Spyware file: sqlbkup.exe

  • Thread starter Thread starter Guest
  • Start date Start date
The Anti Virus program finished running and found 21 viruses. It was not able
to remove 7 of them. Those are the following:

Java/Bytverify
Trojan:Java/Classloader
Trojan:Java/Dummy.C
TrojanDownloader:Java/OpenConnection.F
TrojanDownloader:Java/OpenConnection.L
TrojanDownloader:Java/OpenStream.C
TrojanDownloader:Java/OpenStream.H

I'll be able to work on the problem later tonight.
 
Ok, now that I was able to select each individual file that it said could not
be removed, it removed them. So it appears that all 21 are now gone. But our
friend sqlbkup.exe is still there.
 
It is not free but PC-Cillin 2006 will take care of viruses.
Ira
:I think the problem is I don't have any Anti-Virus programs, they're all
: anti-spyware. Where am I able to find an Anti-Virus? Most of the adware is
: gone as far as I can tell (MSAS did an awesome job getting rid of it). I
: found out the other files and deleted them manually (such as the one
causing
: the freeprod). So the only thing I need apparently is the Anti-Virus and
then
: I will get to work on getting rid of this for good.
:
: "Dave M" wrote:
:
: > OK got both your multi-scanner reports now. You have quite a load
there.
: > I'm not sure of what MSAS has detected for you but has been unable to
remove so
: > far. So give it a chance, most of that stuff your seeing is Adware.
: >
: > In order to remove as much as possible I think you should clean your
system,
: > delete prefetch files, and run both your Anti-Virus and Anti-Spyware
scans from
: > Safe Boot mode. You do have an Anti-Virus right?
: >
: > Update your Anti-Virus and Anti-Spyware definitions (MSAS was having
some update
: > problems but it should be settled out soon)
: >
: > Download and install Ccleªner (from Engle)
: > http://www.ccleaner.com/ccdownload.asp
: >
: > Reboot to Safe Mode
: >
: > Please ensure you are doing this under a Administrator accºunt
: >
: > Clear prefetch files by going to Start menu and Run and typing
: >
: > prefetch
: >
: > and then click OK.
: >
: > Open Ccleaner and press "Run Cleaner" from the menu choose 'Issues' and
then
: > press scan for issues, Repair any fºund.
: >
: > Run an Anti-Virus full deep scan
: > Run a MSAS full deep scan repeatedly until nothing is detected on your
system or
: > three full cycles of scanning complete.
: >
: > Reboot back to Normal Mode.
: >
: > Let us know if any problems still exist and what was cleaned by MSAS and
the A-V
: > scans.
: > --
: > Regards, Dave
: >
: >
: > Dave M wrote:
: > > ...geesh, don't click on the post link to w w w freeprod com, sorry
about
: > > posting it that way... it's gonna give you some drive by download
probably
: > > like sephiroth61787 has if you go there.
: > >
: > > Hi sephiroth61787;
: > >
: > > Try running the jotti one also... it could be either very new or
: > > non-malignant, but you did take a malignant download from freeprod it
looks
: > > like. Does MSAS pick anything up? How about your Anti-virus? Do a
full
: > > deep scan with updated definitions on both
: > >
: > > Dave M wrote:
: > >> ...actually I did find freeprod.com finally.
: > >>
: > >> 127.0.0.1 freeprod.com #[IE-SpyAd]
: > >> 127.0.0.1 w w w freeprod com
: > >> http://www.mvps.org/winhelp2002/hosts.txt
: > >>
: > >> You might be interested in the Hosts file from mvps.org that prevents
: > >> downloads from malware sites such as this.
: > >> Blocking Unwanted Parasites with a Hosts File
: > >> http://www.mvps.org/winhelp2002/hosts.htm
: > >>
: > >> sephiroth61787 wrote:
: > >>> Hello all,
: > >>> I just ran the Microsoft AntiSpyware program, but I
still have
: > >>> two forms of spyware apparently. One window keeps coming up as
: > >>> "Freeprod.com" and tries to install itself whenever the computer is
brought
: > >>> up. The other file, sqlbkup.exe, has been on my computer since
Monday and I
: > >>> know for a fact this is a virus of some sort due to it not wanting
to be
: > >>> deleted. Any help would be greatly appreciated!
: >
: >
: >
 
Hi again;
I know you've done this a few times already, but I'm thinking that the cleanup
and virus removal process you've performed may have eliminated whatever is
re-generating sqlbkup.exe. So since it's still running in taskmgr, you need to
re-visit Safe boot once more and try cleaning your prefectch again without that
program running in the background.

It would be real helpful if you had an A-V to run in safe mode like you did with
MSAS. Perhaps we can try it following Bill Sanderson's post. Here's how I'd do
it:

Start > Run > type "msconfig" > OK

In the window that comes up select BOOT.INI tab > check /SAFEBOOT > check
NETWORK > Apply > OK

after you re-boot you should have internet connectivity while in Safe. You can
proceed to the Ms A-V scan site and try a re-scan in Safe mode. If that fails,
I'd get the AVG free A-V with current updates (thanks Frank and all) in order
to run in Safe, it's a good recommendation, and you eventually need a permanent
A-V anyway.

After all is clean go back to looking at the Hosts file from mvps.org. I just
made a post in the General forum in regard to how it works in conjunction with
MSAS. and you might want to look that over. Hosts file can be a bit
confusing... like a double negative almost:

Subject: Re: MVPS HOSTS File Update 28.12.05
Date: Thu, 29 Dec 2005
 
Here's a few links that may help.

Ccleaner to remove temp and unused files from the system:

http://www.ccleaner.com/ccdownload.asp

Install and open then press Run Cleaner,

Ewido Security Suite

http://www.ewido.net/en/download/

When installing, under "Additional Options" uncheck "Install background
guard" and "Install scan via context menu". Click on update in the left menu,
then click the Start update button. After the update finishes close Ewido

Now reboot to Safe Mode - Restart your computer and immediately begin
tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe
Mode option and press Enter.
To return to normal mode just restart your computer as you normally would.

Run Ewido again. From the main menu click on 'scanner' then click 'Complete
System Scan' When ewido finds something, it will pop up a notification.
Select "Remove" and check the boxes "Perform action with all infections" and
"Create encrypted backup" then click on ok.When the scan finishes, click on
"Save Report" and save it to your desktop or c:/drive incase you need it
again and reboot back to normal mode.

If its a AIM virus then download AIMfix

http://www.jayloden.com/AIMFix.exe

Download and run, If it detects any infection reboot and run it a second
time to be sure its removed all traces.

Freeprod Toolbar will enter itself into the add/remove screen (Start menu>
control panel > add/remove programs) and also have a folder in
c:\programfiles which can be removed but Ewido will probably remove them if
any files exist

I noticed you post at BleepingComputer.com about this, Getting your pc clean
will be alot easier after they see your log. With you mentioning SurfSideKick
and TimesSquare.exe (Trojan.Startpage.aw) Hijack This would help show and
remove the problems then run a couple of online Virus scans and get some
strong protection on the pc to prevent further attacks,

OnlineScanners :

http://housecall.antivirus.com/
http://www.trendmicro.com/spyware-scan/
http://www.kaspersky.com/virusscanner
http://www.pandasoftware.com/activescan
http://www.windowsecurity.com/trojanscan/trojanscan.asp
http://www.bitdefender.com/scan8/ie.html


Here's some free Anti-Virus and Firewall programs if needed.

Computer Associates EZ Anti Virus (12 month free trial for Microsoft users)

http://www.my-etrust.com/microsoft/Default.aspx

AVGFree

http://www.grisoft.com/doc/1

Avast4

http://www.avast.com/eng/avast_4_home.html

A-Squared

http://www.emsisoft.com/en/software/free/

AntiVir Personal

http://www.free-av.com/


Firewall :

ZoneAlarm Free

http://www.zonelabs.com/

Agnitum's Outpost Firewall

http://www.agnitum.com/

Sygate Personal Firewall

http://www.sygate.com/


Hope you get things clean soon and all the best for the New Year :)

Regards

Andy
 
Back
Top