PDA

View Full Version : Virtumonde questions



Kealan
2009-01-07, 16:57
Hello. My laptop was infected with Virtumonde, and I am currently waiting for a response in the Malware Removal forum on how to get rid of it, seeing as how McAfee is useless. Anyway, I have a few questions about it.

Firstly, I recieved an iPod Classic 6th gen, the 120gb one, for Christmas. Aside from putting hundreds of songs and podcasts on it that I already had on my old Zune 30, I bought well over $150 worth of stuff from the iTunes store. It recommended that I make a backup of the information in case something happened to my laptop, and as I do not own an external hard drive, I simply used my iPod as one and copied all my music to it a second time, via the My Computer menu. I do not know when I was infected, as the virus could have been dormant and/or controlled for a while before it began attacking in earnest, so I am wondering: Once I get it out of my computer, is it possible that there is some copy of it lurking in my iPod, that could possiby re-infect it once I connect it again? I apologize if this is a stupid question, I really don't know very much about these sort of things.

Also, I use FireFox, and have it save my passwords. However, I use CCleaner occasionally and it wipes out the saved passwords list, so I have to re-enter them. I used it when I first noticed problems due to Virtumonde, before I knew what it was. I then re-entered my passwords to several forums and my Yahoo e-mail address, the one I use for almost everything. Is it possible that Virtumonde noticed and stored these? Should I change them all?

One last thing: Is Avast! more effective than McAfee? I know it is less demanding on a computer, which is almost enough reason for me to switch already, since my laptop is fairly low-end. Although Spybot was unable to delete Virtumonde, McAfee can't even DETECT it, after numerous scans. I have several months of my subscription left, but I will gladly switch after the virus is gone if recommended to, since my laptop is slower than ever with it installed (I previously used Norton, but apparently that is pretty demanding as well).

Thanks in advance for the help. :D:

Tom.K
2009-01-07, 19:15
Once I get it out of my computer, is it possible that there is some copy of it lurking in my iPod, that could possiby re-infect it once I connect it again?

It's possible. Don't use any autoplay function when you insert it. Before opening removable drive (iPod), try to scan it for viruses.



Is it possible that Virtumonde noticed and stored these? Should I change them all?

It is possible and you should change them after making that the computer is clean again. If you create a new password and your computer is not clean yet, Virtumonde could get it and you have to get another password.



One last thing: Is Avast! more effective than McAfee?
Yes, and it's free (Avast Home Edition only) for use.

Kealan
2009-01-07, 20:25
It's possible. Don't use any autoplay function when you insert it. Before opening removable drive (iPod), try to scan it for viruses.


It is possible and you should change them after making that the computer is clean again. If you create a new password and your computer is not clean yet, Virtumonde could get it and you have to get another password.


Yes, and it's free (Avast Home Edition only) for use.

Thank you for the fast response. :) However, My antivirus, McAfee, can't even detect the virus on my computer normally, so I will just reformat it and put the stuff back on after I get the virus cleared up, I guess.

drragostea
2009-01-08, 00:44
Better safe than sorry, you should take no risk to leave the passwords as they are. I would suggest you change the most important ones such as bank accounts and login info to other important sites. Virtumonde doesn't tend to be a password trojan (but it's possible), but more a trojan that installs SmitFraud along with it and annoys the heck out of you with pop-ups.

In the past I've heard of malware infected USB flash drives so that everytime you plug it in, it might create a random folder in the flash drive itself. Of course malware can always manipulate flash drives and infect it, but I never heard of it infected iPods, because iPods are mainly hard drives and it has a large space capacity. The iPod works as a hard drive too, so it'll show up in My Computer.

I use CCleaner too v.2.15.815 but I've never heard of it deleting passwords after every cleaning. Unless... you ticked the Password option in 'Clear Private Data' in Mozilla Firefox. Last I checked, CCleaner doesn't have a clear password option.

I personally use avast! anti-virus, because it is light on system resources and effectively covers most of the system with it's Resident Shield. Right now, I wouldn't say McAfee is that bad, but I just don't like their business practices.

randomcthulu
2009-01-14, 12:17
Sorry to jump into your thread, but I can't get rid of this Virtumonde and something called Smitfraud-C. Both of these showed up about a week ago when I miss-typed a site name and got re-routed. Every time I run a scan they show up, then SpyBot offers to fix them, but they never go away. My comp is really starting to bog down and I don't even know where to start anymore.:sad:

Zenobia
2009-01-14, 14:04
randomcthulu,you could ask for help in the malware removal forum.

The instructions to follow are here:
http://forums.spybot.info/showthread.php?t=288

Malware removal:
http://forums.spybot.info/forumdisplay.php?f=22