View Single Post
Old 12-27-2007, 09:42 PM   #21 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 20,901
OS: WinXP and Vista


Re: Popups and Trojan.Virtumonde

Yes, John. Reinstalling those programs is the best way to move forward with this. Those programs had been infected and there apparently were no backups left for us to move to fix them. For example:
Quote:
C:\qoobox\Quarantine\C\Program Files\Windows Defender\MSASCui.exe.vir ------> AdWare.Win32.Virtumonde.cli skipped
Make sure you uninstall them first via the Add/Remove programs panel, reboot, then reinstall.

----------------------------------------------------------

Let's tidy up a bit as well. The following procedure will clear out ComboFix.exe, as well as the backups and quarantines created by the fix. It will also reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point.

Click Start > Run and copy/paste, or type the following bolded text into the Run box and click OK:

ComboFix /u

--------------------------------------------------------------------

Launch Spybot S&D and click 'Recovery'. Purge all items.

--------------------------------------------------------------------

Also, check your SunJava and make sure it will update.

Test out the system and let me know how it's running in a couple of days.
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline  
Sponsored Links