PDA

View Full Version : Help Torpig Spyware



Arnaud92
2007-06-14, 22:38
Hi
I have a problem with my PC and unfortunately I didn't find any solution.
Spyboot identifies spywares called :

- Torpig : It generates 2 fils in windows/temp/$_2341233.TMP and $_2341234.TMP. But Spyboot didn't manage to delete the spyware (even after rebooting and scanning during the starting of the PC).
I am afraid because the description of the spyware is about bank account ...

- Virtumonde : same problem. Impossible to delete

I would be very helpful for me to have help and advices.
Thank you per advance
Arno

md usa spybot fan
2007-06-14, 23:22
Please post a log of the actual detections you that Spybot is detecting during a "Check for problems" but is not able to fix during that "Fix selected problems". To do that:
Run another scan ("Check for problems").
Do a "Fix selected problems".
Run another scan ("Check for problems")
When the the second scan completes, right click on the results list, select "Copy results to clipboard".
Then paste (Ctrl+V) those results to a new post in this thread.
Thanks

Arnaud92
2007-06-15, 20:35
Here find the result file.
Thank you for your help in advance.
Arnaud



-------------

Smitfraud-C.Toolbar888: Réglages (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-220523388-1682526488-1957994488-1003\Software\Microsoft\aldd

Smitfraud-C.Toolbar888: Réglages (Clé du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR

Torpig: Fichier temporaire (Fichier, nothing done)
C:\WINDOWS\Temp\$_2341234.TMP

Torpig: Fichier temporaire (Fichier, nothing done)
C:\WINDOWS\Temp\$_2341233.TMP

Virtumonde: Bibliothèque (Fichier, nothing done)
C:\WINDOWS\system32\nnlij.dll


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-06-13 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-06-13 Includes\Cookies.sbi (*)
2007-05-30 Includes\Dialer.sbi (*)
2007-06-13 Includes\DialerC.sbi (*)
2007-06-13 Includes\Hijackers.sbi (*)
2007-06-13 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-06-13 Includes\KeyloggersC.sbi (*)
2007-05-30 Includes\Malware.sbi (*)
2007-06-13 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-06-13 Includes\PUPSC.sbi (*)
2007-06-13 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-06-13 Includes\SecurityC.sbi (*)
2007-06-06 Includes\Spybots.sbi (*)
2007-06-13 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-05-16 Includes\Trojans.sbi (*)
2007-06-13 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll

md usa spybot fan
2007-06-15, 20:51
Consider posting in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and having someone take a look at your system. Follow the instructions here:
"BEFORE you POST"(READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
After completing those steps, start a new thread (topic) in the following forum (making sure to include the HijackThis log and online scan logs produced from the instructions above):
Malware Removal
http://forums.spybot.info/forumdisplay.php?f=22

tashi
2007-06-23, 10:05
steffi's post moved to the Malware removal forum:
http://forums.spybot.info/showthread.php?p=97569#post97569