W32/Backdoor.KPI

W32/Backdoor.KPI

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
W32/Backdoor.KPI antioch 05-25-2006
Posted by David H. Lipman on May 26, 2006, 6:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

|
>>
|>> Hello David
|>> The computer started up OK in the morning but on reading through your
>> advice
|>> again, but a couple of times it would not shut down. I did wonder if I
>> had
|>> done the very last bit correctly.
|>> I have been doing scans etc all day as per your past recommendations and
|>> that of others.
|>> Nothing found apart from a couple of open ports which Symantec always
>> finds.
|>> It took some minutes to download all the bits in that i386 folder, yet
>> when
|>> I hit OK after inserting in Run sfc.exe, there was a flash on the
>> desktop
|>> and that was it. Does that seem right. Should I have put something
|>> different into Run.
|>> Also, I was not too sure what you meant by '....to the 'root' of the C
|>> drive.
|>> Rgds
|>> Antioch
|>>
>> The "root" of the "C:" drive is the lowest part. The root. The base.
>> The moniker; c:\
>> means the root of C:.
>>
>> Like I said, the command is; SFC /scannow and is best entered in a
>> command prompt but
>> doesn't have to be.
>>
>> As the switch /scannow infers, it will cause teh OS to "scan" the systems
>> to make sure EXE
>> and DLL files are the right version.
>>
>> --
>> Dave
>> http://www.claymania.com/removal-trojan-adware.html
>> http://www.ik-cs.com/got-a-virus.htm
>>
| Then I did it wrong and there has been no scan etc.
| So just dragging and drop of the i386 folder into the C drive, as opened via
| My Computer/Local C along with the folders for Progs, Windows etc.
| So I better do a proper entry in run. Is that a space bet SFC & /scannow.
| Sorry to keep asking.
| Antioch
|

The full command line...

sfc /scannow

Copy and paste the above.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by antioch on May 26, 2006, 6:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
That's a bit different - it wants my XP Pro Service Pack 2 CD to be
inserted. I only have Home. Is that OK.
Antioch



>
> |
>>>
> |>> Hello David
> |>> The computer started up OK in the morning but on reading through your
>>> advice
> |>> again, but a couple of times it would not shut down. I did wonder if
> I
>>> had
> |>> done the very last bit correctly.
> |>> I have been doing scans etc all day as per your past recommendations
> and
> |>> that of others.
> |>> Nothing found apart from a couple of open ports which Symantec always
>>> finds.
> |>> It took some minutes to download all the bits in that i386 folder, yet
>>> when
> |>> I hit OK after inserting in Run sfc.exe, there was a flash on the
>>> desktop
> |>> and that was it. Does that seem right. Should I have put something
> |>> different into Run.
> |>> Also, I was not too sure what you meant by '....to the 'root' of the C
> |>> drive.
> |>> Rgds
> |>> Antioch
> |>>
>>> The "root" of the "C:" drive is the lowest part. The root. The base.
>>> The moniker; c:\
>>> means the root of C:.
>>>
>>> Like I said, the command is; SFC /scannow and is best entered in a
>>> command prompt but
>>> doesn't have to be.
>>>
>>> As the switch /scannow infers, it will cause teh OS to "scan" the
>>> systems
>>> to make sure EXE
>>> and DLL files are the right version.
>>>
>>> --
>>> Dave
>>> http://www.claymania.com/removal-trojan-adware.html
>>> http://www.ik-cs.com/got-a-virus.htm
>>>
> | Then I did it wrong and there has been no scan etc.
> | So just dragging and drop of the i386 folder into the C drive, as opened
> via
> | My Computer/Local C along with the folders for Progs, Windows etc.
> | So I better do a proper entry in run. Is that a space bet SFC &
> /scannow.
> | Sorry to keep asking.
> | Antioch
> |
>
> The full command line...
>
> sfc /scannow
>
> Copy and paste the above.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Posted by David H. Lipman on May 26, 2006, 6:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| That's a bit different - it wants my XP Pro Service Pack 2 CD to be
| inserted. I only have Home. Is that OK.
| Antioch

It needs the i386 folder of the installation files used to install YOUR OS at
the same
Service Pack level.

If you have a WinXP Home Edition SP2 installed, it needs to see the i386 folder
of WinXP
Home Edition SP2 level.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by antioch on May 26, 2006, 6:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | That's a bit different - it wants my XP Pro Service Pack 2 CD to be
> | inserted. I only have Home. Is that OK.
> | Antioch
>
> It needs the i386 folder of the installation files used to install YOUR OS
> at the same
> Service Pack level.
>
> If you have a WinXP Home Edition SP2 installed, it needs to see the i386
> folder of WinXP
> Home Edition SP2 level.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
I have put the disk in and its asking what do I want to do???
Sorry this is dragging out.



Posted by David H. Lipman on May 26, 2006, 6:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| I have put the disk in and its asking what do I want to do???
| Sorry this is dragging out.
|

Please re-read my last reply.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


begin 666 eek5.gif
M1TE&.#EA#P`0`/<$`````!@8&)R<_____P``````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M````````````````````````````````````````````````````````````
M`````````````````````"'_"TY%5%-#05!%,BXP`P$````A^00%'@`$`"P`
M````#P`0```(3 `)"!0(H&#!@0@)%!3 D.%!A `:2G0X,.+$B0`(7L2HL.%"
MAQ8%?!09<N3(C1Y#H@2Y4F)&E09=:DP)LR)-CPE/DDQ8T6!&GD!Y!@0`(?D$
M!0H`! `L``````\`$ ``"%,`"0@4"*!@P8$("104P)#A080`&DIT.##BQ(D`
M"#JT*&!A1X4.!PR("$"D18\&21K<V-!C1XXN+TJ,*9,BQYH90=:DJ'$CS(0T
M'R94F'*H4:,!`0`A^00%"@`$`"P`````#P`0```(6P`)"!0(H&#!@0@)%!3
M$"/-C!-S4K2HDR+)GCY_JN2Y$2+/C DK&BR:M&G"@ ``(?D$!60`! `L````
M``\`$ ``"%X`"0@4"*!@P8$("104P)#A080`!"QT&!' P(H#!F#4*)$@@(P9
M/X(!"D29,&16H<.7*ARI4C)4:4&)(F1YD-)^)TJ+"A3Y>_[\&52HS)D=
M(2*EF/!BRJ90H08$`"'Y! 4*``0`+ `````/`! ```A,``D(% B@8,&!" D4
M%,"0X4&$`!I*=#@PXL2)``A>Q*C0XD:'"PV&%"E@X4>))D^"5-DPH\>/&16R
MC"D3I$>:!%^6Q E19,*?0 4&! `A^00%"@`$`"P`````#P`0```(7@`)"!0(
MH&#!@0@)%!3 D.%!A `$+'08$<# B@,&8-0HD2" C!D_@CQ8$*1)DP9%:APY
M<J'*E2,E1I08DB9'F0TGXG2HL*%/GQ9[_OP95*C,F1TA(J68\&+*IE"A!@0`
M(?D$!0H`! `L``````\`$ ``"$P`"0@4"*!@P8$("104P)#A080`&DIT.##B
MQ(D`"%[$J-#B1H<+!1B,.!+D1XP>3XI,>3(CRXL9%:H46;&A09L)0]J,F;"C
MP9Y @08$`"'Y! 5D``0`+ `````/`! ```A>``D(% B@8,&!" D4%,"0X4&$
M``0L=!@1P,"*`P9@U"B1((",&3^"/%@0I$F3!D5J'#ERH<J5(R5&E!B2)D>9
M#2?B=*BPH4^?%GO^_!E4J,R9'2$BI9CP8LJF4*$&! `A^00%9 `$`"P`````
M#P`0```(7P`)"!0(H&#!@0@)%!3 D.%!A `$+'08$<# B@,&8-0HD2" C!D_
M@CQ8$*1)DP9%:APY<J'*E2,E1I08DB9'F0TGXG2HL*%/GQ9[_OP95*C,F1TA
M4IQ95"G0A!!3)@P(`"'Y! 4*``0`+ `````/`! ```A?``D(% B@8,&!" D4
M%,"0X4&$``0L=!@1P,"*`P9@U"B1((",&3^"/%@0I$F3!D5J'#ERH4J-(EU&
ME!B28L.)$F<VO*EPIT^'!'_ZM!B4HDZB%XT"3=AS)U*F*9" @`(?D$!0H`
M! `L``````\`$ ``"%\`"0@4"*!@P8$("104P)#A080`!"QT&!' P(H#!F#4
M*)$@@(P9/X(!"D29,&16H<.7*ARI4C)4:4&)(F1YD-)^)TJ+"A3Y>_[\
M&52HS)D=(5*<650IT(004R8," `A^00%"@`$`"P`````#P`0```(7P`)"!0(
MH&#!@0@)%!3 D.%!A `$+'08$<# B@,&8-0HD2" C!D_@CQ8$*1)DP9%:APY
M<J%*C2)=1I08DF+#B1)G-KRI<*=/AP1_^K08E*).HA>-`DW8<R=2IBF?$@@(
M`"'Y! 5D``0`+ `````/`! ```A?``D(% B@8,&!" D4%,"0X4&$``0L=!@1
MP,"*`P9@U"B1((",&3^"/%@0I$F3!D5J'#ERH<J5(R5&E!B2)D>9#2?B=*BP
<H4^?%GO^_!E4J,R9'2%2G%E4*="$$%,F# @`.P``
`
end



The site map in XML format XML site map

Contact Us | Privacy Policy