Results 1 to 8 of 8

Thread: Virtumonde Win98

  1. #1
    Senior Member alicez's Avatar
    Join Date
    Apr 2008
    Posts
    179

    Default Virtumonde Win98

    My elderly neighbor has run SB tonight and she told me it found one Problem. It states: Virtumonde - 1 entry Trojan.
    How would we go about helping her get it off of her old Vaio notebook which is using Win98?

    Thank you for your help. I'll tell her not to worry for now.

    Alice
    Vista also Win7 (64-Bit) IE 9; MSE; SpywareBlaster; MalwareBytes; SpyBot

  2. #2
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Hi alicez,

    which version of Spybot does she use?
    Isn't Spybot able to delete this entry?
    Best regards - Beste Grüße,

    Matt

  3. #3
    Senior Member alicez's Avatar
    Join Date
    Apr 2008
    Posts
    179

    Default

    Thank you.
    I went to see her this A.M. and she told me she clicked the "Fix It" and got the reply (something like) "Problem Fixed." Seems to have been easy to remove!
    Said she ran another scan and nothing found. She looked in the "Vault" and saw that 'virtumonde' was listed.

    I didn't think it would be that easy to remove after reading all the 'virtumonde' posts and the 'long' explanations that were listed regarding how to remove this 'trojan.' Maybe that is because those people had newer OS?

    (I believe she has the latest SB 162)

    So, there is nothing more she has to do?
    Should she leave that virtumonde in the "Vault?"
    Vista also Win7 (64-Bit) IE 9; MSE; SpywareBlaster; MalwareBytes; SpyBot

  4. #4
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Quote Originally Posted by alicez View Post
    I went to see her this A.M. and she told me she clicked the "Fix It" and got the reply (something like) "Problem Fixed." Seems to have been easy to remove!
    Said she ran another scan and nothing found.
    Sounds good to me.

    Quote Originally Posted by alicez View Post
    She looked in the "Vault" and saw that 'virtumonde' was listed.
    Quote Originally Posted by alicez View Post
    Should she leave that virtumonde in the "Vault?"
    Now you have to help me... my Engish isn't good enough. What does "vault" mean? The translation programs I use don't give me a good explanation... and the meanings of this word doesn't fit here

    Quote Originally Posted by alicez View Post
    So, there is nothing more she has to do?
    She could ran more AntiMalware tools.
    Well, the problem is that there aren't many tools which are still supporting Windows 98.

    If she thinks that she is still infected:
    http://forums.spybot.info/showpost.p...88&postcount=2

    Please keep me updated.
    Best regards - Beste Grüße,

    Matt

  5. #5
    Senior Member alicez's Avatar
    Join Date
    Apr 2008
    Posts
    179

    Default

    Thank you Matt.

    Went back to look at her notebook and the file is in the "Recovery" section. I should have said that originally.

    Should she leave that "virtumonde trojan" in there (Recovery section)? If not, how would she get rid of it?

    P.S. Your English is fine.
    Last edited by alicez; 2009-08-03 at 00:36.
    Vista also Win7 (64-Bit) IE 9; MSE; SpywareBlaster; MalwareBytes; SpyBot

  6. #6
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Quote Originally Posted by alicez View Post
    Should she leave that "virtumonde trojan" in there (Recovery section)? If not, how would she get rid of it?
    Well, that's a decision on her own... I would delete it (select the item(Virtumonde) and click "purge selected items")

    Well, it's a little bit strange that Spybot did only detect one file... perhaps a leaving which can be only detected with newer rules...

    Can you give me the path and filename(I want to eliminate the possibility that it is a false positive (FP) )?

    Quote Originally Posted by alicez View Post
    P.S. Your English is fine.
    Last edited by Matt; 2009-08-03 at 13:29.
    Best regards - Beste Grüße,

    Matt

  7. #7
    Senior Member alicez's Avatar
    Join Date
    Apr 2008
    Posts
    179

    Default

    Thank you.

    All that I can see is: C:\Windows\System\DOSFNT01.dll

    Is that what you wanted?
    Vista also Win7 (64-Bit) IE 9; MSE; SpywareBlaster; MalwareBytes; SpyBot

  8. #8
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Quote Originally Posted by alicez View Post
    All that I can see is: C:\Windows\System\DOSFNT01.dll

    Is that what you wanted?
    Well, it looks more like a false positive to me now. It could belong to Microsoft or a printer. Does she get error messages?

    To be really on the safe side, I would like you to report a possible FP here.

    More information:
    Infected Files. How To Submit. Please do not attach or link them here.

    If you decide to do so, I'll write a PM to a member of TeamSpybot to check this in the next days.
    Best regards - Beste Grüße,

    Matt

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •