PDA

View Full Version : Virtumonde



mcoan503
2008-09-18, 02:30
Company:
Product: Virtumonde
Threat: Trojan


Description
Virtumonde copies itself to the system folder and creates a BHO. Virtumonde connects to malicious websites in background. It also adds a randomly named dll to the Winlogon Notify, which will make it very resistable to removal. Removal requires the computer to be disconnected from the internet and restarted after first scan and fixing session. If you need help with removal please contact Team Spybot S&D via forums or email.

Hey guys, any help with this one?
I tried the the above

drragostea
2008-09-18, 02:34
mcoan,
Consider posting in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and having someone take a look at your system.

If you decide to have an experienced malware removal specialist assist you, please follow the procedure in this link to run scans and produce a HijackThis log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) ( http://forums.spybot.info/showthread.php?t=288).
-
Can you run Spybot-Search&Destroy (provided with the latest updates) in 'Safe Mode' and see if it can fix it? Try this first. If Virtumonde becomes a pain (persistence to remove), then you should start your own thread in the Malware Removal Forum.