ComputerForum.com ComputerForum.com  
Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Display Modes
Old 08-28-2006, 10:26 PM   #1 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Exclamation Backdoor.HackDefender

ok guys i need ur help. at work one of our servers has a virus, symantec picked it up but fails to clean and quarantine it. The virus name is Backdoor.HackDefender and is located C:\WINNT\system32\syslog.exe

http://www.symantec.com/security_res...328-99&tabid=3

I have tried this alrdy, but there is no registry key where they specify. by the way, im working with windows server 2000.

Someone please help me!
__________________
got pasta?!
daygowop is offline   Reply With Quote


Old 08-29-2006, 03:27 AM   #2 (permalink)
Platinum Member
 
Join Date: Jan 2006
Posts: 567
Default

It is actually a 'Rootkit'. Here are instructions and a removal tool.

F-secure Blacklight http://www.f-secure.com/v-descs/hacdef.shtml
edifier is offline   Reply With Quote
Old 08-29-2006, 03:39 AM   #3 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Default

I will let my boss know about that one. thanks!

anyone else have any suggestions?
__________________
got pasta?!
daygowop is offline   Reply With Quote
Old 08-29-2006, 03:57 AM   #4 (permalink)
Platinum Member
 
Join Date: Jan 2006
Posts: 567
Default

This utility will just disable the Rootkit to allow removal. Norton is not very good at removal so i would use one or both of these free online scanners.

http://support.f-secure.com/enu/home/ols.shtml

http://www.pandasoftware.com/product...ACHEHINT=Guest
edifier is offline   Reply With Quote
Old 08-30-2006, 05:53 AM   #5 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Default

ok thanks i will giv it a go tomorrow. thanks!
__________________
got pasta?!
daygowop is offline   Reply With Quote


Old 08-30-2006, 09:38 PM   #6 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Default

ok, i am confused and my boss is not helping me because he is busy, do u think u can explain what this rootkit stuff is? and maybe help me understand what to do if f-secure finds syslog.exe? because it is telling me to rename it or something?????

obviously u can tell im confused. Please help me!
__________________
got pasta?!
daygowop is offline   Reply With Quote
Old 08-30-2006, 09:53 PM   #7 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Default

ok now i have been reading a lot of articles that tell me to just delete syslog.exe.

http://www.liutilities.com/products/...ibrary/syslog/
http://www.spywaredb.com/remove-dlp/
__________________
got pasta?!

Last edited by daygowop; 08-30-2006 at 09:56 PM.
daygowop is offline   Reply With Quote
Old 08-31-2006, 06:07 AM   #8 (permalink)
banned
 
Join Date: Feb 2005
Posts: 1,486
Default

Quote:
Originally Posted by daygowop View Post
ok now i have been reading a lot of articles that tell me to just delete syslog.exe.
The problem is additional files may exist on the infected system all in the system 32folder, (syslog.exe.) is created because of the virus.

This is a real nasty...To detect it, try the following program: http://www.sysinternals.com/ntw2k/fr...itreveal.shtml

To clean it your best bet would be to connect your disk as a slave drive to another machine and try removing all the files that were found by RootkitRevealer.

Last edited by cell4me; 08-31-2006 at 06:13 AM.
cell4me is offline   Reply With Quote
Old 09-01-2006, 08:43 PM   #9 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Default

ok im gonna giv it a shot a second time, ill let u kno my results. thanks guys!
__________________
got pasta?!
daygowop is offline   Reply With Quote
Old 09-01-2006, 09:59 PM   #10 (permalink)
Silver Member
 
daygowop's Avatar
 
Join Date: Jun 2006
Age: 22
Posts: 202
Default

Well, the syslog.exe is gone and f-secure worked. i must thank you guys one last time for your help and efforts. The server is back-up and running. This is why I love CF!
__________________
got pasta?!
daygowop is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

All times are GMT +1. The time now is 08:45 AM.


Powered by: vBulletin Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 ©2008, Crawlability, Inc.
Copyright © 2002-2008 Computer Forum and Web Design Forum