Log in

View Full Version : Virtumonde & Zlob Infections


mitchsc
Jun 15, 2009, 01:49 PM
I am running XP Home SP3.

Monthly I do a virus scan and spyware scan with CA 2007 Security Suite + real time protection. I also run Spybot.

I just noticed that my spybot scans were taking much longer than usual (2 hrs as opposed to 20 minutes).

Then I noticed that the Spybot scan would "hover" over 1000's of files called Virtumonde and Zlob.

My anti-virus is not picking these up, nor are my spyware scans. Again, I only noticed it by reading the scanning bar in spybot during the scan.

The web has 100's of applications and procedures for removing these 2 trojans. I don't know where to start, or what to believe.

Would like to find a free app if possible, and avoid any manual removal processes.

Any suggestions on a good and thorough application (free)?

Also, is there some way I can tell if my backup HD is infected? It only contains Word and photos. No applications or programs. I'm afraid to connect it to my PC now for fear of infecting one or the other.

Thanks...

Curlyben
Jun 15, 2009, 02:00 PM
Before you use yet another application, try running the onnes you have in safe mode.
Make sure they are fully updated first.

Remove ANYTHING they find.

NeedKarma
Jun 15, 2009, 02:02 PM
My standard recommendation for these: Malwarebytes.org (http://www.malwarebytes.org/mbam.php)

mitchsc
Jun 15, 2009, 02:12 PM
Curlyben,

I followed my Security Suite instructions: turned off System Restore and ran software in Safemode. No difference (no detection).

NeedKarma,
Does Malwarebytes work on both of these infections? Should I run in Safemode?

Update: I just noticed that both my PCs and my laptop are infected. Now I don't really know how long I've had these.

If it's that contagious, I guess I need a good program to get rid of them in case they come back.

None of my software seems to detect them. Only way for me to tell is run Spybot and watch the scan bar to see if file names come up. This is terrible!

HELP!

NeedKarma
Jun 15, 2009, 02:23 PM
Here's what I would do:
- Download and save the Avira AV install file: Free antivirus - Avira AntiVir (http://www.free-av.com/)
- disconnect from the internet
- uninstall your current AV
- clean up with CCleaner: CCleaner - Download (http://www.ccleaner.com/download)
- install Avira
- install and run MalwareBytes in Safe Mode
- run a virus scan in safe mode

mitchsc
Jun 15, 2009, 02:44 PM
Thank you. I'll give it a try...