PDA

View Full Version : Help with Virtumonde



moJo787
2009-01-12, 17:42
My computer has recently become infected with a number of viruses. After running a series of tests using Spybot S&D followed by my AVG virus scan, I was able to remove most of the infections.

When i run my AVG scan it says i have no threats, however if i run Spybot S&D it comes up with three TrojansC entries under the Virtumonde name. Here's what they show up as:

- (SBI $779C9C0D) Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP

- (SBI $FD08B4B7) Configuration File
C:\WINDOWS\system32\UDNVvyxx.ini2

- (SBI $2A2DCEAC) Configuration File
C:\WINDOWS\system32\UDNVvyxx.ini

If i run Spybot, it detects these three infections. When complete it says they have been fixed, but if i run the test again they still come up.

Any help would be gratefully appreciated. I'm not sure how to post the logs that i see others posting, otherwise i would copy and paste it here too.

Chris

katana
2009-01-17, 13:30
Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hello and welcome to the forums

My name is Katana and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:
Please Read All Instructions Carefully
If you don't understand something, stop and ask! Don't keep going on.
Please do not run any other tools or scans whilst I am helping you
Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)

If you can do those few things, everything should go smoothly http://www.countingcows.de/laechel.gif

Please Note, your security programs may give warnings for some of the tools I will ask you to use.
Be assured, any links I give are safe
----------------------------------------------------------------------------------------



Download and Run RSIT

Please download Random's System Information Tool by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open:

log.txt will be opened maximized.
info.txt will be opened minimized.

Please post the contents of both log.txt and info.txt.