|
Posted by Lisa Simpson on October 28, 2006, 6:27 pm
If you were Registered and logged in, you could reply and use other advanced thread options Reporting results so far: finally identified as BKDR_HAXDOOR.JG
- Ewido was useless for this particular nasty
- AVG similarly useless
- SuperAntiSpyware similarly useless
- Avast similarly useless
- Since it was stopping me from getting online I could not do any online
scans, so they are useless in these cases
- TrendMicro is worse than useless since it requires you to "Activate" via
the web (see above)
What seems to have worked was to:
- delete (caution! heavily abbreviated regkeys here!)
HKLM>SW>MS>NT>CV>Winlogon>Notify>yvbb01
- delete (caution! heavily abbreviated regkeys here!)
HKLM>SYS>CurrentControlSet>Control>SafeBoot>Minimal>yvbb02.sys
- delete (caution! heavily abbreviated regkeys here!)
HKLM>SYS>CurrentControlSet>Control>SafeBoot>Network>yvbb02.sys
then:
search for lps.dat & kgctini.dat & delete
>
> | Anybody got a fix for BackDoor.Generic3.LRT?
> |
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to
go through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode.
> This way all the components can be downloaded from each AV vendor's web
site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and
Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files
or you can
> download the files and perform a scan in Normal Mode. Once you have
downloaded the files
> needed for each scanner you want to use, you should reboot the PC into
Safe Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want
to run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal
Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file. http://www.ik-cs.com/multi-av.htm
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
|