PDA

View Full Version : Virtumonde detect but I can't remove it



majestic100
2007-11-20, 22:41
*** Posted in S&D forum as well as not sure an S&D problem or genuine malware problem ******

Running S&D 1.5 (updated to fix slow opening)

Spybot continually detects the Trojan Virtumonde. Despite "select to fix problems", this always comes back !?!

The identified Registry Key is:-

HKLM\Software\Micrisoft\MSSMGR

I've run VonduFix and VirtuemondeBegone but to no avail. I also edited the registry and deleted the key, but this comes back. Trojan still being detected.

I've also run Ad-Aware, AVG Antispyware as well as Kaspersky and Panda on-line virus scanners and non of these products identify Virtumonde.

Is this a false positive?? Help Please

Shaba
2007-11-22, 10:15
Hi majestic100

Click here (http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe) to download HJTInstall.exe
Save HJTInstall.exe to your desktop.
Doubleclick on the HJTInstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\HijackThis .
Click on Install.
It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis.
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

Shaba
2007-11-29, 10:36
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.