Virtumonde effects still present

Discussion in 'Malware Help (A Specialist Will Reply)' started by RichC, Apr 11, 2010.

  1. RichC

    RichC Private E-2

    Part One

    SpyBot found Virtumonde.sdn and said it had been removed, but the effects continued. At this point, I only see it affecting Internet access--specifically downloading pages. Three types of problems occur: some pages are prevented from loading at all (e.g., hotmail); some pages load partially (it looks like some graphics don't download); and some pages seem to load fine. In some cases, repeating hitting reload will cause the page to finally load; when pages do load okay, however, I usually can't click through links to other pages.

    I followed the steps to remove Virtumonde.sdn as describe in this forum. It seemed to work--pages loaded normally and no other effects were observed. But the problem gradually reappeared over a day or two.

    I reran all the programs, but this time, it didn't seem to help at all. I have attached the logs to this message and the next.

    Thanks for your help.
     

    Attached Files:

  2. RichC

    RichC Private E-2

    Part Two--the final log file is attached. (MGlogs.zip)

    Thanks.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs. However, why are these here:
    c:\temp\Repair
    c:\temp\CC Cleaner
    c:\temp\SpyBot
    C:\Temp\Malwarebytes

    That is not the place to be running them from.
     
  4. RichC

    RichC Private E-2

    I created the c\temp folder to hold the apps that I downloaded. They're not installed there, I used the default directory setting when I installed each one of them. But do you think that just having the installation files in that directory affected the way they ran? And whether they were successful at finding/fixing the problem?

    Thanks for your help.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If those are just the install files, there shouldn't be a problem. If you want to keep them for some reason, move them all into a folder.

    Are you still being re-directed? Does it happen with all browsers? What other issues are you having?
     
  6. RichC

    RichC Private E-2

    I'm still having the same problems--and all appear to be browser related--sites won't load at all or load partially (& slowly). I've tried Firefox and IE 8--if anything, it seems to be a little worse with Firefox. The only other manifestation that I've seen is when my AV (AVG) tries to download updates, the transfer speed just keeps dropping until it's near zero and the update craps out. Other than that, I really haven't seen any other evidence...

    Again, thanks for your help.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  8. RichC

    RichC Private E-2

    Hi--

    Ran GMER as directed, the log file is attached.

    Thanks.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That log was clean. This is sounding like an issue with your ISP. Have you talked to them about your internet speeds? Have you done any speed tests? I suggest you try doing one HERE.
     
  10. RichC

    RichC Private E-2

    Hi again--
    Don't think it's an ISP problem--we have 3 other PCs (and an iPod Touch) using the same connection. I tested it on SpeakEasy as you suggested and downloads were 4MB-12MB, uploads ~2.5MB.

    Could it be hardware? The wifi radio?

    Thanks--
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried connecting directly to the router? Does that make a difference?
     
  12. RichC

    RichC Private E-2

    Yes, I had tried direct cabling to the router, but that didn't help. I also shut off the internal WiFi and tried and external WiFi adapter (USB), and I downloaded and reinstalled the WiFi drivers. No luck...

    It's still strange--some pages load, others don't, and it seems to get worse the more I try. When I ping the same sites I've tried to load, it's also intermittent--sometimes it pings okay (and quickly) and other times it just times out.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This sounds like a hardware issue. Or one with your ISP. You can try doing a test by doing a longer test by typing a -t at the end of the test ( there is a space after the ping address). Control + C to stop it.

    Ex: ping www.majorgeeks.com -t
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try a temporary shutdown of AVG and also ZoneAlarm and see if your problem goes away.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds