Solved backdoor win32 cycbot.b

Hey Jacee -

Just returned myself. My husband has spent sometime on here today (Lorien probably thinks I'm ignoring him).

Just purchased a new computer, they are setting it up adn we pick up in a couple hours.

Thank you so much for your response. Give me sometime to print out and check over the links (print what I might need).

I have a question - I pulled a password protected Excel file from this computer and deleted the original from the disk. When we get the new computer up, is it safe to view that file from the thumb drive?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
You could have your Anti-virus or Malwarebytes' Anti-Malware scan it before opening it. ;)
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device. One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Mouse
    Microsoft PS/2 Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
One other thing I need to mention, you will need to change all your passwords using the new computer. Don't use the infected one to do that.


Backdoor Trojan Cycbot.B allows unauthorized access and control of an affected computer. An attacker can perform any number of different actions on an affected computer using Backdoor:Win32/Cycbot.B. This could include, but is not limited to, the following actions:


  • Download and execute arbitrary files
  • Upload files
  • Spread to other computers using various methods of propagation
  • Log keystrokes or steal sensitive data
  • Modify system settings
  • Run or terminate applications
  • Delete files
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device. One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Mouse
    Microsoft PS/2 Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Where did the password protected Excel file come from originally?
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device. One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Mouse
    Microsoft PS/2 Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
the infected computer? I now wish I printed some of the info from it before. that is why we purchased the new machine - so we can get in and change everything - but without the file, I can't log into anything.
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
can I put it back into the infected computer to print it? (so based on what you just said, sounds like I ruined the stick drive?

Oivay
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
OK - I am getting things ready and I made my first blunder! I did the copy & past, saved to desktop. I clicked to open, not realizing it was going to run. so it ran and rebooted, but I did not run as Administrator - should I just do that again when I am ready to proceed with all the instructions?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Yes, just do it again.
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Mouse
    Logitech HID-compliant Cordless Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive] Dell AIO Printer A940 Conexant HDA D110 MDC V.92 Modem 6TO4 Adapter Broadcom 440x 10/100 Integrated Controller Broadcom 802.11n Network Adapter Microsoft ISATAP Adapter Teredo Tunneling Pseudo-Interface Router Linksys / WRT54G -01
I now wish I printed some of the info from it before. that is why we purchased the new machine - so we can get in and change everything - but without the file, I can't log into anything.
Well you lost me here ... you can't get into what without what file?

You can't log into the infected computer?
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device. One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Mouse
    Microsoft PS/2 Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Sorry that was not clear. No, there is no problem getting into the infected computer.

The password protected file (sensitive info) was on the infected computer. Then I saved it to a stick drive so I could remove the original file from the infected computer.

I saw that you were offline last night, so I just proceeded to put the stick drive back in the infected computer so I could print my password protected file (for reference). I have isolated that stick drive as I am not sure it can be used again.

I am working on changing all the passwords (& getting e-mail up) in the NEW computer so I can continue to work while we (hopefully, praying) correct the infected computer. New pc not going as smoothly as I hoped - it is Windows 7 and I do not have the same software on it.

The new computer has Trend Micro Titanium installed. Is this satisfactory for now or do you suggest an additional or another Portection Software? (I want this baby locked down like Maid Marion in 'Men with Tights'!)
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
BTW Jacee - I don't want you to think I am not working on correcting the issue, it has simply taken a slight back burner so I can get the new computer up & running and accounts changed. I will get the results to you asap. I very much appreciate your expertise (and all the support & input I have received from this forum).

Thanks again - and on a personal note, have you been spared the wrath of all the storms?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Hi FCUSA,

Here's my recommendation:

Here's how to properly uninstall Trend Micro: Frequently asked questions (FAQs) about uninstalling Trend Micro products.

Then download and install the free Microsoft Security Essentials: http://www.microsoft.com/security_essentials/. Set it to run in real time. Set it to automatically update through Windows Updates (and update it youself right after installation to make certain it is up-to-date without waiting for an update to appear). I recommend you schedule it to run a quick scan weekly and manually do a full scan monthly.

Next, download, install, and update the free Malwarebytes http://www.malwarebytes.org/mbam.php and run it every two or three weeks (updating first to make sure it is current).

Confirm that the Windows Firewall is enabled and running. Go to the exceptions tab and remove any feature that you don't use as each exception is a way into your computer. Don't go overboard or you may not be able to use the internet or access certain sites or download certain files - but if you never intend to use Ping, for example, then uncheck the box since it isn't necessary. If in doubt, either ask or leave it alone. A little bit of excess won't hurt.

That should take care of you - and is what many here recommend.

I hope this helps.

Good luck!
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Mouse
    Logitech HID-compliant Cordless Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive] Dell AIO Printer A940 Conexant HDA D110 MDC V.92 Modem 6TO4 Adapter Broadcom 440x 10/100 Integrated Controller Broadcom 802.11n Network Adapter Microsoft ISATAP Adapter Teredo Tunneling Pseudo-Interface Router Linksys / WRT54G -01
I knew (while at the store) I should have asked this question here first! I was intuitive enough to ask the Tech if it was easy to uninstall - of course he said 'yes', I hope he was right. Well, I think I have all the basics taken care of here and will work on this. I did find Windows Firewall and took care of that.

Thank you for that recommendation.

I actually don't know what 'ping' is?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Hi FCUSA,

It's easy to uninstall, but a bit harder to do it the right way so you have no troubles later. Follow the guidelines I gave you and you'll do fine. A simple, normal "uninstall" through Programs and Features in Control Panel sometimes isn't enough - it even says so on their website and suggests the program and procedure I provided you.

If you have trouble with those procedures, then download Revo Revo Uninstaller Pro - Uninstall Software, Remove Programs easily (if your new computer is 32-bit, use the freeware version; if it is 64-bit, download the pro version with a 30-day free trial and cancel it during the trial period). Run it in Advanced Mode. When given the option to uninstall items that weren't uninstalled by the normal uninstall program (which it runs first), be careful that the items are all related to the program you are uninstalling (sometimes - not often, but sometimes - it suggests options that don't apply and should not be removed). It should be fairly easy to tell - it will have the name in it or be in a folder where everything is related to that program. If in doubt, leave it as that's safer than deleting the wrong thing. It's not as perfect a solution as the actual removal program but if that's difficult (I've never tried to uninstall Trend before) then this should be a lot easier and will most likely work just as well if you get most of the extra stuff.

If you have a 32-bit system. Then keep Revo as it will come in handy again. I personally do not ever use the Vista uninstall program at all and only use Revo to remove programs I no longer want/need - it simply does a much better job. That decision is up to you but I will say that, unlike me, most people use Revo only when necessary (mostly I think out of habit and because it's easier - though in my opinion not sufficiently thorough).

Ping is a process where you can check your network connectivity (and that of the site you're also testing) by connecting to a known website (not using a browser) to just send a signal and confirm it was received (it usually does so three times to verify you can connect). The point here is that if you don't know what it is, you aren't using it and it isn't necessary for what you do, so you can uncheck that checkmark in the firewall exceptions.

Good luck with your new baby. Remember that all your current programs may not be compatible with Windows 7. Most will be fine. Some will work anyway in Compatibility Mode. Some may not even install let alone work. This is especially true if your current system is 32-bit and the new one is 64-bit. You can check them at the Windows 7 Compatibility Center: Windows 7 Compatibility: Software Programs & Hardware Devices: Find Updates, Drivers, & Downloads.

I hope this helps.

Good luck!
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Mouse
    Logitech HID-compliant Cordless Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive] Dell AIO Printer A940 Conexant HDA D110 MDC V.92 Modem 6TO4 Adapter Broadcom 440x 10/100 Integrated Controller Broadcom 802.11n Network Adapter Microsoft ISATAP Adapter Teredo Tunneling Pseudo-Interface Router Linksys / WRT54G -01
Yes, we (I) not so thrilled about a different system (considering I don't know the Vista so well). Do you really trust me all this - I just accidentally locked myself out of this forum - don't laught too hard!!
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
You'll do fine. From what I hear, W7 and Vista aren't all that much different. Yes, there are differences and some things are located in different places, but if you can manage with Vista, you'll be fine with Windows 7 in time (and be able to do most of what you need to do immediately).

Trust yourself. You did fine through all of this (and the other problems) and are better at it than you give yourself credit for.

I do NOT want to know how you locked yourself out of VF. LMAO!!!
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Mouse
    Logitech HID-compliant Cordless Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive] Dell AIO Printer A940 Conexant HDA D110 MDC V.92 Modem 6TO4 Adapter Broadcom 440x 10/100 Integrated Controller Broadcom 802.11n Network Adapter Microsoft ISATAP Adapter Teredo Tunneling Pseudo-Interface Router Linksys / WRT54G -01
Lorien - You, as always, raise an important question. The infected computer is Vista 64 and I have wonderful paperwork that tells me about the system.

We received nothing with it and since it is Windows 7 (I know I am in the wrong forum) - is there a way for me to pull the system information?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Try going to Start / Computer / System Properties and seeing what it tells you. That's how it would work in Vista and I hope it's the same in Windows 7.
 

My Computer

System One

  • Manufacturer/Model
    Dell Inc. MP061 Inspiron E1705
    CPU
    2.00 gigahertz Intel Core 2 Duo 64 kilobyte primary memory
    Motherboard
    Board: Dell Inc. 0YD479 Bus Clock: 166 megahertz
    Memory
    2046 Megabytes Usable Installed Memory
    Graphics card(s)
    ATI Mobility Radeon X1400 (Microsoft Corporation - WDDM) [Di
    Sound Card
    SigmaTel High Definition Audio CODEC
    Monitor(s) Displays
    Generic PnP Monitor (17.2"vis)
    Screen Resolution
    1920 x 1200 pixels
    Hard Drives
    Hitachi HTS541616J9SA00 [Hard drive] (160.04 GB) -- drive 0, s/n SB2411SJGLLRMB, rev SB4OC74P, SMART Status: Healthy
    Case
    Chassis Serial Number: 5YK95C1
    Mouse
    Logitech HID-compliant Cordless Mouse
    Keyboard
    Standard PS/2 Keyboard
    Internet Speed
    1958 Kbps download ; 754.8 Kbps upload
    Other Info
    Optiarc DVD+-RW AD-5540A ATA Device [CD-ROM drive] Dell AIO Printer A940 Conexant HDA D110 MDC V.92 Modem 6TO4 Adapter Broadcom 440x 10/100 Integrated Controller Broadcom 802.11n Network Adapter Microsoft ISATAP Adapter Teredo Tunneling Pseudo-Interface Router Linksys / WRT54G -01
Firewall is set to notify me and also to block all programs except those on the approved list. I guess I will be prompted and just add them as I go?
 

My Computer

System One

  • Manufacturer/Model
    Dell Studio XPS 1640
    CPU
    Intel Core 2 Duo P8600 (2.4GHz/1066Mhz FSB/3M L2 Cache)
    Memory
    4GB
Back
Top