Two Plus Two Publishing LLC Two Plus Two Publishing LLC
 

Go Back   Two Plus Two Poker Forums > Other Topics > Computer Technical Help

Notices

Computer Technical Help Post your questions about computer hardware and software and configuring same here.

Reply
 
Thread Tools Display Modes
Old 08-01-2012, 01:51 PM   #16
newbie
 
Join Date: Jul 2006
Posts: 23
Re: Help please - got a trojan (xsecva.exe)

I think my computer is running alright. HM is not working properly (can't connect to the database) but I think that is unrelated. Hitman Pro didn't want to run on Win 7, something about 32 bit. Where can I download another version?
onehandclapping is offline   Reply With Quote
Old 08-02-2012, 04:05 AM   #17
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 12,625
Re: Help please - got a trojan (xsecva.exe)

We are going to run a scan with ESET Online Scanner. Please make sure you are logged in as a user with administrator rights and proceed with the following steps:
  • Use Internet Explorer to browse to the ESET Online Scanner webpage
  • Click the green ESET Online Scanner button
  • A popup window will open
  • Accept the terms of use and click Start
  • Internet Explorer probably informs you that ESET tries to install an add-on. Allow that.
  • UNSELECT the Remove all threats option.
  • Click Start
  • When the scan has finished and threats were found, click List of found threats
  • Click Export to text file and save it as e.g. eset.txt on your desktop
  • Click Back
  • Select Uninstall application on close
  • Click Finish. ESET Online Scanner will now uninstall itself
  • Please post the contents of the eset.txt in your next reply.
Gabethebabe is offline   Reply With Quote
Old 08-03-2012, 05:04 PM   #18
newbie
 
Join Date: Jul 2006
Posts: 23
Re: Help please - got a trojan (xsecva.exe)

Here are the results of the ESET scanner:

C:\Microgaming\Poker\5050pokerMPP\install.exe a variant of Win32/PrimeCasino application
C:\Microgaming\Poker\NordicBetMPP\install.exe a variant of Win32/PrimeCasino application
C:\Qoobox\Quarantine\C\Users\Daniel\AppData\Local\ {c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\n.vir Win64/Sirefef.W trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\n.vir Win64/Sirefef.W trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\00000008.@.vir Win64/Agent.BA trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\000000cb.@.vir Win64/Conedex.B trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\80000000.@.vir Win64/Sirefef.AP trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\80000032.@.vir a variant of Win32/Sirefef.FD trojan
C:\Qoobox\Quarantine\C\Windows\System32\services.e xe.vir Win64/Patched.B.Gen trojan
C:\Users\Daniel\Downloads\NordicBet.exe a variant of Win32/PrimeCasino application
C:\_OTL\MovedFiles\07312012_174351\C_Users\Daniel\ AppData\Roaming\mpidms.dll a variant of Win32/Medfos.BK trojan
C:\_OTL\MovedFiles\07312012_174351\C_Windows\Insta ller\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\00000008.@ Win64/Agent.BA trojan
C:\_OTL\MovedFiles\07312012_174351\C_Windows\Insta ller\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\000000cb.@ Win64/Conedex.B trojan
C:\_OTL\MovedFiles\07312012_174351\C_Windows\Insta ller\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\80000000.@ Win64/Sirefef.AP trojan
C:\_OTL\MovedFiles\07312012_174351\C_Windows\Insta ller\{c50e9bb8-b711-e88e-2f53-ae507f8b3da6}\U\80000032.@ a variant of Win32/Sirefef.FD trojan
onehandclapping is offline   Reply With Quote
Old 08-03-2012, 06:05 PM   #19
newbie
 
Join Date: Jul 2006
Posts: 23
Re: Help please - got a trojan (xsecva.exe)

Quote:
Originally Posted by Gabethebabe View Post

The infection that I suspected on your computer (a rootkit called ZeroAccess) seems to have been removed sometime ago already (swhere around march, this rings a bell?).

How are things running now, btw? Anything suspicious going on?
I actually got this computer on the 28th of March so that would have been weird. I can't recall having any issues before. As an aside I do believe my computer did get banged up a bit by the Combofix though
onehandclapping is offline   Reply With Quote
Old 08-03-2012, 06:09 PM   #20
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 12,625
Re: Help please - got a trojan (xsecva.exe)

OK, eset found only the dead bodies of malware we eliminated.

combofix went ape**** on you, because it found the principal threat that was on your computer - the ZeroAccess (Siresef) rootkit and needed some reboots to get rid of it.
ZA is a nasty piece of work, but it is gone now.

I recommend you change all relevant passwords.

As far as I can see, your computer is CLEAN.



Time to uninstall used tools.
  • Go to Start > Run and type or copy/paste Combofix /uninstall (note the space before the "/") (if you deleted combofix, you should download it again, so it can remove all stuff that it installed on your computer).
  • Double click OTL.exe to run it again and click the CleanUp button.
  • If we used any other tools and they still remain on your desktop, please delete them manually.

====================
You need to install the latest version of Java. Having the latest version is important to take advantage of fixes that have eliminated security vulnerabilities.
  • Go to Start > Control Panel
  • Double-click on Add or Remove Programs
  • Look for entries that say Java, Java RunTime Environment or J2SE.
  • Uninstall all of them that are not named Java (TM) 7 Update 5
After doing this, you can go to java.com, click on Free Java Download and proceed from there to install the latest version of Java (currently Version 7 Update 5).

After installing Java, go to Start > Control Panel > Java to open the Java Control Panel.
Under the General tab, Temporary Internet Files click Settings, then click Delete Files.
Select both options and click OK to delete the Java cache.

Note: only install Java 64-bit if you use a 64-bit browser (which I think you do not).

====================


Click here for some final recommendations that may help you to stay clean.
Gabethebabe is offline   Reply With Quote
Old 08-04-2012, 08:04 AM   #21
newbie
 
Join Date: Jul 2006
Posts: 23
Re: Help please - got a trojan (xsecva.exe)

I managed to uninstall everything, but rkill. Google also came up empty. How do I properly uninstall it? Everything seems to work fine now so thanks for all the help!
onehandclapping is offline   Reply With Quote
Old 08-04-2012, 09:28 AM   #22
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 12,625
Re: Help please - got a trojan (xsecva.exe)

rkill is just a single exe that you can delete.
Only combofix and OTL require being uninstalled.
Gabethebabe is offline   Reply With Quote
Old 08-05-2012, 08:21 AM   #23
stranger
 
Join Date: Aug 2012
Posts: 1
Re: Help please - got a trojan (xsecva.exe)

I have the same virus it got by my trend antivirus.How do I get rid of it?
dcdcnr is offline   Reply With Quote
Old 08-05-2012, 09:17 AM   #24
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 12,625
Re: Help please - got a trojan (xsecva.exe)

Quote:
Originally Posted by dcdcnr View Post
I have the same virus it got by my trend antivirus.How do I get rid of it?
Open a new thread and do not hijack this one.
Gabethebabe is offline   Reply With Quote

Reply
      

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -4. The time now is 10:21 PM.


Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.
Copyright © 2008-2010, Two Plus Two Interactive