CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

BDS Backdoor and following mrrockford's advice

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
blo-up-yer-tv

Cadet
Cadet


Joined: Mar 13, 2005
Posts: 6
Location: USA

PostPosted: Sun Mar 13, 2005 7:03 pm    Post subject: BDS Backdoor and following mrrockford's advice
Reply with quote

I started a new thread because I was afraid adding to old thread might be ignored.
On Jan 27, Spike27 posted, titled: AVPE Detected something called BDS Backdoor... to which mrrockford replied with a set of instructions to follow. Since I got a similar bug, I attempted to follow same.
The CCleaner, SpyBot, and HijackThis zip files are refusing to open. If you choose Extract all... (Win XP), the error message indicates corrupt zip file. I can open existing zip files on my computer, but so far no new zip files. Ever hear of a cause for that?

If you can tell me what gives, I'll continue following advice, including placing a Hijackthis log file in proper forum.

Gratis,
Mike


_________________
It's better to know who grew your food.
Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Mon Mar 14, 2005 11:13 am    Post subject:
Reply with quote

Howdy,

Try downloading them again. Which zip software are you using?


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
blo-up-yer-tv

Cadet
Cadet


Joined: Mar 13, 2005
Posts: 6
Location: USA

PostPosted: Thu Mar 17, 2005 2:36 am    Post subject:
Reply with quote

I downloaded Ccleaner again with same results. As for software, I am simply using what's built into Win XP. Double clicking or right clicking and choosing Open produces no response, and right clicking choosing "Extract All..." gets the (XP) Extraction Wizard, which ultimately gets me an error message stating: "The Compressed (zipped) Folder is invalid or corrupted".
Strange, I know. I can't think of any sound reason why this would happen. And I restate: Existing zipped files open, but neither of the 2 new zipped files will.
Question
Thanks Again

Mike

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Thu Mar 17, 2005 11:21 am    Post subject:
Reply with quote

Howdy,

I have put in a request to our experts to help here. Someone should be along shortly. Thanks for your patience.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
Mister2

SRT Team Lead
SRT Team Lead
Premium Member

Joined: Oct 28, 2004
Posts: 7326

Moderators MVP Premium SRT Team F@H

PostPosted: Thu Mar 17, 2005 1:11 pm    Post subject:
Reply with quote

Try downloading HJT from here - http://danborg.org/spy/HJT/hijackthis.exe

This is an unzipped version and should allow you to get your log posted while we figure out what's going on.


_________________
Never stop learning
Back to top
View users profile Send private message
Mister2

SRT Team Lead
SRT Team Lead
Premium Member

Joined: Oct 28, 2004
Posts: 7326

Moderators MVP Premium SRT Team F@H

PostPosted: Thu Mar 17, 2005 1:33 pm    Post subject:
Reply with quote

You could also try the trial version of Stuffit Expander - http://www.digitalriver.com/dr/v2/ec_dynamic.main?SP=1&PN=14&sid=52277


_________________
Never stop learning
Back to top
View users profile Send private message
Robin

Site Admin
Phishing Squad Team Lead

Joined: Oct 15, 2003
Posts: 8946

1st Responder Mentors a-squared Anti-Malware Administrators Forums Admin MIRT Moderators MVP Phishing Squad Security Experts Team CC Committee Team F@H

PostPosted: Thu Mar 17, 2005 3:46 pm    Post subject:
Reply with quote

I was just able to download the files and extract them without issue. Are you trying to open them or save them?

Back to top
View users profile Send private message
blo-up-yer-tv

Cadet
Cadet


Joined: Mar 13, 2005
Posts: 6
Location: USA

PostPosted: Sat Mar 19, 2005 12:57 am    Post subject:
Reply with quote

Answering last question first:
Downloaded & saved the zip files in the normal manner. Once the files are saved on the hard drive, see my previous post for exact method.

Regarding Stuffit: I have downloaded & saved it, can't run it this moment as I'm in the middle of a disc operation. I will post back here with results.

Regarding the Hijackthis.exe unzipped link: Thanks, that worked well. Anybody notice that the unzipped version is 213KB vs. zipped being 208KB? Why zip it?

I will run Hijackthis, and submit the logfile per your instructions on the thread I mentioned in my first posting.

Hope you come up with something as to why my Win XP would suddenly stop unzipping newly downloaded zip files.

Gratis,
Mike

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Sat Mar 19, 2005 5:32 pm    Post subject:
Reply with quote

Howdy,

Try winzip to unzip the files.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
blo-up-yer-tv

Cadet
Cadet


Joined: Mar 13, 2005
Posts: 6
Location: USA

PostPosted: Mon Mar 21, 2005 1:47 pm    Post subject:
Reply with quote

I hate when things act up, with no sound explanation, and then something changes and the problem can't be duplicated!
Since all 3 of the most recent zip file downloads all failed, but earlier downloads seemed fine, I randomly grabbed a zip file from a government website, and it UNZIPPED! So it somehow appeared to only be related to the 3 files, all of which I had linked to from mrrockford's posting.

I installed Stuffit, and immediately tried it on the SpyBot zip file to NO AVAIL. Then I deleted SpyBot zip, and happened to be using MSN Explorer when I downloaded it again (3rd time, mind you). I had been using MS Internet Explorer for all earlier attempts. This time Stuffit opened the zip file! I tried retracing my steps & doing some duplicating and can't do it! I just don't have enough time to get really methodical about it, so I'll cut my losses and run. Confused I have installed all 3 programs.

Consider the zip file problem concluded.

One other problem, and I need your advice on whether I should start a new thread or not, or will an administrator do it?

I have AntiVir PE continually popping up a warning that it found a signature of backdoor program BDS/SkSocket 1.0.8 in Svchost.exe in my Windows\Help directory. I delete the file, but a new one is created. Apparently AntiVir PE can't find what keeps creating the file.

Walk me through?

Gratis,

Mike

Back to top
View users profile Send private message
swatkat

Security Expert


Joined: Mar 04, 2005
Posts: 2039

MVP RootKit Detection Hosts Rootkit Experts Security Experts

PostPosted: Mon Mar 21, 2005 5:37 pm    Post subject:
Reply with quote

Is that infected svchost.exe is in Windows\Help Directory? Try deleting the file in SAFE mode.
Genuine svchost.exe must be in System32 Directory.
Update the AntiVir and do a full System in SAFE Mode, if it gives an alert again then follow below steps.

There is not much information about BDS/SkSocket Trojan, maybe due to the fact that different AV/Security firms refer them by slightly different names.

Download Trojan Remover, WebRoot SpySweeper Trial, CleanUp! and install them.

http://www.simplysup.com/tremover/download.html
http://www.webroot.com/downloads/?WRSID=4955734f12ec7d76df8c979f793cbec7
http://cleanup.stevengould.org/

Then reboot in SAFE mode, and perform a full system scan.
(In SpySweeper, before scanning, click Options Button, and then click Sweep Options, here select all the Hard disk partitions to scan.)
After this run CleanU! and reboot to Normal mode.

Finally perform virus scan at TrendMicro HouseCall and spyware scan at eTrust PestPatrol.
http://housecall.trendmicro.com/
http://store.ca.com/dr/v2/ec_main.entry25?page=freePestPatrolScan&client=ComputerAssociates&sid=35715

Post back the results.

Back to top
View users profile Send private message Visit posters website
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Mon Mar 21, 2005 5:51 pm    Post subject:
Reply with quote

Howdy,

Right now wait to make any changes until you have closed out the HJT thread that you need to start by posting your HJT log in the Hijackthis - Spyware, Viruses, Worms, Trojans Oh My! Forum. Most of what it lists will be harmless or even essential, don't fix anything yet. It is easier to control changes when it all stays in one thread. I will lock this thread now. If problems come up after your HJT thread is finished, please start a new thread and we will go from there.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer