HELP!~How to clear Backdoor.Win32.Gabot.AUS

Discussion in 'malware problems & news' started by glober, Mar 23, 2005.

Thread Status:
Not open for further replies.
  1. glober

    glober Registered Member

    Joined:
    Mar 23, 2005
    Posts:
    1
    "Msgfix.exe",this file will renew after i deleting it under safe mode.And it would create "IUSR_user name" and "IWAM_user name" guest user in my Win2000 system!And other virus files in my system:winsmss.exe; winsmss.exe; wincore.exe; winsys.exe; integitor.exe and so on. They r cannot be removed totally!!!

    Please help me remove it!Thank you!
     
  2. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    See if this helps:- http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.aus.html

    Are you using Norton AV? Have you tried doing a full system scan in safe mode?

    Also check and see if you have Registry changes referred to.

    Also you could try downloading and running Avert Stinger from here:- http://vil.nai.com/vil/stinger/

    Different companies use different names, but I think McAfee calls this W32/Sdbot.worm.gen, in which case the latest version of Stinger should be able to deal with it. Run it in 'Safe' of course.
     
    Last edited: Mar 23, 2005
  3. brown_dog

    brown_dog Registered Member

    Joined:
    Jun 21, 2005
    Posts:
    1
    I'm using MacAfee Super Dat command line scanner.
    Using the command prompt of Bart PE, which I booted from the CD drive,
    and the scanner succesfuly detected and removed the trojan Win32.Gabot.AUS
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.