PDA

View Full Version : VIRTUMONDE Infected - Help Appreciated!!!



Najkiie
2008-06-24, 13:32
Hey. First i just wan't to say that ive been reading the other posts about Virtumonde and i didnt know if i should post my quest there or if i should create a new one... Anyways.

ALL MY INFO:
**********
Well, the pc just started to slower and slower and at the end i restarted the computer to SafeMode and scanned it with Ad-Aware and Spy-Bot. Both of them detected 1 infection! Virtumonde. It was located in:

HKEY_USERS > S-1-5-21-472136900-3222424326-2930229843-1000 > Software > Microsoft > contim

i looked for it in the Registry editor (i didnt remove or change anything)!

I totally belived that the virus was gone after those scans. but after a normal reboot it showed up again in the same place as before (i scanned with spybot again).

Then i strated to be alittle scared of that crap! so i started googling abit and i found some programs that was only for removing this virus, here's some of them:

FxV Monde
VundoFix v6.5.10
I also found another program with the same name "VundoFix"

I scanned the pc with those scanners to (in safe mode) and both of them came up CLEAN!!!! and i really couldnt belive my eyes! What kinda removed virus is this?


And thats pretty much all i know! ow, aight.. i read the other posts and i saw that u recommended them to download "ComboFix" and scan the pc.
i did as you guys told me to, and here's the log!

http://www.speedyshare.com/939333364.html<<-The log
When you press download. It will come up a new window with the log.
so, you won't be downloading it!!!



Please respond with some good news! -Najkiie
You can also reach me through my hotmail adress if you need to!:

(data_freak_93@hotmail.com)

Najkiie
2008-06-24, 14:12
I just wanted to say, I'm using

Windows Vista Ultimate SP1 32-bit

if you needed to know that for some reason

and i posted 2 the same post abowe... rread the second one. Couse i just edited the fist one... i forgot to say a thing...

Najkiie
2008-06-25, 21:46
I just want to say, TO LATE. ive been waiting for over 2 days now and i havnt got even 1 respond.

I do want to recommend everyone else to download and install the FULL version of Spyware Doctor from Pc Tools. That seems to be the only program that actually REMOVES the trojan.

thnx anyways!

tashi
2008-07-01, 08:21
Hello Najkiie,

Reading a forum's sticky topics before posting is always a good idea.

I just want to say, TO LATE. ive been waiting for over 2 days now and i havnt got even 1 respond.

This forum's helpers are all volunteers, and it is not a shop.

The Waiting Room: Post here if waiting for help longer than four days (http://forums.spybot.info/showthread.php?t=1137)



Hey. First i just wan't to say that ive been reading the other posts about Virtumonde and i didnt know if i should post my quest there or if i should create a new one... Anyways.


And thats pretty much all i know! ow, aight.. i read the other posts and i saw that u recommended them to download "ComboFix" and scan the pc.
i did as you guys told me to, and here's the log!

http://www.speedyshare.com/939333364.html<<-The log
When you press download. It will come up a new window with the log.
so, you won't be downloading it!!!

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

All logs should be copy/pasted into topic
Posting additional comments or logs before a volunteer responds, can push you back instead of forward, because your thread ends up with a newer date. Also, helpers may think you are already being assisted because of the post count.



ComboFix is not a general purpose cleaning tool, please do not use this tool without supervision.



Please note that all instructions given are customized for that member's computer only, the tools used may cause damage if run on a computer with different infections. Your symptoms may only appear to be similar.



Do NOT run 'fixes' before helpers have analyzed the HJT log (http://forums.spybot.info/showthread.php?t=16806)




You can also reach me through my hotmail adress if you need to!:


For your own safety and privacy, please do not post your email, personal address or phone number.http://forums.spybot.info/faq.php?faq=vb_faq#faq_signatures

Regards.