HELP!~How to clear Backdoor.Win32.Gabot.AUS

Discussion in 'malware problems & news' started by glober, Mar 23, 2005.

Thread Status:
Not open for further replies.
  1. glober

    glober Registered Member

    Joined:
    Mar 23, 2005
    Posts:
    1
    "Msgfix.exe",this file will renew after i deleting it under safe mode.And it would create "IUSR_user name" and "IWAM_user name" guest user in my Win2000 system!And other virus files in my system:winsmss.exe; winsmss.exe; wincore.exe; winsys.exe; integitor.exe and so on. They r cannot be removed totally!!!

    Please help me remove it!Thank you!
     
  2. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    See if this helps:- http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.aus.html

    Are you using Norton AV? Have you tried doing a full system scan in safe mode?

    Also check and see if you have Registry changes referred to.

    Also you could try downloading and running Avert Stinger from here:- http://vil.nai.com/vil/stinger/

    Different companies use different names, but I think McAfee calls this W32/Sdbot.worm.gen, in which case the latest version of Stinger should be able to deal with it. Run it in 'Safe' of course.
     
    Last edited: Mar 23, 2005
  3. brown_dog

    brown_dog Registered Member

    Joined:
    Jun 21, 2005
    Posts:
    1
    I'm using MacAfee Super Dat command line scanner.
    Using the command prompt of Bart PE, which I booted from the CD drive,
    and the scanner succesfuly detected and removed the trojan Win32.Gabot.AUS
     
Loading...
Thread Status:
Not open for further replies.