Geek Valley
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Go Back   Geek Valley > Computer Geeks > Computer and Internet Security
User Name
Password

Google Ad

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 09-17-2007, 06:10 AM   #1
teret
Registered User
 
Join Date: Sep 2007
Posts: 15 teret is on a distinguished road
BackDoor-CVT Trojan

Hi folks.

I have a Trojan on my machine - BackDoor-CVT

This is what McAfee says about it;

When this dropper file is run, it creates the following file:

%SysDir%\winicd32.dll (18,944 bytes)This file is injected into Internet Explorer's memory space, to avoid triggering firewall software.

The following registry keys are created:

hkey_local_machine\software\microsoft\windows,
nt\currentversion\winlogon\notify\winxtx32,
hkey_local_machine\software\microsoft\mssmgr\

The dropped file will also try to connect to a remote website, like here4search.biz, where it can get an additional configuration file, named text.dat.

I have the latest update but the scan results say that the infected file
(CWINDOWS\SYSTEM32\WINBFI32.DLL) can not be removed.

If I delete these registry entries will the Trojan be removed or should I remove the WINBFI32.DLL file manually - or would I be screwing up my machine?
teret is offline   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Google Adsense Trojan Stops Riding W3Reports Technology News 0 01-22-2006 12:05 PM
Trojan Hunter plonkeroo Computer and Internet Security 2 10-06-2004 10:05 AM



All times are GMT -6. The time now is 04:25 PM.

Primary Sponsor: eMotion Picture Studios, Toronto

Interior Designer Oakville


Powered by: vBulletin Version 3.0.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
forum style designed by eMotion Digital Marketing, Toronto