Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Virtumonde
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Virtumonde
after i run adaware and spybot(my 2 usuals) it usually finds and gets rid of virtumonde. it keeps coming back though. and lately something else has been popping up. when i try to look at mypictures, dr watson(i believe) shuts it down and then my desktop blinks and a message window at top left comes up. it comes and goes so fast that all i can see is 'personalized settings' at the top and c:
recycler............and a bunch of other characters. ive tried deleting c:\recycler to get rid of contents(from what i understand it'll come back after reboot) but still have same problem. just checked and still does it after everything i did as you instructed. wasnt able to do online scan. something about siging up for something. i hope you can help. and any help you give will be greatly appreciated |
|
#2
|
|||
|
|||
|
I suggest that you repeat the Malware Removal procedures.
Combofix.log appears to be incomplete. System Restore archive shows past infection with Purity. HJT analysis courtesy of Castlecops gives conflicting info for "MSCONFIG.EXE" from the program files/pchealth. MSCONFIG.EXE (pchealt) is on the startup list. I consider this usage suspect. Dr. Watson being invoked as you describe does not sound reasonable. Suspicious. One strain of Purity adds /Windows/??system32 directory. Windows Explorer lists this directory before the legit copy of 'system32'. '??system32' filename contains non-printing characters. Command prompt > dir c:\windows\*system32* > analyze results Purity malware could have impacted the wbem directory, as well. I believe that the removal of the infection by my AV protection made a bad decision and quarantined the legit copy of the directory. I'll never know since this was over a year in the past. |
|
|
|
#3
|
||||
|
||||
|
Actually the combofix log will always cut off if it is too long - by design
and the legit msconfig file has been moved to a bak folder and replaced with a malicious file Did you run Smitfraudfix? If so attach rapport.txt If not, Run Smitfraudfix
====================================== FindAWF Click here to download FindAWF.exe and save it to your desktop.
Attach Here: 1)C:\rapport.txt 2)AWF.txt |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Help cant get rid of Trojan Virtumonde | Virus & Malware removal | 5 | 09-01-2008 08:48 AM | |
| Virtumonde infection | Virus & Malware removal | 2 | 08-11-2008 01:51 PM | |
| Recurring virtumonde | Virus & Malware removal | 9 | 08-09-2008 03:56 PM | |
| 'Virtumonde' Virus | Virus & Malware removal | 2 | 06-26-2008 04:13 PM | |
| Darksma & virtumonde help | Virus & Malware removal | 1 | 04-25-2008 09:17 PM | |
All times are GMT -4. The time now is 11:24 AM.



Run Smitfraudfix