|
-
Jul 28th, 2004, 10:14 AM
#1
A little disinfection help, please... [Resolved]
A virus just got into my system. My antivirus, AVG, detected it, and it says:
---------------------------
AVG Resident Shield
---------------------------
Virus
Virus identified Worm/Padobot.I
is found in file
C:\WINDOWS\system32\ftpupd.exe
To remove this virus, please run AVG for Windows
---------------------------
OK
---------------------------
So I did run a full scan on my machine, and no go. It just didn't pick up Padobot.I
So my questions are:
1. What can I do about Padobot.I? Any removal tools or files/registry entries I must delete?
2. What is "ftpupd.exe"? Do I need it?
A little more info: Once in a while, an instance of Internet Explorer will suddenly open up, and head over to some angelfire.com website, where it prompts me to install an ActiveX control. Luckily, some of my gray cells still function, so I close it all. I believe that this is related to Padobot.I.
Note that Norton AV is not an option for me, I simply cannot afford it. Also, this is the only file that seems infected.
Help.
Last edited by mendhak; Jul 28th, 2004 at 08:35 PM.
-
Jul 28th, 2004, 11:03 AM
#2
OK, AVG finally picked it up on the scan, and is asking me whether it should be moved to the virus vault or not.
Once moved, I cannot use it anymore.
So, what is ftpupd.exe???
-
Jul 28th, 2004, 11:22 AM
#3
http://www.globalhauri.com/html/supp...ode=WOW3000615
Have a quick read of that. The ftpupd.exe file was created by the worm, so it is fine to remove it. It uses the MS LSASS exploit for which Microsoft have released a patch for:
http://www.microsoft.com/technet/sec.../MS04-011.mspx
-
Jul 28th, 2004, 08:35 PM
#4
If I had the chance, I'd sneeze again. The world needs more people like you.
-
Jul 29th, 2004, 02:04 AM
#5
Originally posted by mendhak
If I had the chance, I'd sneeze again. The world needs more people like you.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
Click Here to Expand Forum to Full Width
|