Results 1 to 10 of 10

Thread: Virtumonde all the time

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    2

    Default Virtumonde all the time

    I'm not sure....I'm using Vista. Every time I scan, it detects Virtumonde, in c:Win/sys32/zipfldr.DLL. So I run the program as Administrator, and clean it. Then when I reboot, and Spybot starts it auto search, there it is again! So I'm wondering is it not really cleaning it or what? Anyone have an idea? Thanks!

  2. #2
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Hi dlbhina,

    to Safer Networking Forums.

    Which version of Spybot do you use?
    Best regards - Beste Grüße,

    Matt

  3. #3
    Junior Member kenmur's Avatar
    Join Date
    Aug 2009
    Location
    Vancouver, BC
    Posts
    12

    Default Same problem

    I too have the same problem. I use Windows XP Media Centre Edition.
    Is this a real threat? Event viewer sees c:Win/sys32/zipfldr.DLL as a protected windows file and windows keeps restoring the file after Spybot cleans it up.
    Last edited by kenmur; 2009-08-15 at 19:39.

  4. #4
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Hi kenmur,

    to Safer Networking Forums.

    It sounds like a false positive from Spybot 1.5.x . But this verison is out of date. If you use this version, I would like to uninstall Spybot 1.5.2, reboot your computer, delete all leavings manually and install Spybot 1.6.2 from here.

    For the two of you:
    Which version of Spybot do you use?
    Last edited by Matt; 2009-08-15 at 19:44.
    Best regards - Beste Grüße,

    Matt

  5. #5
    Junior Member kenmur's Avatar
    Join Date
    Aug 2009
    Location
    Vancouver, BC
    Posts
    12

    Default

    Thank you Matt.
    I tried as you said and it seemed to work.
    btw I was using 1.5.2.20 and now 1.6.2.46
    Cheers,
    Ken.

  6. #6
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Quote Originally Posted by kenmur View Post
    Thank you Matt.
    I tried as you said and it seemed to work.
    btw I was using 1.5.2.20 and now 1.6.2.46
    Cheers,
    Ken.
    You're welcome.
    Best regards - Beste Grüße,

    Matt

  7. #7
    Junior Member
    Join Date
    Aug 2009
    Posts
    2

    Default

    Thanks Matt. Was on vacation and didn't get to your reply until now.

  8. #8
    Senior Member Matt's Avatar
    Join Date
    Aug 2006
    Location
    Bavaria
    Posts
    1,169

    Default

    Quote Originally Posted by dlbhina View Post
    Thanks Matt. Was on vacation and didn't get to your reply until now.
    I hope you enjoyed your time.

    Happy Safe Surfing!
    Best regards - Beste Grüße,

    Matt

  9. #9
    Junior Member
    Join Date
    Aug 2009
    Posts
    1

    Red face should I upgrade also?

    While I have not seen any classic symptoms of "Virtumonde", I always seem to find it in a scan.

    I've been getting a simular false positive on a dll file or dll files that come under different names. Always in the C:\WINNT\system32 area.

    Copying one of them and renaming to a txt file displays a company name in the file as: w w w . h e l i x c o m m u n i t y . o r g

    This relates to RealPlayer (which I've tried to remove many times).

    My version of S&D is 1.5.2.20

    What worries me is the advice; "delete all leavings manually".

    So if one does miss something, then what?

    TIA,
    Gerry

    PS: While I donated many years ago, as soon as this old retired fart get's some expendable cash, I will do so again.
    Last edited by Gerry_D; 2009-08-26 at 03:41. Reason: added PS.

  10. #10
    Senior Member
    Join Date
    Oct 2005
    Location
    Germany
    Posts
    5,263

    Default

    Hello,

    This is a false positive in older versions.
    You seem to be using a dated version of Spybot-S&D.

    Please uninstall Spybot - Search & Destroy according to the following link:
    http://www.safer-networking.org/en/howto/uninstall.html
    Then download our current version Spybot - Search & Destroy 1.6.2. That should fix it.
    You will find links to several download locations for this new version on our web site:
    http://www.safer-networking.org/en/mirrors/index.html

    Best regards
    Sandra
    Team Spybot

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •