Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 22

Thread: virtumonde trojan

  1. #11
    Junior Member
    Join Date
    Aug 2009
    Posts
    2

    Default

    Similar to this thread started above, I visited my out-of-state sister last weekend, and updated her Spybot (she is not computer savvy). After running a scan, it turned up two instances of virtumonde trojan on her PC. One is cqsccol.dll, and the other dosfnt01.dll. I clicked the fix problem button, and Spybot said both instances were fixed. Then I re-scanned her PC, and it again turned up the two instances of virtumonde trojan. I repeated the fix problem, but the re-scan again showed the virtumonde trojan. I rebooted her PC, and again Spybot was not able to successfully permanently remove the trojan.

    She runs Windows ME.

    Any suggestions on how to permanently remove the virtumonde trojan? What is the danger of not being able to delete it?

    Thanks for the help....

  2. #12
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,959

    Default

    Hello GhanGuy

    The issue "False Positives > virtumonde trojan" has not been marked as resolved yet.

    Quote Originally Posted by GhanGuy View Post
    She runs Windows ME.
    Meanwhile please see: End of support for Windows 98 and Windows ME

    Best regards.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #13
    Retired
    Join Date
    Oct 2005
    Posts
    566

    Default

    Hello,
    it would be very helpful if you could provide us these files. Please send it to detections@spybot.info . If it is a false positive we will solve it with our next update scheduled for wednesday

    Best regards,
    Markus
    Team Spybot

  4. #14
    Junior Member
    Join Date
    Aug 2009
    Posts
    2

    Default

    Tashi - Thank you for the quick reply. Spybot runs well on Windows ME (unlike some other programs that are not backwards compatible). It's too bad that MicroSoft does not support the older software at all. My sister will probably unfortunately keep running the Windows ME until it gets totally corrupted.

    MisterW - I have returned home, so I cannot forward you the affected .dll files. I'll try to talk my sister through the process of sending them to you.

  5. #15
    Senior Member alicez's Avatar
    Join Date
    Apr 2008
    Posts
    179

    Default

    Quote Originally Posted by MisterW View Post
    Hello,
    Before you restore the file what would mean a possible risk for your computer please have a look at the recovery files itself. They are stored at

    c:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery

    There should be one file named something like Virtumonde.zip. Please send this file to us via mail.

    Best regards,
    Markus

    @drragostea: Sorry for my late reply to your pm!
    =======================

    How do I send via email?
    Vista also Win7 (64-Bit) IE 9; MSE; SpywareBlaster; MalwareBytes; SpyBot

  6. #16
    Retired
    Join Date
    Oct 2005
    Posts
    566

    Default

    Hello,
    we got your mail and we can confirm that it is a false positive and will be fixed in the next update scheduled for Wednesday

    Best regards,
    Markus

  7. #17
    Senior Member alicez's Avatar
    Join Date
    Apr 2008
    Posts
    179

    Default

    Quote Originally Posted by MisterW View Post
    Hello,
    we got your mail and we can confirm that it is a false positive and will be fixed in the next update scheduled for Wednesday

    Best regards,
    Markus
    Thank you.

    What should I do now? Should I remove the Virtumonde from Recovery?
    Should I restore the Virtumonde? If so, how would I do that?
    Vista also Win7 (64-Bit) IE 9; MSE; SpywareBlaster; MalwareBytes; SpyBot

  8. #18
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    @alicez

    yes please recover these 2 files,
    • start Spybot S&D
    • click on recovery
    • look for the 2 files named above
    • select them and click on the check boxes until there are green checkmarks
    • click on recover selected items
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  9. #19
    Member tiger2's Avatar
    Join Date
    Nov 2006
    Location
    USA
    Posts
    64

    Default

    What do you mean by:
    "look for the 2 files named above"

    I think there is only one files, namely: Virtumonde

    I'll be going to my neighbor's house tomorrow when I can see what actually is in the Recovery.

    AliceZ (Sorry for posting under my husband's sign-in name!)
    Last edited by tiger2; 2009-08-14 at 14:07.
    Vista Home Premium sp1 / IE7 / Toshiba Satellite notebook 3GB Ram / 250GB HD / Defender / AVG 8 / SpyBot S&D 1.6 / SpyWare Blaster

  10. #20
    Member tiger2's Avatar
    Join Date
    Nov 2006
    Location
    USA
    Posts
    64

    Default

    Quote Originally Posted by GhanGuy View Post
    Similar to this thread started above, I visited my out-of-state sister last weekend, and updated her Spybot (she is not computer savvy). After running a scan, it turned up two instances of virtumonde trojan on her PC. One is cqsccol.dll, and the other dosfnt01.dll. I clicked the fix problem button, and Spybot said both instances were fixed. Then I re-scanned her PC, and it again turned up the two instances of virtumonde trojan. I repeated the fix problem, but the re-scan again showed the virtumonde trojan. I rebooted her PC, and again Spybot was not able to successfully permanently remove the trojan.

    She runs Windows ME.

    Any suggestions on how to permanently remove the virtumonde trojan? What is the danger of not being able to delete it?

    Thanks for the help....
    Just a thought = Think it would be proper for you to have posted your question as a separate thread as I am getting messages when answers are posted to your question(s). Thank you.
    Vista Home Premium sp1 / IE7 / Toshiba Satellite notebook 3GB Ram / 250GB HD / Defender / AVG 8 / SpyBot S&D 1.6 / SpyWare Blaster

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •