Vegabanik.exe spyware
Recently I had to plug in a lot of unclean USB sticks in my office PC, though I have a regularly updated Forticlient anti Virus in my system, I suspected that something was not right... system seemed sluggish and network seemed slow, so I activated the Firewall module, also available with Forticlient Free Edition, and I could see that there was some serious network activities.. a lot of packets were getting blocked by the firewall from one vegabanik.exe... it was trying to send to network ranges of my system and to some outside IP's.
My antivirus couldn't clean it completely though intermittently it popped up showing "I've caught some spyware"
Googling didn't turn up any clues... then i looked for top spyware removers, got a site which listed the top5 .. was looking for options other than the popular spybot... noticed ComboFix, liked its interface and robust looks... seemed the right one, downloaded and installed this free program, ran it and it caught the following exe's in the following paths...
d:\documents and settings\Administrator\fxmdk.exe
d:\documents and settings\****\Application Data\Microsoft\difu.exe
d:\documents and settings\****\Application Data\Microsoft\poniri.exe
d:\documents and settings\LocalService\Application Data\Microsoft\difu.exe
d:\documents and settings\LocalService\Application Data\Microsoft\poniri.exe
After a reboot, everything clean.....
Hope this helps someone bothered by this spy ware...
My antivirus couldn't clean it completely though intermittently it popped up showing "I've caught some spyware"
Googling didn't turn up any clues... then i looked for top spyware removers, got a site which listed the top5 .. was looking for options other than the popular spybot... noticed ComboFix, liked its interface and robust looks... seemed the right one, downloaded and installed this free program, ran it and it caught the following exe's in the following paths...
d:\documents and settings\Administrator\fxmdk.exe
d:\documents and settings\****\Application Data\Microsoft\difu.exe
d:\documents and settings\****\Application Data\Microsoft\poniri.exe
d:\documents and settings\LocalService\Application Data\Microsoft\difu.exe
d:\documents and settings\LocalService\Application Data\Microsoft\poniri.exe
After a reboot, everything clean.....
Hope this helps someone bothered by this spy ware...

0 Comments:
Post a Comment
<< Home