![]() |
| ||
| AIM Virus - Virtumonde? My friend's PC is infected with some kind of trojan that is spamming out AIM messages to users on her buddy list - but I can't seem to find any trace of Virtumonde on her system. I'll be running other utilities this evening, but I wanted to post the Malwarebytes log and the Hijackthis log now to try to get some advice ahead of time. Thank you! Logfile of Trend Micro HijackThis v2.0.2 Malwarebytes' Anti-Malware 1.32 |
| ||
| Re: AIM Virus - Virtumonde? Update - I ran MWB again - no infections found. But the computer is still spamming. Short of a reformat - any other utilities that I could try? |
| ||
| Re: AIM Virus - Virtumonde? Reformat is extremely drastic. There is NO reason to reformat at this time. Turn off the AIM program completely until the computer is deemed clean. It cannot spam if it isn't turned on. There were multiple Trojans on the computer; Vundo(which is the same family of trojans as Virtumonde) Trojan.Spambot also known as Fake.Alert, Trojan.TinyDownloader705, Backdoor.Bot Trojan.Downloader. Go to Start, Control Panel, Add/Remove and look for any or all of these listings: * FunWebProducts * My Web Search (Smiley Central or FWP product as applicable) * My Way Speedbar (Smiley Central or other FWP as applicable) * My Way Speedbar (AOL and Yahoo Messengers) (beta users only) * My Way Speedbar (Outlook, Outlook Express, and IncrediMail) * Search Assistant - My Way *AskBar UNINSTALL any of the above items found. Reboot. Please be sure you are in NORMAL mode. Please empty ALL TEMP files. BOTH the MBA-M program and HJT must be run in Normal mode. They are meant to be run in NORMAL mode. There is a new version of MBA-M, please do the update and then do a full scan with it again. Reboot the System. AFTER you run the MBA-M then run the HJT. Post back here with BOTH logs. |
| ||
| Re: AIM Virus - Virtumonde? I'm sorry for abandoning this thread - the user decided her university's IT department knew better than I did and reformatted the PC without checking with me first. Of course, they didn't back up her data either. Oh well, her loss. She did manage, however, to infect someone else and I have her laptop with me right now. Same circumstances as before, including Windows Vista as the OS. I don't want to start a new thread for (seemingly) the same issue. This time, however, I cannot run Malwarebytes in Normal or in Safe Mode. It installs just fine, but it doesn't launch - no error message. No process shows up in the Task Manager. No entries in the Event Log. HiJackThis will not install in Normal or Safe Mode. In normal, Vista reports that the application did not install properly. In Safe Mode, nothing happens when running the install. It does, however, generate an Event Log entry. "Faulting application HJTInstall.exe, version 1.0.0.1, time stamp 0x46683992, faulting module HJTInstall.exe, version 1.0.0.1, time stamp 0x46683992, exception code 0x80000003, fault offset 0x001fac9, process id 0x81c, application start time 0x01c97cef6411f325." I've had a lot of experiences with nasty-ware (I work in an IT Department so I see A LOT of stuff), but this has me stumped. |
| ||
| Re: AIM Virus - Virtumonde? Update - ran AVG in Safe Mode (could not run in Normal). I also disabled suspicious looking executables running from the temp directory from the Msconfig startup tab. Now Windows won't start up at all - upon log in it notifies me that "An unauthorized change was made to Windows." I can "Learn more online" or "Close." Upon clicking Close it logs me out. Before I was able to bypass that by using the Last Known Good startup. But it doesn't work now. This thing is nasty. |
| All times are GMT -4. The time now is 5:15 am. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC