Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 22nd, 2009, 05:55 PM
jamest jamest is offline
Infrequent Poster
 
Join Date: Jan 2007
Posts: 4
Question Win32/Waledec.KA trojan

Hi there

I'm a long time user of NOD32 and never been infected before (I think!). I have been infected today and would appreciate any advice on how to ensure my computer is now clean.

Today at 12:05 I got a NOD32 warning message about the file:

"http://u8r.in/se/1.exe"

which was identified as "a variant of the Win32/Waledac.KA trojan"

I first opted to block this. But the message appeared twice again over the next 25 minutes and on both these occasions I chose the Terminate option.

After the 3rd warning, I looked in my task manager and saw the process:

wpv121248215369.exe

I killed this process. Reading about something called trojan.bredolab I discovered this exe file in the folder windows\temp and deleted from there (the file was created at 12:05).

I also found the file rncsys32.exe in my programs\startup group, although I am not sure if this has any connection. I deleted that too.

I have rescanned my computer a couple of times and nothing was found.

However, as NOD32 did not remove the infection, I am concerned it may reappear.

How can I be sure this is gone?
Also if anyone knows how I got this, please let me know?

Any advice greatly appreciated

James
  #2  
Old July 22nd, 2009, 06:41 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,003
Default Re: Win32/Waledec.KA trojan

Download an application such as MalwareBytes or SuperAntiSpyware and do a scan.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #3  
Old July 22nd, 2009, 07:17 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,195
Default Re: Win32/Waledec.KA trojan

Quote:
Originally Posted by jamest
I have rescanned my computer a couple of times and nothing was found.

Maybe nothing was found because v2 detects less threats than v3/v4. Unless you use Windows 9x or have NOD32 for Exchange installed, I'd strongly suggest that you upgrade to v4.
  #4  
Old July 22nd, 2009, 10:59 PM
jjavierv17 jjavierv17 is offline
Infrequent Poster
 
Join Date: Jul 2009
Location: Monagas, Venezuela
Posts: 7
Default Re: Win32/Waledec.KA trojan

Hi There! You can also use "Trojan Remover". It's not a freeware but it helps a lot when talking about Trojans. the current version is 6.7.9, I think. Bye ;-)
__________________
Viruses, don't bother my PC or you'll face eset antivirus.
  #5  
Old July 24th, 2009, 04:25 AM
jamest jamest is offline
Infrequent Poster
 
Join Date: Jan 2007
Posts: 4
Default Re: Win32/Waledec.KA trojan

Quote:
Originally Posted by Marcos
Maybe nothing was found because v2 detects less threats than v3/v4. Unless you use Windows 9x or have NOD32 for Exchange installed, I'd strongly suggest that you upgrade to v4.

Thanks for these suggestions.

I have installed NOD32 v4 and rescanned but no threats were found.

Prior to that, I installed SuperAntiSpyware and scanned - no threats.

I also scanned with MalwareBytes. This found one infected file also created a 12:05:
c:\documents and settings\****\Application Data\wiaserva.log

What bothers me is that apart from this file found by Malwarebytes all of the files/process to be removed have been identified by me. This does not give me much confidence I am in the clear.

Does anyone know what these threats are (rncsys32.exe, wpv[numbers].exe), how they got on my computer, and how I can be sure I'm rid of them?

I have searched on the eset website and cannot find any information.

Kind regards

James
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 10:24 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums