Author Topic: Infected by x.exe more than 20 times  (Read 34870 times)

0 Members and 1 Guest are viewing this topic.

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #15 on: November 30, 2008, 05:29:49 PM »
;D bading ka ba? :D ;D :o

Di ako bading! Trip ko lang.
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #16 on: November 30, 2008, 05:36:45 PM »
http://www.mediafire.com/download.php?imjzm4xvomd

for new OTScanit log

http://www.mediafire.com/?hjymd2dmazl

for new hijackthis log

DR Web scanner detect sdfix.exe as malware. what is going on?

Also Vista Transformation Pack 9 is also detect as malware. Is this because vtp can modify system files?

Dr. Web is not bad. Scan archives highspeed.
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #17 on: November 30, 2008, 05:40:40 PM »
Whilst I look at the logsand to put your mind at rest sdfix.exe was reported as it can do good or bad.  In our case it is good

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #18 on: November 30, 2008, 05:43:34 PM »
The logs look OK are you still getting alerts ?

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #19 on: November 30, 2008, 05:50:57 PM »
Dr. Web isn't done yet but it picked up t[1].txt and recognized as Win.irc.worm.virus
t[1].exe is partner of x.exe
x.exe might be a bot.

the alerts only appear when dr. web finds malware that is a partner of x.exe
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #20 on: November 30, 2008, 05:51:40 PM »
That will be as it opens them to see what they are

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #21 on: November 30, 2008, 06:21:19 PM »
Since defense+ banned ftp.exe from downloading quicktime.exe, every 4-15 seconds comodo firewall blocks almost 700 intrusion attempts since midnight(my place). :o :o

Those blocks are similar all UDP and goes to port 50213 (The same port I use for utorrent). I might got x.exe from using utorrent. Should I change the port of utorrent or temporarily stop using utorrent for a while? ??? ???
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #22 on: November 30, 2008, 06:26:04 PM »
That is the source of your problems yes.  As fast as the problems are cleared more keep coming

Lets try Combofix as that is a lot stronger and from that I may be able to detect and kill the driver/service that is downloading

Download Combofix from any of the links below. You must rename it before saving it.  Save it to your desktop.

Link 1
Link 2
Link 3





--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #23 on: November 30, 2008, 06:41:18 PM »
should I stop dr. web? It is still not done with full scan.
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #24 on: November 30, 2008, 06:42:03 PM »
I thought it had, no complete dr web then run combofix

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #25 on: November 30, 2008, 06:59:36 PM »
ok,
Earlier, I was suddenly disconnected from the net. All the connections to the malware distributors are gone. It might resume if utorrent is started
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #26 on: November 30, 2008, 07:06:16 PM »
Was that when combofix was running as it will do that

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #27 on: November 30, 2008, 07:07:37 PM »
Nope, while waiting for dr web to finish
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Infected by x.exe more than 20 times
« Reply #28 on: November 30, 2008, 07:08:16 PM »
Is it still running,  you must have a large hard drive  ;D

Offline RZPogi

  • Sr. Member
  • ****
  • Posts: 237
Re: Infected by x.exe more than 20 times
« Reply #29 on: November 30, 2008, 07:13:34 PM »
Quite and I have a lot of archives because of the many games installed in my pc.
DESKTOP: Win 10, Avast 20 Free, Windows firewall, Malwarebytes free

LAPTOP: Win 10, Windows Defender, Malwarebytes free, Windows Firewall, Mcshield