This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Backdoor Trojan Help

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried the instructions in the 'Are you infected' topic, but I cannot get on the internet very long until the computer will just crash and restart. (And Internet Explorer works, but Google Chrome just crashes when I try to open it) Alright. I have a netbook. It is a HP Mini110-1012NR. Windows XP SP3. And I had a Norton 360 Premier installed (I don't know the exact specs for all these at the moment…but I could get them if the netbook decides to cooperate). And recently (August 18 was when I first noticed it) Norton says that I had a Backdoor,trojan. At first it quarantined it, but now it says removal failed. It says the two locations affected were winlogon.exe and a browser cache. And I've looked in System 32, but there seems to be no misspelled "infected" filed of winlogon. I have noticed the virus's vicious symptoms though. If I try to connect to the internet, it freaks out and quickly flashes a blue screen and then restarts…so I'm guessing that's the entire deal with the browser cache (I am using Google Chrome) I have not tried to access the internet with another program. The same goes when I'm in safe mode with networking. And with winlogon I've noticed that it won't shut completely down from the menu if I try (only restarts itself) and sometimes it will freeze when I try to type in my password to my account. It also states "Winlogon has encountered a problem and has to close." An option does pop up that says "insert your Windows XP SP3 disk because files have been replaced that require windows to run properly." Which I would, but I don't have an external disk drive (A friend does so I was wondering…just out of curiosity, is it safe to use hers when I have this trojan? I just want to make sure because I don't want her to get this virus or something) My guess is that I got this trojan from a website because I didn't download any "suspicious" files I don't think (I downloaded Chrome, AIM, Skype, Windows Live, Norton…and that's all I believe) …which I'm guessing would explain the effected browser cache? And I had a question…would system restore work? Or would the virus still be intact and I would be left with a computer without Norton or any type of anti-virus program on it? Or is my only option at this point is to take it somewhere to get it fixed (which I don't really want to if I can fix it by myself…and I am completely okay with losing all my files if I have to reinstall windows. I had nothing really valuable on there anyways since I just got it in June—and it was used, but the previous owner had restored it—maybe buying used wasn't the best idea, but…it was better on bank account) Thanks so much.
Hi :welcome:

Backdoor Trojan:

The capabilities of this particular trojan include keylogging and password stealing so I advise you to take all precautions to safeguard your accounts, passwords, and sensitive data. If you have entered any credit card details or use your computer for financial/banking transactions, you should notify your banks and financial institutions that you may have been a victim of identity theft and to put a watch on your accounts. For more information, please read How to report ID theft, fraud, drive-by installs, hijacking and malware. I also recommend that you change your online passwords for email, banks, etc., immediately – from a clean computer. It bears repeating to change passwords from a clean computer only.

Many experts believe that once a computer has been infected with this type of Trojan, it is best to reformat and reinstall the Operating System. The reason is that even after cleaning, there may be some remnants left in the system. It is hard to discern how much damage has been done. Only you can decide whether it would be best to reformat and start over. We can proceed with the cleanup process if you prefer. If you decide to reformat, be sure to save your important data to backup media but make sure that you scan it all before you put it back on a clean system.

Please read the following:
How to Reformat and Reinstall your Operating System
When should I re-format? How should I reinstall?

Also, system restore might or might not work as we don't know the extent of the damage done to your computer and how much security has been compormised.

Please tell me your thoughts on this if you wish to reformat or go with the clean up.
Thank you for replying and I have taken necessary precautions and have changed passwords on a clean computer. And I would be completely okay with going for a reinstall/ reformat. If if just gets rid of this virus, I will be alright with it. This has to be the worst virus I've ever gotten and I have no idea how I got it, so just getting rid of it by means of anything will be alright with me. :)
Hi,

Reformat it is then. This is the better way to be sure that your computer is clean :thumbup:

Other than reading those links I've mentioned above, if you need help in reformatting your computer, our excellent Tech Team would be able to help you.

Please read this: Guidelines: Asking for and Offering Help in our tech forums.

Then create a new topic here.

After you've reformatted and reinstalled you software, here are some recommendations to help keep your computer clean:

To keep your operating system up to date visit
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .

Here are some tips to reduce the potential for spyware infection in the future:

1. It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them

Then consider a password keeper, to keep all your passwords safe.

2. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
3. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. SpywareBlaster - Download and install SpywareBlaster. This program prevents the installation of ActiveX-based spyware and other potentially unwanted programs.

8. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

9. Some excellent free firewalls. Note: Use only one firewall at a time.
Agnitum Outpost Firewall
Online Armor Personal Firewall

10. And finally, please read these excellent articles:
Limited User Accounts
Malware: Help prevent the Infection by Sandi Hardmeier
Preventing Malware - Tools and Practices for Safe Computing

We will keep this thread open for a couple of days. Please post back if you have any problems or questions or when you have finished so this thread can be closed.

Good luck, happy computing and stay clean! ^_^

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI