PDA

View Full Version : virtumondo or virtumonde please help !



Andromeda
05-18-2010, 10:47 AM
Something strange happened with my Spybot SD. Something called virtumonde or virtumondo started running. I have reinstalled Spybot, run TrendMicro Housecall shows no infection.
Have CCleaner, Malwarebytes, Avast 5, HijackThis, but need help as I don't know what's bad there.
Am not sure if there is anything still on the computer I need help urgently from an expert, please !!
(Have XP Pro 3, use IE8)

Andromeda
05-18-2010, 12:52 PM
Can anybody please help me, please ???

Erik
05-18-2010, 04:41 PM
Do you have access to another computer? If so I would download the Avira Anti-vir Rescue System you can either burn the ISO to a disc or the exe will do it for you, then boot the infected computer from the CD and run a full anti-virus check, backing up any important data while doing so would be a good idea.

http://www.avira.com/en/support/support_downloads.html

Here's a smilar tool from AVG that can work from USB stick or CD:

http://www.avg.com/ca-en/avg-rescue-cd

This should be able to find and remove the infection. In either case I would do a re-install of all your AV/malware software starting with Malwarebytes and running a full scan. If Vundo is still active and prevents running of the exe, renaming it can help.

Avoid using Hijackthis, if you've already run it then don't reboot to safe mode - I've read with some versions of Vundo this can cause a blue screen of death which can't be recovered from without a re-install or restoring registry keys.

Andromeda
05-18-2010, 05:37 PM
Thanks so much for replying Erik I am very grateful, but I don't have another computer. I am familiar vith antivir, have used it before.
I have re-installed Malwarebytes and run a scan, and it found nothing.
I don't have AVG so how can I get just that portion??
It's strange, I have had no crashes, no blue screan, no pop-ups, so I don't know what's going on.
I am a total loss. Any suggestions ??

linuxguru
05-18-2010, 09:29 PM
Virtumonde is a trojan. It probably arrived via email or download. Best chance to remove it is by turning off system restore temporarily and then running your updates and scans if possible in safe mode.

Andromeda
05-19-2010, 08:21 AM
Will try that. Thanks linuxguru !! How do I get into safemode on an XP Pro SP3??

linuxguru
05-19-2010, 08:36 AM
Safe mode.
Reboot the PC and as it starts you will see a message on the screen to press F8. Sometimes it works best to press and hold F8 as it boots.
Follow the screen to select Safe Mode with Network Support so you can update the anti-virus signature files.

Erik
05-19-2010, 09:14 AM
Both the Avira and AVG "rescue" disks are independent of the actual program - you click on the download link and either burn the cd or in the case of AVG USB rescue unzip/unrar the files and copy them to a USB stick.

How exactly did you know the Virtumonde virus was running to begin with - did Spybot tell you it detected the virus and offer you the option to block it? Or did you get a message that the virus was shutting the program down? If Spybot detected the virus and you stopped it from running in the first place that would explain why you aren't experiencing any infection symptoms.

Scanning in safe mode as Linuxguru described is usually a good idea - should be good if you haven't run Hijackthis in the case of Virtumonde.

lycan246
05-19-2010, 05:15 PM
I seriously doubt that Avir or AVG is going to fix this issue even if you use the stand-alone scanners. What needs to happen is for you to run VundoFix (http://www.atribune.org/ccount/click.php?id=4) and Combofix (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) (Each one is a direct download). Combofix will need a active Internet connection to use its scanner to install Microsoft recovery console (if you don't have one MSG back and i will give you another option). If neither of these very serious scanners do not remove this infection your looking at a reinstall.

Andromeda
05-20-2010, 10:42 AM
There is no problem was checked with MGtools, Superantispyware, Repeal, Malwarebytes by Malware expert. Thanks to all that answered.