Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93124 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Resolved] Need to get rid of Virtumonde and Win32.TDSS.rtk.


  • This topic is locked This topic is locked
139 replies to this topic

#136 Neo

Neo

    Silver Member

  • Guests
  • PipPipPip
  • 374 posts

Posted 23 March 2009 - 03:08 PM

Tom, when I updated spybot it said there were some corrupted files and that I had to get updates in order to fix them. Upon opening the current update window for spybot, it had none of the updates available for me to download, so I deleted spybot and all of it's components from my pc and will soon get a fresh download of the spybot program and of course run another scan once get it updated. Below are 2 files I uploaded for scanning. The first of them is the original file that showed up when I ran and fixed the virtumonde that showed back up. The second is a suspect. File: zipfldr.dll Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: c444b433a340c24b51a2dace9d13fc70 Packers detected: - Scanner results Scan taken on 23 Mar 2009 20:39:46 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Quick Heal Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing File: zipfldr.dll_old Status: OK(Note: file has been scanned before. Therefore, this file's scan results will not be stored in the database) MD5: c444b433a340c24b51a2dace9d13fc70 Packers detected: - Scanner results Scan taken on 23 Mar 2009 20:57:35 (GMT) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Ikarus Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Quick Heal Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing Hmmmm.... Ok then... I guess i'm clean :unsure: gonna get a new spybot newbe17
Best
Wishes
,

Neo

Posted Image

    Advertisements

Register to Remove


#137 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 23 March 2009 - 05:24 PM

newbe17, I'm going to predict that you have spybot 1.52. That is a known false positive. If you update your spybot (I think current version is 1.62) it should quit flagging that file. Those files are good.
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

#138 Neo

Neo

    Silver Member

  • Guests
  • PipPipPip
  • 374 posts

Posted 23 March 2009 - 07:18 PM

Tom, Wheeew, I love it when u r right :) I now have version 1.6.2.46. I think I should just give it a rest for a day or 2, keeping an eye on it, looking for any sudden changes in speed or disappearing and reappearing programs on my desktop. What do you think? newbe17
Best
Wishes
,

Neo

Posted Image


#139 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 23 March 2009 - 07:27 PM

newbe17, Sounds like a plan. I'll leave this thread open for a couple of days.
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

#140 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 25 March 2009 - 07:57 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

Related Topics



1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users