Please help me with Backdoor.Beasty.Family

Discussion in 'malware problems & news' started by Dan1975, Feb 9, 2005.

Thread Status:
Not open for further replies.
  1. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,491
    Location:
    Netherlands
    Can you post the contents of:
    C:\Documents and Settings\AaronK\Local Settings\Temp\sOutTmp154230.tmp

    None of the upx file immediately jumps out as suspect. Can you remember if you downloaded and ran something with a P2P program immediately before this started happening?
    If you have a suspect, I'd very much like a copy sent to the address in my profile.

    Regards,

    Pieter
     
  2. TrojanHelp55

    TrojanHelp55 Registered Member

    Joined:
    Feb 17, 2005
    Posts:
    2
    When trying to open the temp file, it asked me what program to use, and I selected Notepad. The file, it seems, was created by the Registry scanner. Here are the contents of it in wordpad:


    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "c:/windows/system32/mslg.blf" 2/16/2005 3:43:25 PM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)



    Also, I sent you an email with two files attached. I did in fact download two programs from LimeWire the same day that I noticed trouble with the virus.

    Thanks
    -- Aaron
     
  3. TrojanHelp55

    TrojanHelp55 Registered Member

    Joined:
    Feb 17, 2005
    Posts:
    2
    Thank you very much for all the help and the continouous effort.
    The virus is finlly gone !!
    Right before deciding to reformat my drive, I just on a whim thought that I would uninstall Norton and install McAfee instead.
    Like magic, McAfee found the infected files right away and deleted them from the system.
    Now everything works like normal.

    All the best to those who encounter this annoying and time-consuming nuisance,
    -- Aaron
     
  4. zorgunfleck

    zorgunfleck Registered Member

    Joined:
    Nov 5, 2005
    Posts:
    1
    Hello,
    I was hoping someone could help me, I have the same problem discussed here. I'm just a little unclear as to what it was that finally cleared the virus up. If someone could let me know what steps to do to get rid of it, I would be increadibly greatful.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.