Windows Vista Forums

Virus: Backdoor:win32/cybot.b
  1. #1



    Newbie
    Join Date : Nov 2011
    Posts : 1
    Vista Home Pemium x64
    Local Time: 06:28 AM

    Virus: Backdoor:win32/cybot.b

    Windows defender quaratined this virus. Backdoor:Win32/Cycbot.B

    Anyone have a procedure for removing it?? Thanks




      My System SpecsSystem Spec

  2. #2
    richc46's Avatar

    BSOD Squad




    Join Date : Dec 2008
    Fairfield County, CT
    Posts : 19,261
    Windows 7 SP1 x64
    Local Time: 08:28 AM
    usa us connecticut

     

    Re: Virus: Backdoor:win32/cybot.b

    Welcome
    Dont take a chance, dont listen to anyones advice other than our expert. I will summon for her help.
    She will make sure that it is completely removed

    Jacee is off line. She will help asap.

      My System SpecsSystem Spec

  3. #3
    Yard Dog's Avatar

    Senior Member



    Join Date : Oct 2011
    Central Florida in a small town
    Posts : 2,174
    Vista Home Basic. 32 bit SP 2
    Local Time: 08:28 AM
    usa us florida

     

    Re: Virus: Backdoor:win32/cybot.b

    Hello, first thing i would run would be this : How to use Malwarebytes' Anti-Malware to scan and remove malware from your computer
    Post back your results please .

      My System SpecsSystem Spec

  4. #4
    Yard Dog's Avatar

    Senior Member



    Join Date : Oct 2011
    Central Florida in a small town
    Posts : 2,174
    Vista Home Basic. 32 bit SP 2
    Local Time: 08:28 AM
    usa us florida

     

    Re: Virus: Backdoor:win32/cybot.b

    I just checked at Bleeping Computer and this one is not good at all : A security expert there has posted this :
    should also tell you this about this backdoor trojan.

    This allows hackers to remotely control your computer, steal critical system information and download and execute files.

    I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

    Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
    When Should I Format, How Should I Reinstall

    Which that in mind, wait on our expert Jacee and see what she says .

      My System SpecsSystem Spec

  5. #5
    Yard Dog's Avatar

    Senior Member



    Join Date : Oct 2011
    Central Florida in a small town
    Posts : 2,174
    Vista Home Basic. 32 bit SP 2
    Local Time: 08:28 AM
    usa us florida

     

    Re: Virus: Backdoor:win32/cybot.b

      My System SpecsSystem Spec

  6. #6
    richc46's Avatar

    BSOD Squad




    Join Date : Dec 2008
    Fairfield County, CT
    Posts : 19,261
    Windows 7 SP1 x64
    Local Time: 08:28 AM
    usa us connecticut

     

    Re: Virus: Backdoor:win32/cybot.b

    As posted wait for the Security experts. You can have trouble if not done correctly.

      My System SpecsSystem Spec

  7. #7
    Jacee's Avatar

    Security


    Join Date : May 2010
    Posts : 676
    Windows 7 Ultimate Vista Business SP2
    Local Time: 05:28 AM
    usa us washington

     

    Re: Virus: Backdoor:win32/cybot.b

    Hi benakj, first of all, pay special attention to Yard Dog's post. You will need to follow the steps to change all your passwords, using a "clean" computer, not the infected one.

    Next, let's flush the dirty DNS cache, and restore MS's Hosts file:
    Copy and paste these lines in Note pad.

    @Echo on
    pushd\windows\system32\drivers\etc
    attrib -h -s -r hosts
    echo 127.0.0.1 localhost>HOSTS
    attrib +r +h +s hosts
    popd
    ipconfig /release
    ipconfig /renew
    ipconfig /flushdns
    netsh winsock reset all
    netsh int ip reset all
    shutdown -r -t 1
    del %0

    Save as flush.bat to your desktop.
    Vista and Windows 7 users ... right click the .bat file and choose to run as Administrator. Your computer will reboot itself.

    Now, download Malwarebytes' Anti-Malware and "save" to your desktop
    Download Malwarebytes' Anti-Malware 1.51.2.1300 Free - Thoroughly detect and remove even the most advanced malware - Softpedia
    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.

    After doing the above, download Dr.Web CureIT! and "save" it to your desktop.
    Dr.Web CureIt
    alternate download link


    Right click to run as Administrator
    Scan with Dr.Web CureIt as follows:


    Read the anti-virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.




    • The Express scan will automatically begin.
      (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
    • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
    • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)

    • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
    • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
    • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
    • Please be patient as this scan could take a long time to complete.
    • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
    • Click Select All, then choose Cure > Move incurable.
    • In the top menu, click file and choose save report list.
    • Save the DrWeb.csv report to your desktop.
    • Exit Dr.Web Cureit when done.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
    • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

      My System SpecsSystem Spec

Virus: Backdoor:win32/cybot.b problems?

Similar Threads
Thread Thread Starter Forum Replies Last Post
NEED URGENT HELP WITH backdoor:win32/cycbot.b vjay0204 System Security 3 24 May 2011
My computer said it detected backdoor:win32/cycbot.b and said it was removed kiuppo System Security 7 21 Apr 2011
Solved backdoor win32 cycbot.b FCUSA System Security 229 05 Jan 2011
Backdoor:Win32/Zonebac.gen!B Scooter Vista General 2 13 Nov 2007
Backdoor:Win32/Zonebac.gen!B Scooter Vista General 1 13 Nov 2007