TechSpot

Recurring virtumonde

By KcL
Aug 8, 2008
  1. I have a Virtumonde virus which keeps coming back.

    I have tried Avast, Spybot - Search & destroy, spyware doctor, AD-aware, Spyware nuker, NOD 32 among other things to try to get rid og this bastard, but it just keeps coming back. Please help me.....

    attached is hijackthis log and log from something called virtumondoBeGone.

    Appreciate your help!
     
  2. CCT

    CCT TS Evangelist Posts: 3,556

    So, why haven't you just wiped the drive and re-installed?
     
  3. xxdanielxx

    xxdanielxx TS Rookie Posts: 1,214

    why would he do that, very bad recommendation he may want everything on the hdd or he may not want to go threw everything of reinstalling apps
     
  4. xxdanielxx

    xxdanielxx TS Rookie Posts: 1,214

    start by following the Malware removal instructions it is the red text in my sig then post the 3 logs here thanks. My name is xxdanielxx I will be helping you clear your system of infections
     
  5. CCT

    CCT TS Evangelist Posts: 3,556

    'why would he do that, very bad recommendation he may want everything on the hdd or he may not want to go threw everything of reinstalling apps'

    Hey - it is MY advice. If he doesn't like it after all his attempts then he can decide.

    Stick to providing advice, not critique on mine.

    Thanks.

    :)
     
  6. xxdanielxx

    xxdanielxx TS Rookie Posts: 1,214

    not critique on mine.

    no one is it is just bad advice
     
  7. CCT

    CCT TS Evangelist Posts: 3,556

    Listen,, advice is to say 'Do this or that!" I asked (ASKED????) why he hadn't done a reinstall.

    That is a question - you get the difference?


    Now - leave my posts alone!
     
  8. xxdanielxx

    xxdanielxx TS Rookie Posts: 1,214

    I am not going to argue over something dumb
     
  9. KcL

    KcL TS Rookie Topic Starter

    Okay. Followed all the steps, and here's the logs.......
     
  10. xxdanielxx

    xxdanielxx TS Rookie Posts: 1,214

    run hijackthis and place a check next to the items below

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - F:\Player\__CDS2.dll (file missing)

    run MBAM it is the blue text in my sig make sure to update it then run a full scan in safe mode

    Double Click mbam-setup.exe to install the application.
    Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    If an update is found, it will download and install the latest version.
    Once the program has loaded, select "Perform Full Scan", then click Scan.
    The scan may take some time to finish,so please be patient.
    When the scan is complete, click OK, then Show Results to view the results.
    Make sure that everything is checked, and click Remove Selected.
    When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    Copy&Paste the entire report in your next reply.
    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.