KiLL
August 23rd, 2006, 12:30 PM
there was no need to close my previous thread. you could just remove the log.
Anyways can anyone help me remove this Medbot.BD trojan.
It creates setup.exe and autorun.inf on all partitions. NOD detects it all the times and removes setup.exe and i remove autorun.inf manually. but it keeps comming. Here are my running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\GAMING~1\MouseElf.EXE
C:\PROGRA~1\KYE\ERGOME~1\SyTray.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Neobee Speeedy Internet Accelerator\speeedycore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
I don't see anything suspicious here. Any assistance would help.
thank you.
Anyways can anyone help me remove this Medbot.BD trojan.
It creates setup.exe and autorun.inf on all partitions. NOD detects it all the times and removes setup.exe and i remove autorun.inf manually. but it keeps comming. Here are my running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\GAMING~1\MouseElf.EXE
C:\PROGRA~1\KYE\ERGOME~1\SyTray.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Neobee Speeedy Internet Accelerator\speeedycore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
I don't see anything suspicious here. Any assistance would help.
thank you.