Results 1 to 3 of 3

Thread: virtumonde.sdn

  1. #1
    Member
    Join Date
    Aug 2008
    Location
    Chicago, IL
    Posts
    31

    Default virtumonde.sdn

    Recently due to a problem on another computer (Which I have posted a thread for) I wanted to check my laptop again. I use several tools, MBAM, SuperAntiSpyware, Spybot S&D, and also use AVG 9.0 anti-virus.

    I did come up with a couple trojans (1 on each malware program), nothing with AVG... but spybot shows 2 instances of virtumonde.sdn - Which I has a run-in with on late 2008.

    Here is a bit from the ss&d log:
    Virtumonde.sdn: [SBI $29141721] Executable (File, nothing done)
    C:\WINDOWS\system32\oVpO9PU.vbs
    Properties.size=615
    Properties.md5=768466EA2059580A84F9C0E68D94C644
    Properties.filedate=1241406564
    Properties.filedatetext=2009-05-03 22:09:24

    Virtumonde.sdn: [SBI $29141721] Executable (File, nothing done)
    C:\WINDOWS\system32\wZbfr.vbs
    Properties.size=615
    Properties.md5=768466EA2059580A84F9C0E68D94C644
    Properties.filedate=1241401899
    Properties.filedatetext=2009-05-03 20:51:39

    I re-ran all other malware programs, and AVG, nothing else shows it.

    Tips?

  2. #2
    Senior Member
    Join Date
    May 2009
    Posts
    236

    Default

    You could upload the two .vbs files to VirusTotal to see if any of the other antivirus programs the site uses finds anything.

  3. #3
    Member
    Join Date
    Aug 2008
    Location
    Chicago, IL
    Posts
    31

    Default Actual virus

    Yep... checking through the link you supplied several antivirus sites showed both files as containing a virus.

    Luckily, It appears I have been successful in cleaning this without too much problem.

    I've rescanned the computer multiple times with my malware programs, brought the system back to normal, and no issues so far.

    Oddly, I had no symptoms prior to the fins.

    Thanks!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •