Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19

Thread: Virtumonde help please...

  1. #11
    Security Expert-Emeritus steamwiz's Avatar
    Join Date
    Dec 2005
    Location
    Yorkshire. U.K.
    Posts
    1,313

    Default

    HI

    In the main.txt from DSS, it looks as though your Panda Internet Security 2008 is working ... but the extra.txt shows :-

    FW: Panda Internet Security 2008 v12.01.00 (Panda Security) Disabled
    AV: Panda Internet Security 2008 v12.01.00 (Panda Security) Disabled Outdated

    With the FW (firewall) disabled, you should at least have the windows firewall turned on. but ...

    Windows Internal Firewall is disabled.

    What's your position on this ? did you know that they were disabled & Outdated ?

    -
    I DO need a new report log from KASPERSKY ONLINE SCANNER ...

    The first scan you ran, completed in under 2 hours (01:53:55)

    I have seen scans take up to 12 hours to complete, but what you say is exceptional ...

    Let's clean a few areas of the computer out (which need cleaning anyway) & maybe it will allow the KASPERSKY scan to complete quicker ...

    -
    Please Download CCleaner from :-

    http://www.filehippo.com/download_ccleaner/ (click the download tab)

    During the installation be sure to UN-check the box for "Ccleaner Yahoo Toolbar" unless you want it.

    doubleclick the ccsetup.exe file and install the program...

    After installing, go to Start > programs > CCleaner > Options > Advanced > UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

    Make sure the "windows" tab is selected

    Under "internet explorer" tick...

    Temporary internet files
    Cookies* > see Note below
    History
    Recently typed URL's
    (leave this unticked if you DON'T want to clear the drop down list in the address window of IE)
    Delete index.dat files
    Last download location
    Autocomplete form history


    under "Windows explorer" these are optional, but you can safely tick them all if you wish, they are only "most recently used lists"

    Other explorer MRU's
    (leave this unticked if you DON'T want to clear lists such as the start\run list)

    under "System"

    Tick ALL these ...


    under "Advanced"

    no need to tick any of these (but you can if you want, and realise what they do)


    Applications tab...

    These will mostly clean out old log files for these applications...

    Clean:- (if you use them)

    Firefox/Mozilla (optional - leave the cookies - see note)
    Opera
    Sun Java
    ZoneAlarm

    ...
    Personally I clean everything in the applications tab... but you tick what you want...

    Note: *If there are any cookies you want to keep (if you remove the cookie for a site you require a password for, you will need to re-enter your password when you next visit that site) ... click options > cookies > then keep the cookies you want.

    click "analyse" if you want to see a list of what is going to be removed, before it is removed.

    Or

    click "run cleaner" to let it get on with it's work... clicking this will result in the following pop-up

    "This process will permanently delete files from your system. Are you sure you wish to proceed?"

    click OK.

    THEN ...

    This will clear all your infected restore points...

    Turn off (Disable) System Restore in XP :-

    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.
    Restart your computer.

    Then...

    Turn on (enable) System Restore :-

    Follow the same procedure, but this time uncheck Turn off System Restore

    if you have any problem with this... here's a link to instructions :-


    Disabling or enabling Windows XP System Restore >

    http://service1.symantec.com/SUPPORT...rc=sec_doc_nam

    THEN ...

    Run KASPERSKY again & post a new ONLINE SCANNER REPORT

    steam
    MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E

  2. #12
    Junior Member
    Join Date
    Jun 2008
    Location
    Greece
    Posts
    12

    Default

    Hi
    I didn't know if there was problem running Deckard's System Scanner and Panta antivirus (and firewall) at the same time so i closed Panta, then i open it again


    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7 REPORT
    Thursday, June 12, 2008
    Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, June 11, 2008 22:27:06
    Records in database: 853614
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\
    F:\

    Scan statistics:
    Files scanned: 106525
    Threat name: 8
    Infected objects: 12
    Suspicious objects: 1
    Duration of the scan: 13:59:54


    File name / Threat name / Threats count
    C:\Documents and Settings\gido\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.88439 Infected: Net-Worm.Win32.Kolab.ws 1
    C:\Documents and Settings\gido\Επιφάνεια εργασίας\DOWNLOADS\LimeWire-Pro-4.17.7.1\LimeWireWin 4.17.7.1.exe Infected: Trojan.Win32.Monder.gen 1
    C:\Documents and Settings\gido\Επιφάνεια εργασίας\sims2freetime\TS2_SP1[1].part1.rar Suspicious: Password-protected-EXE 1
    C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
    C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji 1
    C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\CLONECDv5.2.9.1\Slysoft.exe Infected: Backdoor.Win32.Hupigon.cdnk 1
    C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1
    C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji 1
    C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar Infected: not-a-virus:AdWare.Win32.Virtumonde.rji 1
    C:\QooBox\Quarantine\C\WINDOWS\system32\gktgiajq.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.rqz 1
    C:\QooBox\Quarantine\C\WINDOWS\system32\kxldceeu.dll.vir Infected: Trojan.Win32.Monder.gen 1
    C:\QooBox\Quarantine\C\WINDOWS\system32\qyiufbyx.dll.vir Infected: Trojan.Win32.Monder.gen 1
    C:\QooBox\Quarantine\C\WINDOWS\system32\sssnuvkw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.rkn 1

    The selected area was scanned.

    thanks

  3. #13
    Security Expert-Emeritus steamwiz's Avatar
    Join Date
    Dec 2005
    Location
    Yorkshire. U.K.
    Posts
    1,313

    Default

    Hi

    Thanks .. that explains the conflicting evidence about Panda being disabled... however not the Outdated ... have you got the latest updates or has your subscription run out ?

    Your first KASPERSKY ONLINE SCANNER REPORT showed :-

    Number of viruses found: 33
    Number of infected objects: 70

    & your last one :-

    Threat name: 8
    Infected objects: 12
    Suspicious objects: 1

    Much improved ...

    I mentioned in my first post about you downloading cracked files, and the consequences (them being infected) ...

    The following files are infected & YOU need to delete them :-

    1. C:\Documents and Settings\gido\Επιφάνεια εργασίας\DOWNLOADS\LimeWire-Pro-4.17.7.1\LimeWireWin 4.17.7.1.exe Infected: Trojan.Win32.Monder.gen 1

    2. C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1

    3. C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji 1

    4. C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\CLONECDv5.2.9.1\Slysoft.exe Infected: Backdoor.Win32.Hupigon.cdnk 1

    5. C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\Nero 9 ULTRA EDITION + SERIALS (FULL WORKING)\Nero 9 Ultra.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm 1

    6. C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack\setup\dldsetup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.rji 1

    7. C:\Documents and Settings\gido\Τα έγγραφά μου\TORRENT\torrent rest\RapidShare_Download_Direct pro + crack.rar Infected: not-a-virus:AdWare.Win32.Virtumonde.rji 1

    I could give you a script to drop into Combofix to delete them for you, but I am concerned about the Greek letters used in the path, in case it confuses Combofix ... so YOU will have to delete them manualy ...

    -

    THEN ...

    Double click the Malwarebytes Anti-Malware icon on your desktop, select the quarantine tab, and delete all.

    THEN ...

    Go to Start > Run > copy and paste ComboFix /u into the Open: box & press OK



    -
    This file is shown as Suspicious because it is a Password-protected-EXE

    C:\Documents and Settings\gido\Επιφάνεια εργασίας\sims2freetime\TS2_SP1[1].part1.rar Suspicious: Password-protected-EXE 1

    It may NOT be infected, can you vouch for it as being safe ? or is it another crack ?

    If you don't know, Please go here and upload this file ...

    C:\Documents and Settings\gido\Επιφάνεια εργασίας\sims2freetime\TS2_SP1[1].part1.rar

    http://www.virustotal.com/flash/index_en.html

    Click the browse button & browse to the file on your computer

    Post back the results ... right click on the page > select all

    right click again copy

    post the results in your next post here...

    After we know about this last file, we shall need one (hopefully) last KASPERSKY ONLINE SCANNER REPORT to confirm you are clean

    steam
    MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E

  4. #14
    Junior Member
    Join Date
    Jun 2008
    Location
    Greece
    Posts
    12

    Default

    Hi
    quess what!!! I was trying with kaspersky online scanner ,but i couldn't make it.
    i tryed many times but no result.
    Scaning run about 20-25% in 17 hours and twice when i came home my pc was disconected.Asking for user to login..!!? one of the scans at 21% kaspersky stoped to responde.
    Then i thought to download kaspersky trial version and scan my pc found Net-Worm.Win32.Kolab.ws only. But now when I'm trying online scan i get a blue screen...
    thanks

  5. #15
    Security Expert-Emeritus steamwiz's Avatar
    Join Date
    Dec 2005
    Location
    Yorkshire. U.K.
    Posts
    1,313

    Default

    HI

    Did you do EVERYTHING I said in my last post ? including :-

    Double click the Malwarebytes Anti-Malware icon on your desktop, select the quarantine tab, and delete all.

    The following file is in Malwarebytes Anti-Malware quarantine :-

    C:\Documents and Settings\gido\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.88439 Infected: Net-Worm.Win32.Kolab.ws 1

    That's what KASPERSKY found ...

    Please run Ccleaner again, same as before, then try the KASPERSKY online scanner again ...

    If it still wont run, try this scanner :-

    http://www.pandasoftware.com/products/activescan.htm

    1. click the Scan your PC button
    2. A new window will open...click the Check Now button
    3. Enter your Country
    4. Enter your State/Province
    5. Enter your e-mail address and click send
    6. Select either Home User or Company
    7. Click the big Scan Now button
    8. If it wants to install an ActiveX component allow it to...

    It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

    9. When download is complete, click on My Computer to start the scan

    When the scan completes, if anything malicious is detected...

    10. click the See Report button,
    11. then Save Report and save it to a convenient location.

    Post the ActiveScan report

    steam
    MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E

  6. #16
    Junior Member
    Join Date
    Jun 2008
    Location
    Greece
    Posts
    12

    Default

    Hi
    thanks a lot for the help but i must do format because i havn't sound i get an error 0xC00D11BA. i try but i can't do anything
    thanks

  7. #17
    Security Expert-Emeritus steamwiz's Avatar
    Join Date
    Dec 2005
    Location
    Yorkshire. U.K.
    Posts
    1,313

    Default

    HI

    If "no sound" is your only problem, then there may be no need for you to format ...

    Error ID = 0xC00D11BA ... no audio device (is this the error ?)

    This could be just that you need to reinstall the drivers for your sound card ..

    You may need to remove & re-seat the sound card (if it's removable) ... if this is the problem, then a reformat & reinstall wont help.

    check your device Manager (right-click My Computer > Manage > Device Manager > sound video & game controllers > look for any yellow question marks or yellow exclamation marks ...

    But this is not a malware issue, you would do better in a hardware forum, try here :-

    http://www.bleepingcomputer.com/forums/forum65.html

    Do please let me know how you get on ?

    steam
    MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E

  8. #18
    Junior Member
    Join Date
    Jun 2008
    Location
    Greece
    Posts
    12

    Default

    HI again
    I did everything i could for the sound problem i had (i've reinstal drivers many times) but no results. So, i did format and now it's ok. Thanks a lot for your help and advices you are the greatest .
    Thanks

  9. #19
    Security Expert-Emeritus steamwiz's Avatar
    Join Date
    Dec 2005
    Location
    Yorkshire. U.K.
    Posts
    1,313

    Default

    Hi

    Sometimes a format & reinstall is the only way to get everything working again the way you need it to, at least you now have a clean install "just like when it came out of the box"

    Remember to get all the latest Microsoft updates, update java & install all the security programs before you start surfing again

    Be sure to have a look here :-

    So how did I get infected in the first place? by TonyKlein

    http://forums.spybot.info/showthread.php?t=279

    Happy surfing

    steam
    MICROSOFT MVP - Security 2004/9 .member of ASAP since 2004 - member of U.N.I.T.E

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •