PDA

View Full Version : Product: Virtumonde



dagger666
2007-07-26, 21:42
Company:
Product: Virtumonde
Threat: Trojan
Description
Virtumonde copies itself to the system folder and creates a BHO. Virtumonde connects to malicious websites in background. It also adds a randomly named dll to the Winlogon Notify, which will make it very resistable to removal. If you need help with removal please contact Team Spybot S&D via forums or email

Spybot found this and deleted it from the registry i guess, now what it seams nasty

dagger666
2007-07-26, 21:56
Sorry but i guess i should have included this;
AOL Antivirus by Kaspersky
Spybot Search & destory
Comodo Pro Firewall
Spyware Blaster
Ad-Aware SE
CCleaner

md usa spybot fan
2007-07-26, 22:29
I'm sorry but I'm having difficulty interpreting the intent of your post.


Spybot found this and deleted it from the registry i guess, now what it seams nasty
Are you indicating that Spybot-S&D: Found and corrected your problem although the software that you mentioned in your second post did not.

---or that ---


There is still a problem and Spybot-S&D as well as the software list have not corrected the problem.

dagger666
2007-07-27, 13:00
and i have AVG Anit-rootkit. Spybot did deleted it but it reads as that this does more than just put a key in the register. I figured you would like to know all the protection i have on my system because it might help prevent it from spreading. What is this about copying it's self to other folders "It also adds a randomly named dll to the Winlogon Notify, which will make it very resistable to removal" so do i need to concern myself with this or has spy bot taken care of it with the 1 register key it deleted?

dagger666
2007-07-27, 13:18
Process Library.com Is this site safe and all its scanners? Also a took a look at Spy bot System startup and disabled some things it said were not needed and so far everything is fine. it did find this "Filename: System32.exe Added by AGOBOT-UK WORM! And has been blocked. Who is Paul Collins Startup list?

md usa spybot fan
2007-07-30, 22:11
dagger666:

I sorry but I still can't help you because I still don't understand what the specific nature of your inquiry or problem. I stated


I'm sorry but I'm having difficulty interpreting the intent of your post.
I then asked a question that I though would help me understand the nature of your problem or inquiry by limiting the response to two alternatives:


Are you indicating that Spybot-S&D: Found and corrected your problem although the software that you mentioned in your second post did not.

---or that ---


There is still a problem and Spybot-S&D as well as the software list have not corrected the problem.
In response you state:


and i have AVG Anit-rootkit. Spybot did deleted it but it reads as that this does more than just put a key in the register. … so do i need to concern myself with this or has spy bot taken care of it with the 1 register key it deleted?
And then posted again concerning other products/informational lists:


Process Library.com Is this site safe and all its scanners? … Who is Paul Collins Startup list?
If you still need help with this particular problem, you could start by answering my initial question. Or better yet if you actually still have a problem, you could post the actual logs (Checks.yymmdd-hhmm.log and/or Fixes.yymmdd-hhmm.log) of the Spybot detections that you received and were/were not able to corrected during the Spybot "Check for problems"/"Fix selected problems".

In the mean time, I'll assume that you no longer require help with this particular query because of you're new post:
How can i Fix this
http://forums.spybot.info/showthread.php?t=16462