Trojan.virumonde and tojan-pws.transpy infection

By gian0819
Jan 27, 2008
  1. hi. good day. i first did a spybot scan and found virtumonde in my system. i chose fix selected problems and said it was successful. i rebooted my system and did again a spybot scan and found the same virus again. then i used spydoctor. it did found virtumonde and another virus, the trojan-pws.transpy. i tried to fix the said viruses by clicking "fix checked". and i rebooted my pc and did another scan. it found again the same viruses. help me please...
  2. grimesy69

    grimesy69 TS Rookie Posts: 52

    Can you try it in safe mode please, and see what happens then.

    To get into the Windows 2000 / XP Safe mode, as the computer is booting press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu". Use your arrow keys to move to "Safe Mode" and press your Enter key.

  3. tomrca

    tomrca TS Rookie Posts: 1,000

    this service needs to be stopped, Trojan-Downloader.Win32.Agent
    O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
    then you can click fix then look for and delete if there. npkcsvc.exe

    download vundofix from HERE
    download VirtumundoBegone from HERE
  4. gian0819

    gian0819 TS Rookie Topic Starter

    i tried running vundofix and virtumundobegone but both found nothing.

    how do i stop the service? should i use hjt to fix it?
  5. tomrca

    tomrca TS Rookie Posts: 1,000

    control panel/performance and maintenance/admin tools/services, right click and disable. you can also get information on the programme and any other software that depends on it., probably none!
  6. gian0819

    gian0819 TS Rookie Topic Starter

    ok, i still don't get how to stop the said service. sorry. avast alerted me that i am infected now with a different trojan. something called win32.tratbho. waaahh. i still did nothing to my pc
  7. gian0819

    gian0819 TS Rookie Topic Starter

    i found the services in the admin tools. i looked for npkcsvc and found out that it is already stopped. what should i do next
  8. tomrca

    tomrca TS Rookie Posts: 1,000

    follow the path delete what is in bold C:\WINDOWS\system32\npkcsvc.exe
    download COMBOFIX to desktop. do not run any other programmes. do not click mouse while it is running. then post log and new hjt log
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...