quoting many is research
Frogs have it easy; they can eat what bugs them..

Image
User avatar
Yappinator
Banned
 
Posts: 849
Joined: Thu Jul 04, 2002 10:12 pm
Location: On. Canada

Postby RIP! on Fri Jan 10, 2003 7:28 pm

CD isn't bootable. :(
~One Liner!~
RIP!
PRO Level 15
PRO Level 15
 
Posts: 1009
Joined: Fri Jul 26, 2002 12:35 pm
Location: Va

Postby *Starz* on Fri Jan 10, 2003 8:10 pm

I'm asking everyone for help right now in behalf of RIP, I have him on MSN right now...he has finally managed to get into his registry...and is looking for the problem...is anyone able to be of assistance...if so please pm me and I will invite you into the conversation...He's in serious need of help with this one...he has his business files in there and can't afford to loose them...

Thanks in Advance
[align=center]Image

~ You Are Never Given A Wish Without Being Given The Power To Make It Come True ~[/align]
User avatar
*Starz*
PRO PLATINUM
PRO PLATINUM
 
Posts: 6527
Joined: Fri Aug 16, 2002 8:05 pm
Location: Great Smoky Mountains

Postby Stan on Fri Jan 10, 2003 8:34 pm

Rip...I found this

Delete the Winstart.bat file
Most variants of Backdoor.Optix will create a batch file named Winstart.bat in the %Windows% folder. Winstart.bat is a standard Windows file that can be created and used by programs when you install software. If the Winstart.bat file exists, it will run when you start Windows, and any commands in it will be executed. by default this is C:\Windows or C:\Winnt) and copies itself to that location.
Backdoor.Optix keeps a second copy of itself on the hard drive. if you delete the Trojan from its original location, when Winstart.bat is run, it will recreate the Trojan file.
Therefore, if Backdoor.Optix is found on the computer, use Windows Explorer to locate and delete the \Windows\Winstart.bat file before you restart the computer.
To do this:
1. Start Windows Explorer.
2. Browse to the folder where Windows is installed. By default this is C:\Windows or C:\Winnt.
3. Locate and delete the Winstart.bat file.
also check this out:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Troj/Optix will also copy the Trojan to the Startup group in the Start Menu.
here's how it works:
When first run, the Trojan creates the sub-directory \OleFiles\, moves itself there and creates the following registry entry :
HKLM\Software\Microsoft\Windows\
CurrentVersion\explorer\User Shell Folders\ Common Startup = \OleFiles\.

This ensures that the server process is run automatically each time the machine is restarted.
so delete the value in that key: eg;\OLEFILES\delete the trojan value
hope this helps, all the best
Image
User avatar
Stan
PRO Level 2
PRO Level 2
 
Posts: 45
Joined: Tue Oct 15, 2002 7:25 pm
Location: Clearwater, Florida

Postby *Starz* on Fri Jan 10, 2003 8:41 pm

Thanks Stan

He's at the site now reading your post... :peanutbutta
[align=center]Image

~ You Are Never Given A Wish Without Being Given The Power To Make It Come True ~[/align]
User avatar
*Starz*
PRO PLATINUM
PRO PLATINUM
 
Posts: 6527
Joined: Fri Aug 16, 2002 8:05 pm
Location: Great Smoky Mountains

Postby Xstream on Fri Jan 10, 2003 8:50 pm

this doesnt help rip, but it is a good lesson. either have a second hard drive, or a second partition on your drive that is only for non-installed files such as regular data, photos, music, etc. then if you have to do a reinstall, you can still get to the other drive/partition after you get back up, without losing it.
Rip, I've pm'ed my meager attempt at help to stars. good luck!
User avatar
Xstream
PROfessional Member
 
Posts: 7563
Joined: Thu Mar 14, 2002 9:30 pm
Location: USA

Postby *Starz* on Fri Jan 10, 2003 8:59 pm

Update...

None of the files mentioned in Stan's post were showing up on his system. X...I sent him a copy of your PM...he's doing another scan right now...still looking for assistance...if anyone can help with more ideas...it would be most appreciated...
[align=center]Image

~ You Are Never Given A Wish Without Being Given The Power To Make It Come True ~[/align]
User avatar
*Starz*
PRO PLATINUM
PRO PLATINUM
 
Posts: 6527
Joined: Fri Aug 16, 2002 8:05 pm
Location: Great Smoky Mountains

PreviousNext

Return to Security & Virus

Who is online

Users browsing this forum: No registered users and 0 guests