W32/Backdoor.KPI

W32/Backdoor.KPI

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
W32/Backdoor.KPI antioch 05-25-2006
Posted by antioch on May 25, 2006, 9:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>>
>>
>> | I have browsed and found i368 - will it drag and drop into C
>> |
>>
>> Yes. After it is copied, edit the registry...
>>
>> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
>>
>> and change...
>>
>> "SourcePath" from D:\ (or other location) to; c:\
>>
>>
>> --
>> Dave
>
> OK - thats Run/ regedit - which set of HKEY do I want
>> http://www.claymania.com/removal-trojan-adware.html
>> http://www.ik-cs.com/got-a-virus.htm
>>
>>
>
I have reached SET-UP - cannot see source path yet



Posted by antioch on May 25, 2006, 9:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>>
>>>
>>>
>>> | I have browsed and found i368 - will it drag and drop into C
>>> |
>>>
>>> Yes. After it is copied, edit the registry...
>>>
>>> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
>>>
>>> and change...
>>>
>>> "SourcePath" from D:\ (or other location) to; c:\
>>>
>>>
>>> --
>>> Dave
>>
>> OK - thats Run/ regedit - which set of HKEY do I want
>>> http://www.claymania.com/removal-trojan-adware.html
>>> http://www.ik-cs.com/got-a-virus.htm
>>>
>>>
>>
> I have reached SET-UP - cannot see source path yet


Right I am there - ready to change from d\ to c\
Please confirm what you mean by root of c\
>
>



Posted by antioch on May 25, 2006, 9:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>>
>>>
>>>>
>>>>
>>>> | I have browsed and found i368 - will it drag and drop into C
>>>> |
>>>>
>>>> Yes. After it is copied, edit the registry...
>>>>
>>>> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
>>>>
>>>> and change...
>>>>
>>>> "SourcePath" from D:\ (or other location) to; c:\
>>>>
>>>>
>>>> --
>>>> Dave
>>>
>>> OK - thats Run/ regedit - which set of HKEY do I want
>>>> http://www.claymania.com/removal-trojan-adware.html
>>>> http://www.ik-cs.com/got-a-virus.htm
>>>>
>>>>
>>>
>> I have reached SET-UP - cannot see source path yet
>
>
> Right I am there - ready to change from d\ to c\
> Please confirm what you mean by 'root of c\'
>>
>>
I have changed Source data fro d\ to c\
I should come out and the do Run/type in sfc.exe then just let it do its
thing from there on??
Hope you are still there



Posted by antioch on May 25, 2006, 10:25 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>>
>>>
>>>>
>>>>>
>>>>>
>>>>> | I have browsed and found i368 - will it drag and drop into C
>>>>> |
>>>>>
>>>>> Yes. After it is copied, edit the registry...
>>>>>
>>>>> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
>>>>>
>>>>> and change...
>>>>>
>>>>> "SourcePath" from D:\ (or other location) to; c:\
>>>>>
>>>>>
>>>>> --
>>>>> Dave
>>>>
>>>> OK - thats Run/ regedit - which set of HKEY do I want
>>>>> http://www.claymania.com/removal-trojan-adware.html
>>>>> http://www.ik-cs.com/got-a-virus.htm
>>>>>
>>>>>
>>>>
>>> I have reached SET-UP - cannot see source path yet
>>
>>
>> Right I am there - ready to change from d\ to c\
>> Please confirm what you mean by 'root of c\'
>>>
>>>
> I have changed Source data fro d\ to c\
> I should come out and the do Run/type in sfc.exe then just let it do its
> thing from there on??
> Hope you are still there
Well I took the final plunge - altered the registry entry as you said.
Came our and typed in the run sfc.exe - hit OK -there was a flash on the
screen - could not see what it was - booted up and the comp has started
without any apparent problems.
Is there anyway of knowing if I have done what was supposed to have been
done
Thanks for your patience and help through this torrid affair.
Good night - or good morning
Antioch



Posted by Phil Weldon on May 25, 2006, 10:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Antioch wrote, in part:

| >
| >>
| >>>
| >>>>

_____


Ease up on the caffeine B^)

Phil Weldon





The site map in XML format XML site map

Contact Us | Privacy Policy