phpBB Forum
 
It is currently Wed Mar 25, 2020 4:03 pm




Post new topic Reply to topic  [ 11 posts ]  Go to page 1, 2  Next
Trojan halp - Virtumonde 
Author Message
HH Donor
HH Donor
User avatar

Joined: Mon Jun 02, 2008 4:18 pm
Posts: 4178
Location: Some Island
STEAM_0:1:18889390
MCID: Bedizen
Post Trojan halp - Virtumonde
Well.

Spybot picked this up the other day and after a scan, remove, reboot it was still present on the next round.

Thinking "oh well, it was about time anyway" I formatted my OS partition and did a fresh install of XP.

Still there on the next scan.

Since then I've tried nailing the little fucker down, but here my woes begin.

When I scan my system with Avast (free), Malwarebytes, SuperAntiSpyware, Rootrepeal and MGTools nothing is showing up. Zero. Nada.

But it's still showing up in Spybot.

I've spent the whole day watching scanning status bars so tell me:

WHO DO I TRUST, WHAT CAN I BELIEVE, WHO IS TELLING THE TRUTH?!

_________________
I'm a stand up comedian. I stand. And I comedian.


Sat Nov 27, 2010 8:20 pm
Profile E-mail
HH Member
HH Member
User avatar

Joined: Sun Aug 03, 2008 4:11 pm
Posts: 376
Location: Behind you
STEAM_0:1:12401470
MCID: SenCommander
Post Re: Trojan halp - Virtumonde
Nasty thing, had it once, spread via the network.
Remove Version A with : http://www.atribune.org/ccount/click.php?id=4
Remove Version B with : http://www.symantec.com/business/securi ... 10-3747-99

More info: http://hubpages.com/hub/Virtumonde-Removal-Tools

_________________
Someone on LSD wrote:
I actually walked into a room, turned to a side and saw myself walk into me.


Sat Nov 27, 2010 8:30 pm
Profile
HH Donor
HH Donor
User avatar

Joined: Sun May 25, 2008 8:20 pm
Posts: 5490
Location: nextdoor
STEAM_0:1:12422276
MCID: bomaster
Post Re: Trojan halp - Virtumonde
lol im having a similar problem, not tried spybot but my os is behaving strangely as of late and again avast picks up nothing. as soon as i see firefox opening on its own and loading bollox i know somethings amiss.also avast is unable to update since this has started. if i find out what kills it ill let you know

_________________
But PGT's the musical one, and he's got poobrain!!

|H|H| PotentGermanThunder: yoooo peej your mustache arrived
|H|H| PotentGermanThunder: thanks ma

|H|H| PotentGermanThunder: evolution didn't bring freud anywhere, he still died
|H|H| Bomaster: i think you're confused with darwin

|H|H| PotentGermanThunder: how about fuck you that's shit go eat a bag of dicks euclid

|H|H| PotentGermanThunder: bon jovi is as good as van halen


Sat Nov 27, 2010 8:31 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Mon Jun 02, 2008 4:18 pm
Posts: 4178
Location: Some Island
STEAM_0:1:18889390
MCID: Bedizen
Post Re: Trojan halp - Virtumonde
Did it!

Booted into safe mode, ran spybot once again, it killed the files and they haven't returned on a normal reboot.

Created new system restore point, cleaned all the shit.

Sorted.

Spybot is an awesome program, I do recommend it to anyone with problems - just run it in safe mode if you are definitely sure you are infected (especially with trojans, which constantly change file/registery names).


Sat Nov 27, 2010 10:34 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun May 25, 2008 8:20 pm
Posts: 5490
Location: nextdoor
STEAM_0:1:12422276
MCID: bomaster
Post Re: Trojan halp - Virtumonde
dude, linky the tool you used :oops:


Sat Nov 27, 2010 11:24 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Tue Mar 24, 2009 2:05 am
Posts: 1911
Location: Here.
STEAM_0:0:538759
MCID: Fluff_a_Licious
BattleTag: Netrahedon#2897
Post Re: Trojan halp - Virtumonde
http://www.safer-networking.org/en/index.html

I guess you meant Spybot Search & Destroy right?

Oh bo, you are so lazy :?

_________________


Sun Nov 28, 2010 12:32 am
Profile E-mail
HH Member
HH Member
User avatar

Joined: Thu Jun 26, 2008 9:20 pm
Posts: 3247
STEAM_0:1:17709863
BattleTag: pinion#2876
Post Re: Trojan halp - Virtumonde
hmm id go with not having a partition tbh

_________________


Sun Nov 28, 2010 12:53 am
Profile E-mail WWW
HH Donor
HH Donor
User avatar

Joined: Mon Jun 02, 2008 4:18 pm
Posts: 4178
Location: Some Island
STEAM_0:1:18889390
MCID: Bedizen
Post Re: Trojan halp - Virtumonde
bfox wrote:
hmm id go with not having a partition tbh


Weeeell, having a partition means I've list no data from formatting and doing a fresh install.

It's useful.

And yes, fluffs link is the one bo.


Sun Nov 28, 2010 12:00 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun May 25, 2008 8:20 pm
Posts: 5490
Location: nextdoor
STEAM_0:1:12422276
MCID: bomaster
Post Re: Trojan halp - Virtumonde
didnt work, installed sophos rootkit and found 8 files but it wont remove them...

the reason i didn't look for that myself is that iv not used it before and couldn't tell the genuine from the fake AV tool. the amount of fakes out there are incredible


Sun Nov 28, 2010 4:02 pm
Profile E-mail
HH Donor
HH Donor
User avatar

Joined: Sun May 25, 2008 10:15 pm
Posts: 1305
Location: Guildford UK
Post Re: Trojan halp - Virtumonde
Another one to try is a program called 'Malware bytes'. It can spot some things that spybot won't.

http://www.malwarebytes.org/

_________________
'Today, a young man on acid realized that all matter is merely energy condensed to a slow vibration – that we are all one consciousness experiencing itself subjectively. There's no such thing as death, life is only a dream, and we're the imagination of ourselves. Here's Tom with the weather. -Bill Hicks


Tue Nov 30, 2010 12:43 pm
Profile E-mail
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 11 posts ]  Go to page 1, 2  Next


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © phpBB Group.
Designed by Vjacheslav Trushkin for Free Forum/DivisionCore.