PDA

View Full Version : virtumonde.sdn -- Removal Help



jidoulfo
2010-10-06, 04:06
Hi, I seem to have a problem with "virtumonde.sdn" and cant' get rid of it. Spybot has gotten rid of it twice over the past week and then scans come clean, and then after a reboot possibly or just a days wait, the scan comes back dirty again. The infection does not seem to serious, don't get me wrong, my computer has its bugs, but nothing too out-of-the-ordinary.

Here is the info from spybot:

Virtumonde.sdn: [SBI $0EDCFC3D] Library (File, nothing done)
C:\WINDOWS\system32\esozoniu.dll
Properties.size=319488
Properties.md5=03EE4E3BAC325B250FE314EAA981AD36
Properties.filedate=1175349918
Properties.filedatetext=2007-03-31 07:05:18


I have looked through a few other threads to see the method of fixing. I downloaded many of the tools recommended: ComboFix, OTL, DDS, and MalwareBytes. I am not going to attempt to remove it myself until I receive some support instructions, which I REALLY appreciate. :)

I am tempted to start posting logs from DDS and OTL, but I'll wait to see what gets asked for!

Thanks in advance for any help,
-J

tashi
2010-10-06, 05:50
Hello jidoulfo,

Please see the forum FAQ which also includes instructions on posting a preliminary DDS log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start a new topic, copy paste the DDS.txt log into it and a volunteer analyst will advise you when available. :)

Best regards.