PDA

View Full Version : Adclick and poebot.t



Lynda44
11-16-2005, 09:24 PM
Son-in-law reformatted and immediately picked up these two goodies. He can't seem to get rid of them. Any help would be appreciated.

frostyone
11-17-2005, 12:33 AM
"reformatted and immediately picked up these two goodies"

Not surprising,
Most vulnerable after a reformat.
This belongs to a family of worms that exploit Windows vulnerabilities.
When you reformat you are back to step one, no updates, lots of vulnerabilities

Next time have him make sure he has a firewall enabled before connecting to the net,
Have him double check that before connecting to the net.
Then windows update
Then update anti-virus.

He can reformat again. If he's just done so, it's probably the best course.

Alternatively:

Make sure firewall is enabled.

F-secure has a removal tool which may help:

"The F-Bot utility disinfects computers infected with all known by
September 2005 variants of the following backdoors:

Poebot (also known as Backdoor.Win32.Poebot)

The F-Bot utility can also disinfect computers that are infected
with new variants of these backdoors, however disinfection will
only work if these variants are detected generically by AVP
engine.

Here's the link:
http://www.f-secure.com/download-purchase/tools.shtml
Scroll down to F-Bot removal
Choose either the zip or exe version.

Instructions are in the read me here
http://www.f-secure.com/tools/f-bot.txt

First the F-Bot utility will kill all detected backdoors'
processes in memory. Then the utility will remove all Registry
values created by these backdoors and will delete all infected
files from a hard disk.

3. Reboot the system. After restart your system should be clean.:


Then have him run an on-line scan at housecall:
http://housecall.trendmicro.com/