PDA

View Full Version : Vundo infection or Not?



lesjackos
2009-03-28, 12:25
I have been using SSD 1.5 for some time and that had reported Virtumonde infection (SBI$92386332 Library/.../zipfldr.dll).

SSD would not remove and reported "Unexpected error in fixing problems (cannot create file c:\windows\winnit.ini. Access is denied)" and this still occurred if run as administrator.

Employed Supportspace expert and he used Combofix, Malwarebytes and other things. SSD then reported clean result but next day the problem was back exactly as before (much as webposts predict it will).

Then upgraded to SSD 1.6 recently and this enabled full immunisation to load (under 1.5 would load immunisation for only a small % of the 91,000+ potential threats).

Now the SSD check does not reveal Virtumonde any more yet I have not taken any further action to remove it?

Shall be grateful for advice on whether I have the malware and / or how to check. NB: pretty basic PC knowledge only.

Thanks

drragostea
2009-03-28, 19:50
If Spybot-Search&Destroy gives a green check mark then your clean (according to Spybot). But I would suggest you run an addition anti-virus/spyware check. I would usually run an anti-virus scan every 2-4 weeks (I don't bother scanning every week, since I'm well aware of what goes on in my PC) and an anti-spyware scan every 1-2 weeks or so.

lesjackos
2009-03-29, 22:53
Thanks.

I have run several Virus checkers and they are all clean.

The bit that is puzzling me is why it went away or, more precisely, IF it has gone away...

Matt
2009-03-29, 23:03
Hi lesjackos,


I have been using SSD 1.5 for some time and that had reported Virtumonde infection (SBI$92386332 Library/.../zipfldr.dll).

This is a false positive from Spybot 1.5. As you already said, an upgrade to Spybot 1.6.2 fixes this problem. :)

Please be sure that you have always installed the newest version of Spybot. ;)

lesjackos
2009-04-02, 20:01
Thank you both for replying