BleepingComputer.com: Possible Kraken Bobax - Trend Micro RuBotted reporting

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Possible Kraken Bobax - Trend Micro RuBotted reporting I am running RuBotted and got the above msg

#1 User is offline   99999jj 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 15-May 11

Posted 15 May 2011 - 09:33 AM

Hello, I am running a windows 7 professional 64bit operating system. My main security suite is Symantec Norton Internet Security 2011. I run RuBotted. I also scan with Superantispyware weekly, and Malwarebytes. In addition, I run the free version of Winpatrol. Today, I noticed RuBotted had alerted and it is showing "Possible Kraken Bobax" infection, and says Botnet Malware cannot be removed.

Any info on what to do would be appreciated.

JJ

#2 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 15 May 2011 - 09:40 AM

what does Super Anti-spyware and Malware Show, and I have never heard of RuBotted.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   99999jj 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 15-May 11

Posted 15 May 2011 - 09:45 AM

They only show what they usually do which is tracking cookies, then they eliminate them. Rubotted is here http://free.antivirus.com/rubotted/

#4 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 15 May 2011 - 09:58 AM

Can you post the rubotted log if it makes one?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#5 User is offline   99999jj 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 15-May 11

Posted 15 May 2011 - 12:31 PM

there is a really simple log which just says Possible Kraken Bobax - unable to remove. You can click on Possible Kraken Bobax which takes you to a Trend Micro web page called Threat Encyclopedia. In the treat encyclopedia it says that they cannot find any results for possible kraken bobax. It is puzzling how a Trend Micro product can alert to a possible bot, and then fail to know what the bot is or have any mention of the bot in their threat database.

#6 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 15 May 2011 - 06:17 PM

I would then consider it to be a false positive.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users