PDA

View Full Version : Virtumonde might be my issue



Bubbain66
2009-05-18, 01:42
I did a scan of my system with spybot and it found 49 problems labeled Virtumonde. i clicked fix problems, and widows came up saying it was going to shut down and it had a counter that when hit zero tried to restart the pc. it did say problems were fixed before it shut down. Now every time i try to start my pc, it gets to a certain point and shuts down then tries to restart. it continually does this but never really boots. i am now on another pc because i cant boot that one. any help would be great!!!! oh and the reason windows said it was shutting down had somthing to do with windows32 file. i also was having virtual memory problems just prioe to this happening.

ken545
2009-05-19, 01:26
Hello Bubbain66

Welcome to Safer Networking.

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
That said, All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.

Try booting up your computer in Safemode with Networking

Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Safemode with Networking
Then press the Enter Key on your Keyboard

Tutorial if you need it How to boot into Safemode (http://www.bleepingcomputer.com/tutorials/tutorial61.html)


While in Safemode, run this program.

Please download Malwarebytes' Anti-Malware from Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) or Here (http://www.besttechie.net/tools/mbam-setup.exe)

Double Click mbam-setup.exe to install the application.

Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.<-- Don't forget this
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and Paste the entire report in your next reply.

Bubbain66
2009-05-19, 22:39
when i try to boot in safe mode with networking, the same thing happens, i am able to choose the startup, then it runs many sys32 drivers then the screen goes blank as if its going to the next step but it shuts down and tries to start again. i do have malwarebyts already on my system.

ken545
2009-05-19, 23:19
Try this, if it doesn't work do you have your windows XP disk?


Go to Start> Shut off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to Last Known Good
Then press the Enter Key on your Keyboard

Bubbain66
2009-05-20, 03:16
This did not work, it seems to fail at the same point. yes i have yes i have my windows xp disc.

ken545
2009-05-20, 04:00
What I would like you to do is go to this forum , like Safer Networking , its free. Tell them that you have your windows CD and your computer won't start, they can run you through a windows repair to get you up and running, then post back here when you can with a Hikackthis log and we can see if any malware is still present.

Windows Helpnet (http://www.windowsbbs.com/)


Download Trendmicros Hijackthis (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe) to your desktop.

Double click it to install
Follow the prompts and by default it will install in C:\Program Files\Trendmicro\Hijackthis\Highjackthis.exe
Open HJT Scan and Save a Log File, it will open in Notepad
Go to Format and make sure Wordwrap is Unchecked
Go to Edit> Select All.....Edit > Copy and Paste the new log into this thread by using the Submit Reply and not start a New Thread.

DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

Bubbain66
2009-05-21, 03:36
I will do that, and ill get back if it goes well. thank you for your time
jim

ken545
2009-06-03, 14:20
If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a new HijackThis log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.