View Single Post
Old 08-05-2008, 05:33 AM   #7 (permalink)
TheBruce1
Moderator, Analyst, Security Team
 
TheBruce1's Avatar
 
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP


Re: Pop ups on I.E. Backdoor Trojan, help please deckards included

Hello again

Delete [4]-Submit_2008-08-04@16.47.zip from your desktop, files uploaded successfully, thank you.

Quote:
Originally Posted by summit15
I keep having windows update notify me of new downloads, but I am hesitant that it might be a trick. So I am not going to install unless you can tell me how to verify it is authentic.
Go ahead and install the updates if you wish.

Quote:
Originally Posted by summit15
For some reason, my HP 7700 printer keeps changing settings to "photo paper", "mirror printing on", and best printing. I have to manually change these back or it prints backward, (right to left)
You may need to uninstall then reinstall your printer software if the problem persists.

Quote:
Originally Posted by summit15
Why doesn't McAfee stop these virus's? I am thinking of getting Karpesky Anti-virus. What do find to be the best one out there now?
I`m afraid no vendor will stop every malicious file out there, when we have concluded i will post a couple of interesting articles on how best to protect yourself. As for for your question as to whether Kaspersky is better than Mcafee, there is no simple answer to that, i prefer Kaspersky to Mcafee for many reasons, its light and it updates hourly to name two, always try the trial version first before purchasing the product.

===========

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O15 - Trusted Zone: http://*.mcafee.com
O20 - AppInit_DLLs: NVDESK32.DLL sqwrpw.dll vhthho.dll
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Please remember to close all other windows, including browsers then click Fix checked.

=========

Open notepad and copy/paste the text in the quotebox below into it:

Quote:
Folder::
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Symantec Temporary Files
C:\Program Files\Common Files\Symantec Shared
Driver::
symlcsvc
File::
C:\WINDOWS\CouponBarIE.dll
Save this as CFscript







Refering to the picture above, drag CFscript into ComboFix.exe

Follow the prompts, and post the resulting log, C:\ComboFix.txt

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


Warning:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

=========

Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.

=========
Logs Required
C:\Combofix.txt
Hijackthis Log


Note: Do NOT attach your logs, just copy/paste them into your reply
__________________
Member of ASAP since 2007
Member of UNITE since 2008


**Notice to BT customers**
BT to dump Phorm, see Here for more information. No DPI

If we have helped you in anyway, please consider Donating
TheBruce1 is offline