Results 1 to 4 of 4

Thread: Can't get rid off Virtumonde

  1. #1
    Junior Member
    Join Date
    Feb 2009
    Location
    Leesburg Florida
    Posts
    10

    Default Can't get rid off Virtumonde

    I've disconnected cable modem and have run Spybot 1.6.0 as well as 1.6.2. Both versions detect Virtumonde.sci in registry but upon Restart it's unable to fix as reported "Some problems couldn't be fixed; the reason could be that the associated files are still in use (in memory)....."

    I've responded YES to above message and spybot finishes with same message. What can I do to get rid of this Virus? What other info. do you need?

    I've noticed during SpyBot scan the following objects: (virumonde.sci, virumonde.sdn, virumonde.dll, virumonde.generic, and virumonde.prx).

    System details:
    Windows XP Home, Service Pack 1
    AdAware
    SpyBot
    Norton anti-virus


    PS I was running AdAware, SpyBot and Norton in preparation to upgrade to Service Pack 2.

    John S.
    Last edited by owlsr1; 2009-02-03 at 16:13.

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    owlsr1 (John S.):

    Consider posting in the Malware Removal forum and having someone take a look at your system.

    If you decide to have an experienced malware removal specialist assist you, please follow the procedure in the following link and produce a HijackThis log:
    After you have read and followed those instructions (excluding running a Spybot scan since it seems you can't), start your own thread in the Malware Removal forum, making sure to post the HijackThis log produced from those instructions.

    _____

    Quote Originally Posted by owlsr1 View Post
    System details:
    Windows XP Home, Service Pack 1
    One of the primary ways to prevent malware is to keep your system's software up to date. Windows XP systems should be at SP3.
    Last edited by md usa spybot fan; 2009-02-03 at 16:26.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Junior Member
    Join Date
    Feb 2009
    Location
    Leesburg Florida
    Posts
    10

    Default

    Quote Originally Posted by owlsr1 View Post
    I've disconnected cable modem and have run Spybot 1.6.0 as well as 1.6.2. Both versions detect Virtumonde.sci in registry but upon Restart it's unable to fix as reported "Some problems couldn't be fixed; the reason could be that the associated files are still in use (in memory)....."

    I've responded YES to above message and spybot finishes with same message. What can I do to get rid of this Virus? What other info. do you need?

    I've noticed during SpyBot scan the following objects: (virumonde.sci, virumonde.sdn, virumonde.dll, virumonde.generic, and virumonde.prx).

    System details:
    Windows XP Home, Service Pack 1
    AdAware
    SpyBot
    Norton anti-virus


    PS I was running AdAware, SpyBot and Norton in preparation to upgrade to Service Pack 2.

    John S.
    HJT:

    Logfile of Trend Micro HijackThis v2.0.2

    __________________________________

    Please post the log here: Malware Removal Forum

    Last edited by tashi; 2009-02-03 at 16:50. Reason: Removed HJT log, not to be posted in the Spybot-S&D forum. Added link

  4. #4
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    owlsr1 (John S.):

    You posted your HijackThis log in the wrong place!!!

    I suggested that you post in the Malware Removal forum.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •