PDA

View Full Version : Help with Virtumonde



gtalarico
2008-10-23, 22:11
Hello.
I have been trying to help a friend clean up her computer for over a week. When I first got the computer, it had no antivirus (at least at the time I got it), and everything was locked up (regeditor, task manager, add/remove programs etc)
I already cleaned lots of stuff out, but there is still something left... (Spy Sweeper always picks up Virtumunde when I scan)
The other two symptoms are pop up ads, and Automatic Update Service for Windows Update cannot be enabled (error 1058).
I have already read a lot about it, and used all the programs I know of :
Spybot-SD, Spy Sweeper, Ad-Aware, Malwarebytes, Avira Rootkit Detection, AVG Anti-Rootkit, and SUPER AntiSpyware.
I have also installed Zone Alarm, Avira Antivirus, and Spyware Blaster.

Here is the log, please let me know how to proceed.

Shaba
2008-10-24, 10:12
Hi gtalarico

Click here (http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe) to download HJTInstall.exe
Save HJTInstall.exe to your desktop.
Doubleclick on the HJTInstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\HijackThis .
Click on Install.
It will create a HijackThis icon on the desktop.
Once installed, it will launch Hijackthis.
Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
Come back here to this thread and Paste the log in your next reply.
DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

Shaba
2008-10-29, 10:51
Due to the lack of feedback this Topic is closed.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.