Trojan, Spybot result, etc

help (please) :slight_smile:

I ran Spybot yesterday and after it updated, immunized , etc etc… I ran it and when it finished I got a strange result from it. Part of it was in german… which i ran thru a translater and found it to mean “can not open”… another part led to the win.ini file… and just before it said “Cabrotor” … which I googled, etc, and found appears to be a backdoor trojan. Now, since our systems are networked here at home, I checked the other one and got the same result.

I did some searching… with google, etc… to find how to get rid of this thing (if it indeed is there) and everything I found doesnt seem to help me (the files and locations they mention arent there??) I used every darned online scanner I could find (most from Rejzor’s site)… ran Hijack This and did the analyzer and found NOTHING in it that was suspicious ???

From what I read about this trojan it is not something I would want to just leave and ignore on here… yet nothing seems to be finding it when I do scans online, etc. One DID come back and tell me Win32.reboot… but then again I cannot seem find where it is… or anything associated with it… registry, or otherwise .

Before I go and just reformatt both of these systems and devote my entire day to this ::slight_smile: has anyone else seen this msg in Spybot??? Or have any other advice for me? I normally have no prob getting rid of bugs… grrr lol

this is the msg Im getting in spybot on both machines:
[b]
Error during check!: Cabrotor (Datei C:\WINDOWS\win.ini kann nicht geöffnet werden. The process cannot access the file because
it is being used by another process) ()

Congratulations!: No immediate threats were found. () [/b]

Note: it says no immediate threats were found… but yet… humm

Have you analyzed the HijackThis log with my analyzer and the online one?

yes, with both

Open win.ini in a text editer, tell me what it say in the line starting with:

run=

nothing…

just " run= "

??? ???

I just ran Spybot again, for the heck of it… and once again it updated…

and this time it only said:

Congratulations!: No immediate threats were found.

::slight_smile:

???

Looks like a problem (fp) with Spybot. If everything is working like it should, I see no reason to worry.

appears so… and I look exactly like the avatar now after staying up half the nite fighting this one LOL

go figure.

I ran into the other room and ran Spybot on the other machine… expecting the prob to be resolved there as well.

Guess what? Now instead of Cabrotor it says Back Orifice…

head hits desk

ok… I had no plans for the day … I think maybe its just time to wipe both machines and start anew.

Have you googled these http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=Win32.reboot
http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=Back%20Orifice there is quite a lot of information.

Perhaps it’s time to look at your backup strategy and purchase some Imaging software, so if things get so screwed up you just restore the last image, time taken 10-15 minutes.

I create a backup image once a week and do a daily backup of data files (word docs, excel, any volatile data), email files, bokmarks and addressbook, etc. After restoring the backup image I then restore the data backup.

I use Drive Image 2002, a bit long in the tooth, but it does the job. There are others, Ghost, etc. the only one I wouldn’t recommend is True Image, my friend had nothing but trouble with it. He couldn’t get it to restore images reliably, in the end he bought Drive Image 7 via ebay and is very happy now.

David… yeah, not a bad idea. I do keep backups of all important things on both pc’s… and burn all programs we use alot to CD so that I do not have to go around downloading everything again. (Avast was definitely one of them :slight_smile: )

Awh well… Ill think of it as winter cleanup… no matter how clean you keep things once in awhile it doesnt hurt to clean it totally. And the nice benefit is it sure is much faster :slight_smile:

Didnt take me that long… will of course need to tweak a few things… This ones done… I think I’ll leave the other til tomorrow… :stuck_out_tongue:

Well er… not totally done lol Im off now to install the printer, cd writer and a few other things I put off…

I just cleaned a system with spybot with the same results… corbarato…or whatever…then backorifice.b… when spybot finishes with error… just click to fix the problems… and it won’t come up again… you will find a checkmark by the error… and it should be fine.