Results 1 to 5 of 5

Thread: A little disinfection help, please... [Resolved]

  1. #1

    Thread Starter
    I'm about to be a PowerPoster! mendhak's Avatar
    Join Date
    Feb 2002
    Location
    Ulaan Baator GooGoo: Frog
    Posts
    38,170

    A little disinfection help, please... [Resolved]

    A virus just got into my system. My antivirus, AVG, detected it, and it says:

    ---------------------------
    AVG Resident Shield
    ---------------------------
    Virus
    Virus identified Worm/Padobot.I

    is found in file
    C:\WINDOWS\system32\ftpupd.exe

    To remove this virus, please run AVG for Windows
    ---------------------------
    OK
    ---------------------------
    So I did run a full scan on my machine, and no go. It just didn't pick up Padobot.I

    So my questions are:

    1. What can I do about Padobot.I? Any removal tools or files/registry entries I must delete?

    2. What is "ftpupd.exe"? Do I need it?

    A little more info: Once in a while, an instance of Internet Explorer will suddenly open up, and head over to some angelfire.com website, where it prompts me to install an ActiveX control. Luckily, some of my gray cells still function, so I close it all. I believe that this is related to Padobot.I.


    Note that Norton AV is not an option for me, I simply cannot afford it. Also, this is the only file that seems infected.

    Help.
    Last edited by mendhak; Jul 28th, 2004 at 08:35 PM.

  2. #2

    Thread Starter
    I'm about to be a PowerPoster! mendhak's Avatar
    Join Date
    Feb 2002
    Location
    Ulaan Baator GooGoo: Frog
    Posts
    38,170
    OK, AVG finally picked it up on the scan, and is asking me whether it should be moved to the virus vault or not.

    Once moved, I cannot use it anymore.

    So, what is ftpupd.exe???

  3. #3
    VBA Nutter visualAd's Avatar
    Join Date
    Apr 2002
    Location
    Ickenham, UK
    Posts
    4,906
    http://www.globalhauri.com/html/supp...ode=WOW3000615

    Have a quick read of that. The ftpupd.exe file was created by the worm, so it is fine to remove it. It uses the MS LSASS exploit for which Microsoft have released a patch for:

    http://www.microsoft.com/technet/sec.../MS04-011.mspx
    PHP || MySql || Apache || Get Firefox || OpenOffice.org || Click || Slap ILMV || 1337 c0d || GotoMyPc For FREE! Part 1, Part 2

    | PHP Session --> Database Handler * Custom Error Handler * Installing PHP * HTML Form Handler * PHP 5 OOP * Using XML * Ajax * Xslt | VB6 Winsock - HTTP POST / GET * Winsock - HTTP File Upload

    Latest quote: crptcblade - VB6 executables can't be decompiled, only disassembled. And the disassembled code is even less useful than I am.

    Random VisualAd: Blog - Latest Post: When the Internet becomes Electricity!!


    Spread happiness and joy. Rate good posts.

  4. #4

    Thread Starter
    I'm about to be a PowerPoster! mendhak's Avatar
    Join Date
    Feb 2002
    Location
    Ulaan Baator GooGoo: Frog
    Posts
    38,170
    If I had the chance, I'd sneeze again. The world needs more people like you.

  5. #5
    VBA Nutter visualAd's Avatar
    Join Date
    Apr 2002
    Location
    Ickenham, UK
    Posts
    4,906
    Originally posted by mendhak
    If I had the chance, I'd sneeze again. The world needs more people like you.
    PHP || MySql || Apache || Get Firefox || OpenOffice.org || Click || Slap ILMV || 1337 c0d || GotoMyPc For FREE! Part 1, Part 2

    | PHP Session --> Database Handler * Custom Error Handler * Installing PHP * HTML Form Handler * PHP 5 OOP * Using XML * Ajax * Xslt | VB6 Winsock - HTTP POST / GET * Winsock - HTTP File Upload

    Latest quote: crptcblade - VB6 executables can't be decompiled, only disassembled. And the disassembled code is even less useful than I am.

    Random VisualAd: Blog - Latest Post: When the Internet becomes Electricity!!


    Spread happiness and joy. Rate good posts.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width