943,513 Members | Top Members by Rank

Ad:
You are currently viewing page 4 of this multi-page discussion thread; Jump to the first page
Jan 16th, 2009
0

Re: Virtumonde/Seneka infection please advise

Ok ..yet another glitch.
I restarted in Safe Mode and tried to run RunThis.bat
A blue window appeared for a fraction of a second and then it closed right off.
I tried to run it again as admin ad stii the same thing.
I don't know what else to do.
I guess vista has something to do with that .
So to wrap it up it didn't do anything , no scan no log no nothing
Reputation Points: 10
Solved Threads: 0
Newbie Poster
OneBlueD is offline Offline
23 posts
since Jan 2009
Jan 16th, 2009
0

Re: Virtumonde/Seneka infection please advise

Port 5550/TCP is open (matches XTCP.200)
Port 5550/TCP is open (matches XTCP.201)
Found trojan file: C:\ComboFix\hidec.exe (RiskTool.Hidec.100)
Found adware file: C:\Program Files\BS.Player ControlBar\BSToolbar.dll (Adware.FastLook)
Found adware file: C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (Adware.FastLook)
Found adware file: C:\Program Files\Webteh\BSplayer\bplay.exe/Upx.tooqfmrg (Adware.BSPlay.100)
Found adware file: C:\Program Files\Webteh\BSplayer\bsplay.exe/Upx.xxoplfyg (Adware.BSPlay.100)
Found trojan file: C:\Users\MIRA\Desktop\ComboFix.exe/hidec.exe (RiskTool.Hidec.100)
Found trojan file: C:\Users\MIRA\Desktop\ComboFix.exe/Upx.hafftohv/hidec.exe (RiskTool.Hidec.100)


I did a scan with TrojanHunter and this is the result

I think that the results here are false pozitives ... at least that is my opinion
Last edited by OneBlueD; Jan 16th, 2009 at 10:06 am.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
OneBlueD is offline Offline
23 posts
since Jan 2009
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

Try and run it in normal mode. Not sure if the latest version will do that or not.

How far back does your system restore go?
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,162 posts
since Feb 2004
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

I tried to run it and it says that I need to do it in SafeMode
So no luck there.
System restore will probably take me to when I first bought the laptop ...so december 2008
Reputation Points: 10
Solved Threads: 0
Newbie Poster
OneBlueD is offline Offline
23 posts
since Jan 2009
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

Might be the way to go seeing that we are having no success this way.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,162 posts
since Feb 2004
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

There has to be a way
This is ridiqulous
Reputation Points: 10
Solved Threads: 0
Newbie Poster
OneBlueD is offline Offline
23 posts
since Jan 2009
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

You will not lose any documents and the like by doing the sys restore.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,162 posts
since Feb 2004
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

Will not hurt I suppose to run this;

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
* Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

* Open SUPERAntiSpyware.
* Under Configuration and Preferences, click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
- Close browsers before scanning.
- Scan for tracking cookies.
- Terminate memory threats before quarantining.

* Click the Close button to leave the control center screen.
* Back on the main screen, under Scan for Harmful Software click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under Complete Scan, choose Perform Complete Scan.
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
* Make sure everything has a checkmark next to it and click Next.
* A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
* If asked if you want to reboot, click Yes.
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
- Click Preferences, then click the Statistics/Logs tab.
- Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
- If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
- Please copy and paste the Scan Log results in your next reply.

* Click Close to exit the program.
Post SUPERAntiSpyware log.
NOTE: Tracking cookies can be omitted from the log.

RECONNECT TO THE INTERNET
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,162 posts
since Feb 2004
Jan 17th, 2009
0

Re: Virtumonde/Seneka infection please advise

I will try .. and if it doesn't work I'll ask for your help in doing the other thing...
Reputation Points: 10
Solved Threads: 0
Newbie Poster
OneBlueD is offline Offline
23 posts
since Jan 2009

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Trojan Found On a Disc I Burned. Did it infect me? Log Provided
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: jeefo virus





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC