PDA

View Full Version : Backdoor-guard?? How to remove?



Shell
2008-01-06, 21:45
Can someone please help me understand how to fix this issue?

I have a "Security Center Software Update" that I know is false. Based on research here I realized this was a virus or something that was trying to get me to install adware.

I have dowloaded and swept my computer with Spybot over a week ago. Many files were found that needed to be deleted, which I did.

However, I still have two screens I can not get rid of. One is a black screen that says my liscense is expired and then it bounces to another screen, telling me to call a 1-900 # to get access. I know it's a trap.

I can not get to my desktop, nor can I use cntrl/alt/delete.

Backdoor-guard is the referenced. There is something called Backdoor-guard Removal, but i have to download Spyhunter. All the feedback I have seen on Spyhunter indicates NOT to load it- that it will only add to my problems.

So how do I get rid of these two screens?? This is the URL they are referencing. Please let me know what other information you need.

backdoor-guard <--Security Center Soft

Thank you so much for your help!!!

ken545
2008-01-12, 03:30
Shell,

Welcome, it sound like this trojan has taken over your system. If you can, boot to Safemode with Network Support and download and run this tool.

To Enter Safemode

Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)


Download ComboFix from Here (http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe) or Here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) to your Desktop.

Double click combofix.exe and follow the prompts.
When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall

If you can I need to see a Hijackthis log.

Download
Trendmicros Hijackthis (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe) to your desktop, double click it to install, follow the prompts
and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe





Open HJT Scan and Save a Log File, it will open in Notepad
Go to Format and make sure Wordwrap is Unchecked
Go to Edit> Select All.....Edit > Copy and Paste the new log into this thread by using the
Post Reply and not start a New Thread.

DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or
even required.