Virtumonde Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by breadcrumb, Mar 20, 2010.

  1. breadcrumb

    breadcrumb Private E-2

    I have followed the READ & RUN ME FIRST but after running Spybot Search & Destroy again, it still picks up the Virtumonde along with Zlob.

    My browser has been experiencing certain lag spikes and my start up and shut down are quite slow.

    I mainly use AVG 9 Free Edition and Spybot S&D, I hope I can get some help.
     

    Attached Files:

  2. breadcrumb

    breadcrumb Private E-2

    The last text file...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will need to tell me exactly what is being reported as I am not seeing any malware in your logs. I need the exact path. Attach a log if you have it.
     
  4. breadcrumb

    breadcrumb Private E-2

    I'm not quite sure what you mean by "exact path" but when I run Spybot S&D it picks up Virtumonde on it. I just want to make sure my computer is clean of any types of malware or viruses...I'm sorry if I'm not helping much with this.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Exact path would be something like:
    C:\Windows\system32\amdpcom32.dll
    or
    C:\Users\%username%\Desktop\D.lnk

    The program should give you a way to save the log which should show what the infected file (s) are. Or you can copy and paste them into notepad and attach that to your next reply.
     
  6. breadcrumb

    breadcrumb Private E-2

    I have checked the logs for my Spybot Search&Destroy, sadly it didn't list anything that would be useful. While I let Spybot scan, I'm able to see it list Virtumonde on it but after it finishes the scan, no threats are found at all. So, I'm getting a bit worried with this.

    I'll attach the log, though it will probably provide no extra help...
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How do you know it is reporting Virtumonde? Yes, the log is clean as were your other logs. So what is being reported that you are "seeing" while it runs?
     
  8. breadcrumb

    breadcrumb Private E-2

    It shows Virtumonde.dll, Virtumonde.sdn, Virutumonde.sci and other ads I'm assuming. When I gotten SpybotS&D, it usually scanned about 300,000 items but now it's over 800,000 items being scanned.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you sure those are not files that it is protecting you from? Virtumonde.dll, Virtumonde.sdn, Virutumonde.sci means nothing unless it gives you a "path" to the file in question. The name itself means nothing.
     
  10. breadcrumb

    breadcrumb Private E-2

    Is that so? I'm still pretty new to all of these antivirus programs, I always assumed that the names it listed were the items found on my computer. But if that is the case, then I suppose my computer is free of any problems for now?

    Thank you for taking your time with helping me.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you are malware free. For some educational assistance, I suggest you post in the software forum for any questions you have regarding that program. They will be more than happy to answer any questions you may have.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds