PDA

View Full Version : Virtumonde no longer detected but iexplore.exe on startup



callisti
2008-12-15, 13:50
Hello

Please can you help with this problem.

A recent spybot S&D scan on showed virtumonde and advised to fix while disconnected to internet. I attempted this and it seemed to work but now I find iexplore.exe running at startup hogging resources.

I have followed some of the other threads re virtumonde so am prepared that it could be a sticky problem. I can supply anti-malware and hjt logs as required.

callisti
2008-12-19, 16:20
I've attached the HJT, Anti-Malware log and Spybot process list log regarding this problem.

IEXPLORE.EXE seems to be running at start up as a thread from another process and is not being picked up by any of the scans ever since virtumonde first detection and fix by Spybot.

Should I use the recover function in Spybot to put the malware back and then try another removal strategy?

callisti
2008-12-20, 15:42
I decided to be pro-active on this matter and found superantispyware (http://www.superantispyware.com) picked up on Trojan.Dropper/Gen-123 which had infected registry keys and added some files.

Fixed using the software and on restart iexplore.exe no longer there. Thank goodness!

Note: was using spybot S&D, SpywareBlaster, AVG8, CCleaner, as my PC "health suite"

However, now also using Anti-Malware, HiJackThis, SuperAntiSpyware, Autoruns to add to range and depth of detection and information.

Also dabbled with PrevX, TrojanHunter, ATF Cleaner, VundoFix but these are not preferred choice for current situation so will archive.