PDA

View Full Version : virtumonde ?



chercat
2008-10-01, 01:14
I ran Spybot today and got a message that I had been infected by Virtumonde . It seemed to fix it but then it appeared again after I ran Spybot again after clearing cookies,etc.

I disconnected from the Internet , rebooted and ran Spybot several more times and now it is coming up : " Congratulations - no immediate problems found". I am not having anything unusual happen - computer not slow , not redirecting me to strange sites, no pop ups , etc. , but when I went to shut down, a box appeared that said vgupbar.exe( not sure of spelling because it is now not in my task manager ) is closing. I am guessing this is something to do with the Virtumonde problem , but Spybot still says I am clean .

I can't find any info on vgupbar.exe and am hesitant to DL any program to clean the PC for fear it will do more harm than good as that happened with my old PC .

AVG AV says no threats found .

Did Spybot just find a way to get rid of virtumonde infections without using other apps now ?

I cannot figure out how I got infected as I had everything immunized and I did not DL anything .

Any info appreciated .

chercat
2008-10-01, 01:34
Now when I look in Control Panel ,there is something called InstallShield under an icon called Program Updates - I don't believe that was ever there before . When I tried to do a google search for that , I clicked on the link and was directed to other sites that di not give any info about InstallShield.

Is there a way to get rid of crap simply using System Restore to a prior date ?

I really do not want to play around in the Registry or install any other program to try to fix a mess and I have no clue how I got attacked .

AdAware , AVG and Spybot are now all coming up clean but that makes no sense .

chercat
2008-10-01, 17:19
I keep running Spybot and it says no threats are found , but I am pretty sure i am still infected with virtumonde .

The computer SEEMS ok , but I still have a suspicious vupgbura.exe on my task manager that I can find zero information about .

I think if I use Google , the virtumonde will show up again so I am staying away from there .

Is it possible to STILL have a virtumonde infection and Spybot will not detect that ?

I never DL'd Windows Malicious Software removal tool - if I am able to install that , can that get rid of virtumonde if it detects it ?

I do not download things on my computer because they always seem to make things worse , so I hesitate to even DL hijack this .
Does Spyware Blaster eliminate virtumonde - I have used that with success in the past on another PC .

Thanks for any advice .

chercat
2008-10-01, 17:32
Ok,even though Spybot , AdAware and AVG all think I am clean , when I just shut down the computer , I got a box that says VUPGBURA.EXE is closing an I hit end now so that is apparently what is controlling my computer .

I can find nothing about it with any search including Microsoft.

chercat
2008-10-01, 18:19
Ok,even though Spybot , AdAware and AVG all think I am clean , when I just shut down the computer , I got a box that says VUPGBURA.EXE is closing an I hit end now so that is apparently what is controlling my computer .

I can find nothing about it with any search including Microsoft.

In addition , when I use any search like Yahoo or Comcast search instead of google for any info like Trend Micro or Kapersky, I was redirected to bogus sites . Finally ,I got to kapersky and Trend house call , but I got kicked off Trend and Kapersky wanted me to run the latest version of Java which I was hesitant to do .

Blade81
2008-10-05, 13:38
Continues here (http://forums.spybot.info/showthread.php?t=34855).