Virtumonde/Seneka infection please advise

Reply

Join Date: Jan 2009
Posts: 23
Reputation: OneBlueD is an unknown quantity at this point 
Solved Threads: 0
OneBlueD OneBlueD is offline Offline
Newbie Poster

Re: Virtumonde/Seneka infection please advise

 
0
  #31
Jan 16th, 2009
Ok ..yet another glitch.
I restarted in Safe Mode and tried to run RunThis.bat
A blue window appeared for a fraction of a second and then it closed right off.
I tried to run it again as admin ad stii the same thing.
I don't know what else to do.
I guess vista has something to do with that .
So to wrap it up it didn't do anything , no scan no log no nothing
Reply With Quote Quick reply to this message  
Join Date: Jan 2009
Posts: 23
Reputation: OneBlueD is an unknown quantity at this point 
Solved Threads: 0
OneBlueD OneBlueD is offline Offline
Newbie Poster

Re: Virtumonde/Seneka infection please advise

 
0
  #32
Jan 16th, 2009
Port 5550/TCP is open (matches XTCP.200)
Port 5550/TCP is open (matches XTCP.201)
Found trojan file: C:\ComboFix\hidec.exe (RiskTool.Hidec.100)
Found adware file: C:\Program Files\BS.Player ControlBar\BSToolbar.dll (Adware.FastLook)
Found adware file: C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (Adware.FastLook)
Found adware file: C:\Program Files\Webteh\BSplayer\bplay.exe/Upx.tooqfmrg (Adware.BSPlay.100)
Found adware file: C:\Program Files\Webteh\BSplayer\bsplay.exe/Upx.xxoplfyg (Adware.BSPlay.100)
Found trojan file: C:\Users\MIRA\Desktop\ComboFix.exe/hidec.exe (RiskTool.Hidec.100)
Found trojan file: C:\Users\MIRA\Desktop\ComboFix.exe/Upx.hafftohv/hidec.exe (RiskTool.Hidec.100)


I did a scan with TrojanHunter and this is the result

I think that the results here are false pozitives ... at least that is my opinion
Last edited by OneBlueD; Jan 16th, 2009 at 10:06 am.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,923
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 709
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virtumonde/Seneka infection please advise

 
0
  #33
Jan 17th, 2009
Try and run it in normal mode. Not sure if the latest version will do that or not.

How far back does your system restore go?
Reply With Quote Quick reply to this message  
Join Date: Jan 2009
Posts: 23
Reputation: OneBlueD is an unknown quantity at this point 
Solved Threads: 0
OneBlueD OneBlueD is offline Offline
Newbie Poster

Re: Virtumonde/Seneka infection please advise

 
0
  #34
Jan 17th, 2009
I tried to run it and it says that I need to do it in SafeMode
So no luck there.
System restore will probably take me to when I first bought the laptop ...so december 2008
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,923
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 709
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virtumonde/Seneka infection please advise

 
0
  #35
Jan 17th, 2009
Might be the way to go seeing that we are having no success this way.
Reply With Quote Quick reply to this message  
Join Date: Jan 2009
Posts: 23
Reputation: OneBlueD is an unknown quantity at this point 
Solved Threads: 0
OneBlueD OneBlueD is offline Offline
Newbie Poster

Re: Virtumonde/Seneka infection please advise

 
0
  #36
Jan 17th, 2009
There has to be a way
This is ridiqulous
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,923
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 709
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virtumonde/Seneka infection please advise

 
0
  #37
Jan 17th, 2009
You will not lose any documents and the like by doing the sys restore.
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,923
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 709
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Virtumonde/Seneka infection please advise

 
0
  #38
Jan 17th, 2009
Will not hurt I suppose to run this;

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under Configuration and Preferences, click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
- Close browsers before scanning.
- Scan for tracking cookies.
- Terminate memory threats before quarantining.

* Click the Close button to leave the control center screen.
* Back on the main screen, under Scan for Harmful Software click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under Complete Scan, choose Perform Complete Scan.
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
* Make sure everything has a checkmark next to it and click Next.
* A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
* If asked if you want to reboot, click Yes.
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
- Click Preferences, then click the Statistics/Logs tab.
- Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
- If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
- Please copy and paste the Scan Log results in your next reply.

* Click Close to exit the program.
Post SUPERAntiSpyware log.
NOTE: Tracking cookies can be omitted from the log.

RECONNECT TO THE INTERNET
Reply With Quote Quick reply to this message  
Join Date: Jan 2009
Posts: 23
Reputation: OneBlueD is an unknown quantity at this point 
Solved Threads: 0
OneBlueD OneBlueD is offline Offline
Newbie Poster

Re: Virtumonde/Seneka infection please advise

 
0
  #39
Jan 17th, 2009
I will try .. and if it doesn't work I'll ask for your help in doing the other thing...
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC