Solved backdoor win32 cycbot.b

FCUSA

Member
Has anyone experienced backdoor win32 cycbot.b

I was hit last night. Defender & McAfee both responded (Defender shows it as Quarantineed - successful) - I instructed it to be removed, but am definitely having problems. The best I can tell it is isolated to 1 user. Keeps changing my connection to proxy server.
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB

My Computer

System One

  • Manufacturer/Model
    HP-Pavilion m9280.uk-a
    CPU
    2.30 gigahertz AMD Phenom 9600 Quad-Core
    Motherboard
    ASUSTek Computer INC. NARRA3 3.02
    Memory
    3582 Megabytes Usable Installed Memory (4 Gig)
    Graphics Card(s)
    ASUS NVIDIA Geforce GTS450
    Sound Card
    Realtek High Definition 7.1 Audio (HP drivers)
    Monitor(s) Displays
    HP w2408 24.0" (Dual monitor)
    Screen Resolution
    1920 * 1200, 1920 * 1200
    Hard Drives
    3*500 Gigabytes Usable Hard Drive Capacity
    Plus 2x USB (160Gig each) external HDD
    BluRay & DVD Weiters
    HL-DT-ST BD-RE GGW-H20L SCSI CdRom (Bluray RW) Device
    AlViDrv BDDVDROM SCSI CdRom (Blueray) Device
    TSSTcorp CDDVDW TS-H653N SCSI CdRom
    Internet Speed
    40 Meg
Hi FCUSA,

Here's what someone (the same person who provides the removal instructions that follow) said about this particular infection. It doesn't sound good - but before you take drastic action like re-installing, let's try these options and then get an opinion from Jacee. http://www.bleepingcomputer.com/forums/topic354181.html/page__p__1977393#entry1977393.


I'm not the security expert, so I'll just offer some advice on a removal process that seems to have worked for at least one person (and was posted by someone with MANY posts): how do i remove Backdoor:Win32/Cycbot.B.

Running the second link Lottie suggested may also be beneficial. The first one, however, seems to want you to have a Norton Product and even though most are available as free trials, I recommend staying away from Norton products as I've seen them cause too many problems (and are sometimes hard to fully remove as well even using the special Removal Tool) - but even if you do this (if only the second link or you decide to download Norton despite my strong recommendation against it) I would still do the process I recommended above to be on the safe side. A bit of overkill won't hurt and may have a better chance of resolving the problem.

If that doesn't work, then we'll need to request assistance from Jacee, our security expert and malware removal guru. Post back and let me know how it goes and, if necessary, I'll alert her to the presence of this thread.

I hope this helps.

Good luck!
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
Hey - what a happy day!

I am waiting for my registration to go through at that site. I did actually find that this morning. I have run a full McAfee scan and it did not find anything. I also ran Defender and it quarantined it and then removed it. I had trouble getting IE and also Firefox working, but that has been resolved with setting changes. Then just a moment ago, I received another notice from Defender.

I wonder if this is isolated to the one user? I did go to a different user last night and all seemed to be working alright (that is also how I noticed the internet connection / proxy had changed. I cannot believe this.

I am going to try to find out from there if it is isolated to the one user; also am I actually infected - it sure seemed like the firewall prevented it - just don't know.
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Hi FCUSA,

McAffee and Defender are not going to help with this particular infection (unless they actually blocked it before it could install) - and it is a serious one (not to be taken lightly). You need to start with the procedure I posted and use both of the recommended programs. Then we need to have Jacee take a look even if it seems to have worked (given how serious it is).

Maybe you were protected, but we don't know that for sure - so we should assume you weren't and do the removal procedures and then let Jacee have a look and verify that you really are clean.

Good luck!
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
OK - I have switched users so I can stay on-line. Are you saying run these two suggestions:

OK, I would run these tools. DrWeb CureIt and MBAM.
This can be a long scan.
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Just another thought - these posts are from mid October (I have not received my login verification for this forum yet - so I cannot post) - Defender and McAfee update daily.
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
I understand that you want to believe this isn't a problem and are trying to find reasons to justify that (and that's a pretty good one), but this particular infection is just too dangerous to fool around with. Did you read the first link in my first post about what this can do and how some experts don't even think it can ever be resolved without a clean install and that your financial information and passwords and such may now be in someone's hands? I hope you're right and it didn't get past your defenses and you're not infected and this is a big waste of time - but we really can't take that chance with this infection. So please do the two (long) scans and remove anything they find. If possible, post the results here (a file or a screenshot or whatever) so we can see what they found, what they removed, and what they didn't remove. Then we'll call in Jacee to verify that you really are clean.

Good luck!
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
Oh, no I read it and am freaking. Do you think it is isolated to one user?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Hi,

When the software does it's checks, it will check all files & users. So you should just do the checks! OK?
 

My Computer

System One

  • Manufacturer/Model
    HP-Pavilion m9280.uk-a
    CPU
    2.30 gigahertz AMD Phenom 9600 Quad-Core
    Motherboard
    ASUSTek Computer INC. NARRA3 3.02
    Memory
    3582 Megabytes Usable Installed Memory (4 Gig)
    Graphics Card(s)
    ASUS NVIDIA Geforce GTS450
    Sound Card
    Realtek High Definition 7.1 Audio (HP drivers)
    Monitor(s) Displays
    HP w2408 24.0" (Dual monitor)
    Screen Resolution
    1920 * 1200, 1920 * 1200
    Hard Drives
    3*500 Gigabytes Usable Hard Drive Capacity
    Plus 2x USB (160Gig each) external HDD
    BluRay & DVD Weiters
    HL-DT-ST BD-RE GGW-H20L SCSI CdRom (Bluray RW) Device
    AlViDrv BDDVDROM SCSI CdRom (Blueray) Device
    TSSTcorp CDDVDW TS-H653N SCSI CdRom
    Internet Speed
    40 Meg
thanks - I just printed everything to go over and that was my question - If I needed to be in a specific user or not?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Hi,

Please bear in mind that for protection the software to work it's "best" & "Easiest" magic, you should be in the user with the infection.
 

My Computer

System One

  • Manufacturer/Model
    HP-Pavilion m9280.uk-a
    CPU
    2.30 gigahertz AMD Phenom 9600 Quad-Core
    Motherboard
    ASUSTek Computer INC. NARRA3 3.02
    Memory
    3582 Megabytes Usable Installed Memory (4 Gig)
    Graphics Card(s)
    ASUS NVIDIA Geforce GTS450
    Sound Card
    Realtek High Definition 7.1 Audio (HP drivers)
    Monitor(s) Displays
    HP w2408 24.0" (Dual monitor)
    Screen Resolution
    1920 * 1200, 1920 * 1200
    Hard Drives
    3*500 Gigabytes Usable Hard Drive Capacity
    Plus 2x USB (160Gig each) external HDD
    BluRay & DVD Weiters
    HL-DT-ST BD-RE GGW-H20L SCSI CdRom (Bluray RW) Device
    AlViDrv BDDVDROM SCSI CdRom (Blueray) Device
    TSSTcorp CDDVDW TS-H653N SCSI CdRom
    Internet Speed
    40 Meg
Both programs are run in Safe Mode so you won't be in any particular user account anyway. If you have to reboot into normal mode (it could happen with MBAM but only sometimes), then choose the account with the problems.
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
I don't want to seem like an idiot - but the instructions say to save it to the desktop - will I be prompted for that or does it happen automatically?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
You should be asked if you want to Run or Save or Save As. Choose Save As and then go to the desktop in the selection window and choose that location. It should then save it to the desktop.
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
Thanks - just to better understand - does Defender/McAfee have partitions on the users or is it the computer? And does it matter where I run the scans recommended from? I'm sorry..
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Defender & McAfee run for the entire computer - not individual users (though they check each user). Same for these other two programs. And yes, you should do so in Safe Mode as recommended.
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
Thank you - Ta Ta and wish me luck!
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Good luck! You'll be fine. Just relax and take it one step at a time and it will work out.
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics Card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Logitech HID-compliant Cordless Mouse
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive]

    Dell AIO Printer A940

    Conexant HDA D110 MDC V.92 Modem

    6TO4 Adapter
    Broadcom 440x 10/100 Integrated Controller
    Broadcom 802.11n Network Adapter
    Microsoft ISATAP Adapter
    Teredo Tunneling Pseudo-Interface

    Router Linksys / WRT54G -01
Ok - I really ran into my first snag - there was only an option of RUN or SAVE, when I clicked save it went to a screen that said

"Your download will begin shortly. If it does not, click here to start it manually"

Afraid that it was going to download into 'nowhere' I did click 'Here' but those options didn't sound like your suggestion.
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Back
Top