Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , , ,

Sponsored Links


How to remove BackDoor-ABF virus

Networking & Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 13-03-2010
Member
 
Join Date: Nov 2009
Posts: 592
How to remove BackDoor-ABF virus

Sponsored Links
Hi every, I am get bugged by trying to removing BackDoor-ABF virus from my computer. This malware slowly gaining full control over the system. And restricting to open a numbers of application or taking long time to open programs. My system taking long time to start up shut down. I want to remove this virus as soon as possible. Can any one will provide me a removal solution?

Reply With Quote
  #2  
Old 13-03-2010
Zachary's Avatar
Member
 
Join Date: Jan 2006
Posts: 4,183
Re: How to remove BackDoor-ABF virus

There are some file information:
  • MD5 - EDA1A3BA4AFC806BCE055C69A60C5071
  • SHA - 99CBB7FFC04C874A74CC3C3082B1F4EF37C3D739
There are some aliases
  • AVG - BackDoor.VB.20.C
  • Symantec - W32.SillyDC
  • Kaspersky - Worm.Win32.Basun.wsc
  • Microsoft - Trojan:Win32/VB
Reply With Quote
  #3  
Old 13-03-2010
Milton.J's Avatar
Member
 
Join Date: Apr 2008
Posts: 3,411
Re: How to remove BackDoor-ABF virus

This virus connects to the IP Address “91.211. [Removed].76 via a remote port 8000” and downloads the given files:
  • %USERPROFILE%\Local Settings\Temp\3.tmp [Detected as TDSS.a]
  • %USERPROFILE%\Local Settings\Temp\Nz0.exe
  • %USERPROFILE%\Local Settings\Temp\Nzz.exe
  • %USERPROFILE%\Administrator\RerZNy.bat
  • %USERPROFILE%\Administrator\SpyoYs.exe
  • %WINDOWS%\system32\sshnas21.dll
Reply With Quote
  #4  
Old 13-03-2010
Steve123's Avatar
Member
 
Join Date: Feb 2008
Posts: 2,615
Re: How to remove BackDoor-ABF virus

The given registry keys are inserted to the system:
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\tdl
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSHNAS
  • HKEY_CURRENT_USER\S-1-(Varies)\Software\TOY5KNQ8OC
  • HKEY_CURRENT_USER\S-1-(Varies)\Software\XML
Reply With Quote
  #5  
Old 13-03-2010
Shen's Avatar
Member
 
Join Date: May 2008
Posts: 2,915
Re: How to remove BackDoor-ABF virus

There are some symptoms:
  • occurrence of above given files and registry keys
  • occurrence unexpected network connections to the above given IP Addresses.
How are they infect:
This virus does not self-replicate. They are increase manually, regularly under the principle that the executable is a little beneficial. Distribution channels contain IRC, peer-to-peer networks, newsgroup postings, e-mail, etc.
Reply With Quote
  #6  
Old 13-03-2010
Big Fish's Avatar
Member
 
Join Date: Jan 2006
Posts: 3,742
Re: How to remove BackDoor-ABF virus

You have to use a standard anti virus software program to remove your system virus. There are to many anti virus application are available in the market. You can use Kaspersky anti virus application, this application easily download from its official web site. During installation you have to select standard installation. After installation you have to update anti virus definition. Now scan entire system to remove virus.
__________________
Truly, if there is evil in this world, it lies within the heart of mankind. -Edward D. Morrison

Old soldiers never die- they just fade away.
Reply With Quote
  #7  
Old 04-04-2011
Member
 
Join Date: Apr 2011
Posts: 1
Re: How to remove BackDoor-ABF virus

here is what I did go to safe mode F8and select command prompt
Once system is up and you are at command prompt type regedit
when regedit comes up -go to edit and click find in the space type abf.exe
Everytime it comes up with the afb.exe delete it don't be surprised to find there are up to 20 of these commands
just keep find afb.exe and deleting until the editor tells you there are no more afb.exe commands
Then just restart the computer and run a malwarebytes to clean up the system
Note you can not get to regedit with just safe mode it has to be safe mode command prompt
even if you go to task manager and end the afb.exe command the next double click will start it again you have to start the system at command prompt to bypass the afb cycle.
Reply With Quote
Reply

  TechArena Community > Technology > Networking & Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "How to remove BackDoor-ABF virus"
Thread Thread Starter Forum Replies Last Post
How to remove Trojan Horse Backdoor.Generic13.CBWE virus on my computer Habiba22 Networking & Security 6 10-08-2011 09:31 AM
How to Remove Backdoor.ProRat Virus ME=Akul Networking & Security 4 11-12-2010 05:25 PM
Need help to remove BackDoor.Click.953 virus ? Its_Macy Networking & Security 4 18-03-2010 06:57 AM
How to remove BackDoor.Rebbew (A,B,C,D) virus from my personal computer? CAROLG Networking & Security 5 20-12-2009 03:03 AM
How to remove Backdoor.graybird.exe virus MagicAlonso Networking & Security 3 08-10-2009 06:49 PM


All times are GMT +5.5. The time now is 02:11 AM.