PDA

View Full Version : Virtumonde



Jim_in_Germany
2008-01-07, 16:11
Hi,
I updated Spybot Search and Destroy today and ran a scan. Unfortunately Spybot is finding an instance of the Trojan "Virtumonde" in my Firefox and Opera default bookmarks!

Virtumonde: [SBI $61F39AC8] Lesezeichen (Firefox: default)

Therefore I decided to use one of the backups of my C: partition I had made with Acronis TrueImage.
However, when I had restored my Windows to an earlier state (and updated Spybot), the trojan was still there!
I then took the first image I had made of my C partition (ca. 1 week after installing the computer). Spybot still finds Virtumonde!!

I tried downloading the Virtumonde fix from the Major Geeks website but it didn't find the Virtumonde trojan on my machine.
Do I have this trojan? Have I had this trojan all along? I haven't noticed a drop in performance or any other indication and am normally very security conscious.

Could somebody please give me some advice as to what to do. Many thanks in advance.

Jim_in_Germany
2008-01-07, 16:14
P.S. Suffice to say, I tried to get Spybot to fix the problem, which it did. When I scanned again, it found nothing. After that I was surfing with Firefox for 20 minutes, scanned again and the same entry was there (the one from Opera had disappeared, but I presume it will return if i open Opera).

tashi
2008-01-07, 18:55
Hello.

This is the malware removal forum and the procedure is here: "BEFORE you POST"(READ this Procedure before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Questions regarding Spybot-S&D support can be asked in the Spybot-S&D Forums (http://forums.spybot.info/forumdisplay.php?f=4) :)

In the event of a possible false positive please see:

False Positives Forum (http://forums.spybot.info/forumdisplay.php?f=16)

How to report False Positives (http://forums.spybot.info/showthread.php?t=19117)

Best regards.

Jim_in_Germany
2008-01-08, 21:32
Hi tashi,
Thanks for your reply.
I had hoped for a little more constructive help and not just a series of links to follow. I also found the "Read before posting link" a little confusing.
Anyway, I did everything advised in the link and found no traces of Virtumonde. It is most likely a false positive.
However, call me paranoid, but to be on the safe side I have decided to format my harddrive reinstall everything anyway (yipee).
All the best.
Jim

tashi
2008-01-08, 21:59
Hello.


I had hoped for a little more constructive help and not just a series of links to follow.
Each forum has a different purpose and the malware forum volunteer helpers only work this particular forum. Therefore as you posted here, I gave you the procedure link in order for you to produce a log and receive assistance.

Ditto links to the other forums, in case upon reflection, you decided you had posted in the wrong one.



Anyway, I did everything advised in the link and found no traces of Virtumonde. It is most likely a false positive.
However, call me paranoid, but to be on the safe side I have decided to format my harddrive reinstall everything anyway (yipee).
All the best.
Jim

Seems rather drastic for what could prove to be a false positive but it's your machine.

Best wishes. :)