Help with Virtumonde

moJo787

New member
My computer has recently become infected with a number of viruses. After running a series of tests using Spybot S&D followed by my AVG virus scan, I was able to remove most of the infections.

When i run my AVG scan it says i have no threats, however if i run Spybot S&D it comes up with three TrojansC entries under the Virtumonde name. Here's what they show up as:

- (SBI $779C9C0D) Settings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP

- (SBI $FD08B4B7) Configuration File
C:\WINDOWS\system32\UDNVvyxx.ini2

- (SBI $2A2DCEAC) Configuration File
C:\WINDOWS\system32\UDNVvyxx.ini

If i run Spybot, it detects these three infections. When complete it says they have been fixed, but if i run the test again they still come up.

Any help would be gratefully appreciated. I'm not sure how to post the logs that i see others posting, otherwise i would copy and paste it here too.

Chris
 
Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hello and welcome to the forums

My name is Katana and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:
  1. Please Read All Instructions Carefully
  2. If you don't understand something, stop and ask! Don't keep going on.
  3. Please do not run any other tools or scans whilst I am helping you
  4. Please continue to respond until I give you the "All Clear"
    (Just because you can't see a problem doesn't mean it isn't there)
If you can do those few things, everything should go smoothly
laechel.gif


Please Note, your security programs may give warnings for some of the tools I will ask you to use.
Be assured, any links I give are safe

----------------------------------------------------------------------------------------



Download and Run RSIT
  • Please download Random's System Information Tool by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open:
    • log.txt will be opened maximized.
    • info.txt will be opened minimized.
  • Please post the contents of both log.txt and info.txt.
 
Back
Top