Virus - backdoor.prorat|?

P

'puter fixer

I am trying to remove A? virus from a friend's computer. Norton Antivirus
indicates the following:
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.

Running WinXP
System restore off
Can access internet

security.symantec.com says 2 files
wininv.dll
winkey.dll

Can't delete files in safe mode
Can delete files in safe mode command line
Change registry keys as requested
Files return

Norton will not perform a liveupdate
Windows update won't run
Can't install AVG Antivirus
Can't run FPROT
Can't update Adaware
Can't update Spybot Search and Destroy

Please help....
 
P

'puter fixer

Cable is unplugged.
Restore is disabled.
Cannot open Norton Antivirus/System Works even in safe mode (cannot even
right click on C drive and select scan using Norton ... nothing happens)
Uninstalled and reinstalled. still Doesn't work except error message
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.
which when starts ... can't stop.

Deleted files and registry items. Even shows back up in "Safe Mode"

Cannot run FProt
Cannot install other antivirus software (ie AVG)
Installed Zone Alarm - it shut down
Cannot do windows updates
Cannot update Adaware or Spybot (did get downloads separately and installed
and ran but still problems)

Any other suggestions? :)
 
S

sunshine

'puter fixer said:
I am trying to remove A? virus from a friend's computer. Norton Antivirus
indicates the following:
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.

Running WinXP
System restore off
Can access internet

security.symantec.com says 2 files
wininv.dll
winkey.dll

Can't delete files in safe mode
Can delete files in safe mode command line
Change registry keys as requested
Files return

This is because your computer is hacked into and the malicious hackers
control your computer.
You have to secure your Windows Platform, e-mail and web browser
applications and then install a firewall before putting your computer
on the Internet or you will never be safe from hackers who use your
computers to trade/sell guns, bo*bs, prosititues, drugs and so on. So
when the FBI comes knocking on your door for being a criminal then
don't cry to me.

Tracker
snailmail(valid)[email protected]
 
P

'puter fixer

It isn't my computer. I fix computers for the low to middle class "families"
for a very nominal fee.

I'm trying to do just that. I have never encountered a
"virus/trojan/backdoor/worm" that I couldn't clean. I am here asking for
help on how to fix this one.

After making sure a computer is "clean", I install AVG and ZoneAlarm and put
a clean up folder on the desktop with full instructions on how to keep a
computer safe.

I would appreciate help with "how to clean" the machine........
 
D

Dale Simmons

'puter fixer said:
It isn't my computer. I fix computers for the low to middle class "families"
for a very nominal fee.

I'm trying to do just that. I have never encountered a
"virus/trojan/backdoor/worm" that I couldn't clean. I am here asking for
help on how to fix this one.

After making sure a computer is "clean", I install AVG and ZoneAlarm and put
a clean up folder on the desktop with full instructions on how to keep a
computer safe.

I would appreciate help with "how to clean" the machine........

Well.... don't take the hysterically-moronic advise of tweaker-babe,
tracker.... That will save you some time
 
K

kurt wismer

'puter fixer said:
Cable is unplugged.
Restore is disabled.
Cannot open Norton Antivirus/System Works even in safe mode (cannot even
right click on C drive and select scan using Norton ... nothing happens)
Uninstalled and reinstalled. still Doesn't work except error message
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.
which when starts ... can't stop.

Deleted files and registry items. Even shows back up in "Safe Mode"

Cannot run FProt
Cannot install other antivirus software (ie AVG)
Installed Zone Alarm - it shut down
Cannot do windows updates
Cannot update Adaware or Spybot (did get downloads separately and installed
and ran but still problems)

Any other suggestions? :)

wininv.dll is being run/hosted by some other process (dlls can't
generally run by themselves)... try getting process explorer from
http://www.sysinternals.com and click on view dlls and then do a search
for that dll to see which process is using it...
 
T

Tom R

'puter fixer said:
I am trying to remove A? virus from a friend's computer. Norton Antivirus
indicates the following:
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.

Running WinXP
System restore off
Can access internet

security.symantec.com says 2 files
wininv.dll
winkey.dll

Can't delete files in safe mode
Can delete files in safe mode command line
Change registry keys as requested
Files return

Norton will not perform a liveupdate
Windows update won't run
Can't install AVG Antivirus
Can't run FPROT
Can't update Adaware
Can't update Spybot Search and Destroy

Please help....


I would run at least one of these
free online virus scan programs,

RAV
http://www.ravantivirus.com/scan/

Panda:
http://www.pandasoftware.com/activescan/

BitDefender
http://www.bitdefender.com/scan/license.php

HTH,
Tom
 
J

Jason Wade

It isn't my computer. I fix computers for the low to middle class "families"
for a very nominal fee.

I'm trying to do just that. I have never encountered a
"virus/trojan/backdoor/worm" that I couldn't clean. I am here asking for
help on how to fix this one.

After making sure a computer is "clean", I install AVG and ZoneAlarm and put
a clean up folder on the desktop with full instructions on how to keep a
computer safe.

I would appreciate help with "how to clean" the machine........

Google search: description of prorat trojan

http://www.sophos.com/virusinfo/analyses/trojproratd.html
http://www.sarc.com/avcenter/venc/data/backdoor.prorat.html

I think that prorat is one of the almost-impossible-to-remove
+punishment-for-removal-attempts trojans.

I would backup and reinstall myself.
 
R

Romper

was said before :
I am trying to remove A? virus from a friend's computer. Norton Antivirus
indicates the following:
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.

Running WinXP
System restore off
Can access internet

security.symantec.com says 2 files
wininv.dll
winkey.dll

Can't delete files in safe mode
Can delete files in safe mode command line
Change registry keys as requested
Files return

Norton will not perform a liveupdate
Windows update won't run
Can't install AVG Antivirus
Can't run FPROT
Can't update Adaware
Can't update Spybot Search and Destroy

Please help....
Unplug the cable and use a boot disk, if that doesnt work put the
harddrive into another computer, a friends etc set it up as a slave
and then delete the files from there :) hope that helps


Outa here.... got a muppet to save
 
D

d_dave

'puter fixer said:
I am trying to remove A? virus from a friend's computer. Norton Antivirus
indicates the following:
Object Name: C:\Windows\System32\wininv.dll
Virus Name: Backdoor.Prorat
Action Taken: Unable to repair this file.

Running WinXP
System restore off
Can access internet

security.symantec.com says 2 files
wininv.dll
winkey.dll

Can't delete files in safe mode
Can delete files in safe mode command line
Change registry keys as requested
Files return

Norton will not perform a liveupdate
Windows update won't run
Can't install AVG Antivirus
Can't run FPROT
Can't update Adaware
Can't update Spybot Search and Destroy

Please help....


you need to download ProRat server and use that to dis-infect your
machine.
 
G

Gabriele Neukam

On that special day, , ([email protected]) said...
you need to download ProRat server and use that to dis-infect your
machine.

Err, you meant to say "client", didn't you? The server is usually
*planted* on hijacked machines.


Gabriele Neukam

(e-mail address removed)
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

backdoor.prorat 2
Pls help - unknown virus problem 4
Virus and Registry help 3
Backdoor.proratD trjan and registry 1
strange virus 8
Is it virus or spyware? 2
@ Help with w32.spybot.worm 1
bad virus 106

Top