PDA

View Full Version : Help, please. Return of virtumonde



Dryeyes
2008-06-12, 05:43
Good day, and thankyou for this forum.

I have run S+D in the past week many times to help rid zenosearch and virtumonde (s+d run offline). In only the last few scans zenosearch is gone but virtumonde remains. But wait...more wierdness ensues: It takes 3x as long to load firefox browser, and I now can't log into certain websites. Yahoo or Hotmail for instance.
Hotmail: entry page comes up, I enter name+password, then system says "waiting for hotmail'
Yahoo: page never even displays
Google: page comes up, I enter my search text in box, hit enter, then system waits forever
This is not a problem on pages without a form to fill out
AND If I happen to do a search querry from a search engine preinstalled on my browser window....It works! So I can't just go to kaspersky and run an online scan - cuz the scanner won't load. So now by eyes are buggy and I'm asking for help: HELP!!!!:eek: please

drragostea
2008-06-12, 05:48
Dryeyes, sorry to hear that :sad:. Virtuemonde can be persistent to remove. I'm suspecting there's more to that than Virtuemonde. Some other baddies disable the Kaspersky scan, and others disable searches to security sites. I'm not sure if the malware edited the HOSTS files.
--
Consider posting in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and having someone take a look at your system.

If you decide to have an experienced malware removal specialist assist you, please follow the procedure in this link to run scans and produce a HijackThis log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) ( http://forums.spybot.info/showthread.php?t=288).
--

Please take a brief look at BEFORE YOU POST thread and then run a Hijack log. Post the log with a fresh thread in the Malware Forums. All you need to know is in that BEFORE YOU POST link. Good luck.


Btw, has Spybot told you to reboot when attempted to remove Virtuemonde? Was it successful?

Dryeyes
2008-06-12, 16:50
Thanks for your reply! I'm very new to posting in any forum. It wasn't clear where I should post, since running spybot S+D discovered the problem, I posted here, not in 'malware unrelated to spybot'. Thanks for your valuable time and for redirecting me.

and....yes I was prompted by spybot to reboot after running the scan offline....which I did...many times.

I'm borrowing a friend's iMac to download the hijack files as recommended + upload to my pc (xp)...since IE or Firefox 'hangs' with pages with forms on them.

I will switch to MALWARE REMOVAL forum to post my result.

thanks again

dryeyes

drragostea
2008-06-13, 00:40
I would suggest you visit the Malware Forums ASAP.

Perhaps removing Virtuemonde may speed up your connection. Also, FF and IE should work after that.