Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Virtumonde Virus. Need help
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Virtumonde Virus. Need help
Hi Guys,
I'm new to this site and need some help with the virtumonde virus. I just did the "UPDATED 8-step Viruses/Spyware/Malware Preliminary Removal Instructions" by Julio and have attached the txt/log with this post. I only attached 2 (one .txt from Malwarebytes and a log from Hijackthis) because nothing came back on the SuperAntiSpyware scan. I'm wondering if I finally got rid of the virus 100%. I did a scan with Spybot and the Virtumonde did not show up but during the last few minutes of the scan I noticed that Spybot was scanning files in "Virtumonde.dll", Virtumonde.sci" and Virtumonde.sdn". Any advice for me on how to check if I got rid of the Virus would be awesome. Thanks, ~Alex~ |
|
#2
|
||||
|
||||
|
Vundofix
Hi :
As a Precaution, I recommend you run a scan from the FREE VundoFix, available at http://vundofix.atribune.org/ . |
|
|
|
#3
|
|||
|
|||
|
SpiritWind,
I ran VundoFix and nothing came back on the scan. /One of my close friend gave me this advice: "Virtumonde is a known ad program that spawns popup ads. However, don't worry about seeing those popup in Spybot - all it's doing is listing what it's -looking- for, not what it's found. It'll list its findings AFTER it's done with the scan." Nothing has been coming up in my scans. I think I'm ok? |
|
#4
|
|||
|
|||
|
Quote:
Since the scan with VundoFix came back clean, the steps above should be a confirming 'clean'. Optional if symptoms are still present
|
|
#5
|
|||
|
|||
|
Took your advice and 1 infection was detected with SAS:
[COLOR="Blue"]Adware.Vundo Variant HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad# SSODL[/COLOR] and 2 was detected with MBAM: [COLOR="Blue"]Trojan.Vundo.H Trojan.BHO[/COLOR] I have attached the findings as well as the HJT log. I get an error massage every time my computer start up (this module could not be found): [COLOR="Blue"]"Error Loading c:\windows\system32\vogujesi.dll"[/COLOR] Any advice from here? Last edited by kimsland; 12-07-2008 at 06:24 PM.. Reason: no need to quote the entire previous reply |
|
#6
|
|||
|
|||
|
Most surprising! Somewhat perplexing.
Overview of next steps
|
|
#7
|
|||
|
|||
|
Downloaded ComboFix and did all the steps. I attached the log from ComboFix and a new scan from HJT.
Please let me know where to go from here. Thx |
|
#8
|
|||
|
|||
|
Asianagentalex,
I think it’s time for another specialist to look at this problem. ComboFix and VundoFix agree with each other, but disagree with MBAM & SAS. Is your computer free of symptoms that you’ve observed? Are any of the protection programs loaded on your computer now complaining of anything? I have used ComboFix to decide things in the past. If you have no findings of an infection, other than MBAM & SAS, then I would not pursue this further. Please advise. Quote:
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Virtumonde? | Virus & Malware removal | 6 | 09-17-2008 02:17 AM | |
| Virtumonde | Virus & Malware removal | 2 | 09-11-2008 10:37 AM | |
| Virtumonde/privacyremover/every virus under the sun | Virus & Malware removal | 1 | 08-25-2008 11:39 AM | |
| 'Virtumonde' Virus | Virus & Malware removal | 2 | 06-26-2008 04:13 PM | |
| Need help finishing of virtumonde virus infection | Virus & Malware removal | 0 | 08-08-2007 01:45 PM | |
All times are GMT -4. The time now is 10:40 AM.



/