View Single Post
Old 12-10-2008, 02:40 PM   #7 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,275
OS: XP SP3


Re: possible Backdoor.PcClient.jhu infection

Hi,

Quote:
The Crossloop software listed as infected (in the kaspersky log) i have researched before and seems to only show up as it enables remote access. I'm going to uninstall it anyway i think when i get the all clear as i no longer have use for it.
OK. That's good.
Quote:
Computer seems to running ok. A little slow, but no blue screen of death on shutdown anymore
That's good to hear. However, something didn't seem to work. Let's try it again.
  • Open notepad (Start>All programs>accessories>notepad ) (It must be notepad, not wordpad, or it won't work)
  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Click Format and ensure Wordwrap is unchecked.

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Code:
Extra::

DDS::
mSearch Bar = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uSearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
Save this as CFScript.txt, in the same location as ComboFix.exe



Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline