PDA

View Full Version : Virtumonde family...



Kramer
2009-02-21, 17:23
Hi there,
I'm pretty new at this... I know there are other threads about Virtumonde, but I don't really understand them...here's my situation:
Spybot-SD updated version (162), upon scanning my laptop, does spend quite some time on all three of these: Virtumonde.sci, Virtumonde.sdn and Virtumonde.dll, but doesn't mention them as threats at the end. I also ran Mcafee, Superantispyware and VundoFix, and none of them found it (as far as I can tell, couldn't stay awake until completion of VundoFix...).
Intrigued by the name, I looked it up and saw that it is a rather common (yet vicious) issue. I have tried a recommended method to get rid of the bugger, to no avail (scan with several programs in safe mode, all in the same Window session...). The three Virtumonde "files" still appear during Spybot scan.
Now I don't get pop ups when surfing, neither do I get prompted to buy all sorts of spyware programs, as I saw many people do (those seem to be the common symptoms). I don't use IE, I use Chrome, does that change anything?
The symptom I do get is that my laptop is painfully slow at times, much more so than it ever was.
No matter what I tried on my own, there's no getting rid of the Virtumonde stuff, and as I read pretty much everywhere that it is one nasty thing, I need help!!!
Any advice would be greatly appreciated. I'm more than willing to go through any necessary process, as long as it proves efficient!
Thanks a lot to you guys out there taking time out of your days to help us novices out...

Matt
2009-02-21, 17:37
Hi Kramer,

if Spybot doesn't mention Virtumonde in red color at the end, then you could be free of Virtumonde. ;) So be happy. :)

Under the green scan bar, Spybot only shows you, for what kind of Malware it is searching. Virtumonde changes every week, so there are lots of detection rules.

If Spybot really finds Virtumonde on your computer and you tried to fix them and it doesn't work, please read the thread "BEFORE you POST" (http://forums.spybot.info/showthread.php?t=288) from tashi and after that open a new thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22).

A security expert can help you there. ;)

Best regards,
-Matt-

Kramer
2009-02-21, 17:49
Hi Matt,

Thanks for your prompt response, was just checking out of curiosity before taking the kids to the park, didn't really expect an answer that soon...wow, so forums do work, huh!
I was wondering if what I was seeing under the green scan bar was actually in my comp. or if it was, as you just confirmed, what spybot was actually looking for. Great, so this could mean I'm not infected after all!
Just for confirmation purposes, is the fact that I'm not getting pop ups and anti spyware purchase prompts a sure sign that I'm not infected?
Sorry I seem to be freaking out on this but I'm also using my laptop for work purposes and can't really afford to having it crash and burn...

Thanks again, Matt, have a great day!

Kramer

PS: Incidentally, any advice on how to check why it is getting so slow recently?...

Matt
2009-02-21, 19:05
Hi Kramer,

please read this thread. Perhaps you can find an answer there:
http://forums.spybot.info/showthread.php?t=45374

Best regards,
-Matt-

Kramer
2009-02-21, 20:12
Thxs Matt, will maybe try some or all of the stuff these guys talk about!

Thxs again, take care.

Kramer