 noway1
join:2004-11-29
edit: July 28th, @11:46PM
| reply to SipSizzurp Re: SuperSick2008
said by SipSizzurp :...This is another NOD32 case, green dot and all. Q1. Sorry, I don't understand what you mean by this sentence.
Q2. AV Version? Sig version?
Q3. Has the updater been updating regularly or have there been some updates missed? (some NOD32 v3 users are having some updater problems right now)
Q4. Do you know how you got this Vundo? |
|
 SipSizzurp Fo' Shizzle Premium join:2005-12-28 Hilo, HI
·RoadRunner Cable
edit: July 29th, @12:40AM
| Q1 The system tray has a green dot. Maximum protection. Number of blocked attacks = 0
Q2 ESET NOD32 AntiVirus 3.0.650.0 Sig Ver. 3304 2008728
Q3 I assume it has been running since it is current.
Q4 No. I wish you hadn't have asked. I just checked it's browser history. It has been to numerous porn sites. The virus may be responsible for some of them, but knowing where I picked the computer up from, not all of them. There was a lot more wrong than Vundo. There was a plethora of trojans and hijackers detected. Spybot found only one more. It is now partially cured, I can get to the local resources in "My Computer" and the start menu is back. It was also empty earlier. Desktop background is still whited out with the icons looking weird. I've got the Exaspery tool running now. It is at about 20% and has found nothing yet. I'm planning to run prevx, and then attempt an exorcism with RKU. After that I'll run SFC to see if I can repair some damage. I'm not sure what else to throw at it.
Looks like the main site for the primary viral download was antivirusxp2008 dot com. The homepage is being hijacked to : softwarereferral dot com. Might make for some interesting whois reading.
Edit - I wonder if she would answer her phone. Easy number to remember ! 
Domain Name: ANTIVIRUSXP2008.COM
Registrant: Goya interco llc Alice Velaques (alice.velasues@botiquestomp.com) La vaal sq 47 of 54 Kemi Ahvenanmasnlääni,10755 FI Tel. +001.41512345678 Fax. +001.41512345678
Creation Date: 17-Jun-2008 Expiration Date: 17-Jun-2009
-- I spent most of my money on Women and Beer, and the rest I just wasted ! |
|
  SnowyOne Premium join:2003-04-05 Kailua, HI
·RoadRunner Cable
·Clearwire Wireless
| said by SipSizzurp :Creation Date: 17-Jun-2008 Expiration Date: 17-Jun-2009 FWIW, the initial infection probably happened sometime after 17-Jun-2008 |
|