Jump to content

Word won't start after deleting Backdoor.bot


Recommended Posts

I'm new, with something similar to the original question on this thread.

Had a problem with bolivar23. Got malwarebytes updated and seemed to fix, scans were clean on MWB and Symantec Endpoint Protection (which I've always used anyway).

Now MWB is sometimes (not always) detecting Backdoor.bot only on my winword.exe file.

MWB "takes no action". Of course, when I manually delete that file, Word won't start :blink:

So is this also an FP? At the moment, I have no "symptoms", just nervous that my original problem is not cleaned out properly, and by some of the comments about Backdoor.bot.

Here's my last MWB scan (a quick one but same results on full scan).

thanks for any help.

Malwarebytes' Anti-Malware 1.30

Database version: 1390

Windows 5.1.2600 Service Pack 3

13/11/2008 11:45:24

mbam-log-2008-11-13 (11-45-22).txt

Scan type: Quick Scan

Objects scanned: 43380

Time elapsed: 2 minute(s), 42 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Program Files\Microsoft Office\WINWORD.EXE (Backdoor.Bot) -> No action taken.

Link to post
Share on other sites

Most strange.. Please use the /developer switch and post a fresh log. We'll try to get this cleared up for ya.

Here you go, attached from /developer.

A quick scan & a full scan - same result on /Microsoft Office/winword.exe

Let me know if this should actually be in the FP thread.

Thanks and I appreciate the investigation help.

mbam_log_2008_11_14__09_48_40_.txt

mbam_log_2008_11_14__10_32_45_.txt

mbam_log_2008_11_14__09_48_40_.txt

mbam_log_2008_11_14__10_32_45_.txt

Link to post
Share on other sites

  • 6 months later...

I also have backdoor.bot detected in Windord.exe (Word 97). virustotal.com says that 41 virus checkers have given the file the all clear.

Tim

Any news on this?

I am assuming it is an FP.....no symptoms for a week now since telling MWB to ignore the allegedly infected winword.exe file, but confirmation would be appreciated.

Thanks!

Link to post
Share on other sites

I also have backdoor.bot detected in Windord.exe (Word 97). virustotal.com says that 41 virus checkers have given the file the all clear.

Tim

I got this today as well. Could it be a FP?

Files Infected:

C:\Program Files\Microsoft Office\WINWORD.EXE (Backdoor.Bot) -> Quarantined and deleted successfully

Link to post
Share on other sites

  • Staff
I have a copy of the original log.....is that what is needed? I know if I do a new scan now it will show nothing. Does the procedure above do something else than a new scan?

TIA

I've been alerted by the team that this should be fixed in the next update. Check for updates in a little while.
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.