chibicitiberiu
New Member
Okay, so long story short... my sister opens a link she gets from someone on Yahoo IM from curiosity, and that opens a virus. AVG keeps detecting a file called rpdnet.exe, and even though I click 'heal' or 'move to vault', it keeps poping up. A full scan with AVG didn't solve it, so right now I'm doing a scan with Malware bytes.
The problem with this virus is that it keeps sending messages to all my list in messenger with that link. Weird enough, I have been receiving these kind of instant messages more than ever in the last few days, maybe it's a really wide infection.
Here are the scan results:
The problem with this virus is that it keeps sending messages to all my list in messenger with that link. Weird enough, I have been receiving these kind of instant messages more than ever in the last few days, maybe it's a really wide infection.
Here are the scan results:
Code:
Memory Processes Infected:
C:\Documents and Settings\Tiberiu\Local Settings\temp\vshost32.exe (Worm.IMStealer) -> Unloaded process successfully.
Files Infected:
C:\Documents and Settings\Tiberiu\Local Settings\temp\vshost32.exe (Worm.IMStealer) -> Quarantined and deleted successfully.
C:\vshost.exe (Worm.IMStealer) -> Quarantined and deleted successfully.
Code:
Malwarebytes' Anti-Malware 1.41
Database version: 3195
Windows 5.1.2600 Service Pack 3
11/18/2009 10:27:18 PM
mbam-log-2009-11-18 (22-27-18).txt
Scan type: Quick Scan
Objects scanned: 111442
Time elapsed: 8 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\Tiberiu\LOCALS~1\Temp\vshost32.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Tiberiu\Local Settings\temp\MyMumNaked.PIF (Worm.IMStealer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Tiberiu\Local Settings\temp\I7RpNn76.com.part (Worm.IMStealer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Tiberiu\Local Settings\temp\827102.exe (Worm.IMStealer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Tiberiu\Local Settings\Temporary Internet Files\Content.IE5\IM4LEHC7\bu[1].exe (Worm.IMStealer) -> Quarantined and deleted successfully.