Results 1 to 3 of 3

Thread: Virtumonde detect but I can't remove it

  1. #1
    Junior Member
    Join Date
    Nov 2006
    Posts
    4

    Default Virtumonde detect but I can't remove it

    *** Posted in S&D forum as well as not sure an S&D problem or genuine malware problem ******

    Running S&D 1.5 (updated to fix slow opening)

    Spybot continually detects the Trojan Virtumonde. Despite "select to fix problems", this always comes back !?!

    The identified Registry Key is:-

    HKLM\Software\Micrisoft\MSSMGR

    I've run VonduFix and VirtuemondeBegone but to no avail. I also edited the registry and deleted the key, but this comes back. Trojan still being detected.

    I've also run Ad-Aware, AVG Antispyware as well as Kaspersky and Panda on-line virus scanners and non of these products identify Virtumonde.

    Is this a false positive?? Help Please

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi majestic100

    Click here to download HJTInstall.exe
    • Save HJTInstall.exe to your desktop.
    • Doubleclick on the HJTInstall.exe icon on your desktop.
    • By default it will install to C:\Program Files\Trend Micro\HijackThis .
    • Click on Install.
    • It will create a HijackThis icon on the desktop.
    • Once installed, it will launch Hijackthis.
    • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Come back here to this thread and Paste the log in your next reply.
    • DO NOT use the AnalyseThis button, its findings are dangerous if misinterpreted.
    • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Due to the lack of feedback this Topic is closed.

    If you need this topic reopened, please request this by sending the moderating team
    a PM with the address of the thread. This applies only to the original topic starter.

    Everyone else please begin a New Topic.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •