Results 1 to 5 of 5

Thread: Banker.fat + Virtumonde

  1. #1
    Junior Member
    Join Date
    Sep 2007
    Posts
    2

    Default Banker.fat + Virtumonde

    Both of these trojans were regenerating themselves in my hard drive... everytime spybot removed them they came back on the next reboot. I finally found that they were coming out of the recovery file within spybot. Once I purged the file they did not come back... DOES THAT MAKE SENSE TO ANYONE ELSE?
    Last edited by Richard L.; 2010-01-17 at 21:05.

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hello,

    this kind of behaviour has not been observed with any kind of malware yet.
    Usually a Virtumonde infection requires a reboot the same may apply to some Banker variants.
    Please create a full Spybot S&D report file and send it to detections@spybot.info with a reference to this thread. With this report file we will be able to take a look at the most common starting places for the named malware above.
    To make a full report do the following:
    • start Spybot S&D
    • do a scan
    • right click the scan results screen and choose to save a full report to your desktop
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Junior Member
    Join Date
    Sep 2007
    Posts
    2

    Default

    Do you want me to reintroduce banker.fat into my hard drive first and have spybot s&d remove it before I do the report. If so, I believe the introduction/infection point is within 'facebook.' I do not no where I can find virtumonde at this point. I had removed it from my hard drive before trying to track its origin.

  4. #4
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    no, I wanted to take a look at the full Spybot S&D report since it is possible that there are some traces of the malware you described are still left on your computer.
    Since we are at it, it might also be helpful if you send in a Spybot S&D fix report, Spybot S&D stores the information about what it checks and fixes (or tries to fix). These reports can be found this way:
    • start Spybot S&D
    • switch to advanced mode
    • navigate to tools - view reports
    • now click on view previous reports
    • select the latest fixes report file, the name contains the date and time in this manner YYMMDD-hhmm


    edit: just saw that you sent us a mail with the full Spybot S&D report, I will keep you updated about what I find
    Last edited by Yodama; 2010-01-19 at 07:48.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  5. #5
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    sent you a mail with instructions for removal and further analysis since the report indicated an infection
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •