Threat found by NOD32!! Virtumonde related....

Status
Not open for further replies.

niccorny

New member
Hi,

Team Spybot last month I seek help of one of you top malware removal specialist and i am very pleased and thankful that i've been entertained by one of your supports, specifically mr. Blade81. Unfortunately, after one month NOD32 detected an infection in:
D:\System Volume Information\_restore{1C0DAECC-E642-4D93-94FA-98FC9080E288}\RP24\A00144221.exe
NOD32 said that it is infected with a variant of Win32/Adware. Virtumonde. NAE application.

I browsed drive D: and i can't find any folder or anything relating to System Volume Information. Some said it is hidden and used by restore points. How can I access or delete this file?

However, my computer's performance still at its best and doesn't seem to be affected by this infection. But I am bugged every time I scanned my computer and detect this infection.

Hoping someone could look into my problem (again) ! Thank you very much! and More power... :)
 
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

D:\System Volume Information\_restore{1C0DAECC-E642-4D93-94FA-98FC9080E288}\RP24\A00144221.exe
That is an infected System Restore file, clean those like this:

Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Reboot

Turn ON System Restore,
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

Additional information:
http://www.google.com/search?hl=en&q=what+is+system+restore&btnG=Google+Search

If that takes care of your problem, fine. If not, read the directions and follow them, they are posted above and pinned (sticky) to the top of this forum.

Thanks
 
Thanks sir... it did solve the problem! rescanned and ZERO threat was found.

One last tiny problem sir...sometimes when I open my browser (firefox) another window will pop up and load this page: http://www.beautyscreens.com/jokes.php

I scanned spybot and nothing was found and did the "clear private data" tool on firefox nothing happened. I know its a little minor but I hated every time that I execute firefox this "JOKE OF THE DAY" appears...its not funny anymore!:sad:

Good day!
 
Wow...thanks PSKELLY!! Thanks to these links...gonna bookmark them out!! Again sir more power and Have a nice day! :bigthumb:
 
Status
Not open for further replies.
Back
Top