I seem to have a Trojan roaming around on my computer and cant get rid of it. I had the Antivirus 2009 plus a host of other Malware on my pc. One of the Trojans i had was the Virtumond…I think thats how you say it. I have used Kaspersky, Spybot, Norton 360, Windows Defender, Spy Doctor and just recently used Anti-Malware. My Homepage also seems to be getting redirected. I have gone into my registry and removed some of the Virtumond stuff that was executing when starting up but there still must be some of it left. When i run a virus scan or any other scan it finds nothing wrong with my pc, but i know that is not so.
PC SPECS
AMD 5000+ Dual Core
MSI MOTHERBOARD
NVIDIA 512DDR3
3 HD's
4GB RAM
WINDOWS VISTA ULTIMATE 32bit SP1
Here is my HiJackThis log Dont think you will see anything unusual on it:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:58:17 AM, on 10/29/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Also, the reason you were probably so badly infected is that I do not see any signs of any security software, including the most important, an Anti-Virus. Any reason for this? I know you mentioned you used some to remove the malware you had but you must have uninstalled it. You should have at a minimum an Anti-Virus running real time. Here are a couple of free for home use ones that will work well in Vista.
Thanks i will try them out and let you know how it goes. Also I got the viruses by a mistake on my part ;/ I have removed most of them but am at a loss with this one. It seems to be attaching itself to different profiles i make.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:44:01 AM, on 10/31/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Everything seems to be fine on my other profile I created. But my main profile isn't working properly. My homepage is redirected to my email login page and I am still having problems with the Trojan.
I did run the AntiVira. It said it removed the trojans that were on my pc . I ran it again and also ran Malware bytes and nothing seems to be on my pc. Any other suggestions would be apprecitated. Thanks for your help so far.
here is the result of the scan. Also to answer your other question i did have hijackthis remove the other two processes/programs.
;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-11-01 14:29:13
PROTECTIONS: 1
MALWARE: 5
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
Windows Defender 1.1.4005.0 No No
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\Starcraft\AppData\Roaming\Microsoft\Windows\Cookies\starcraft@doubleclick[1].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Users\Starcraft\AppData\Roaming\Microsoft\Windows\Cookies\starcraft@fastclick[2].txt
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Users\D\AppData\Roaming\Microsoft\Windows\Cookies\d@yadro[2].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Users\Starcraft\AppData\Roaming\Microsoft\Windows\Cookies\starcraft@apmebf[1].txt
03009106 W32/Xor-encoded.A Virus No 0 No No C:\Users\D\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report5ec0aa78\Report.cab[dgksvbpn.dll.xor]
03009106 W32/Xor-encoded.A Virus No 0 No No C:\Users\D\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report5ec0a509\Report.cab[xrdwbfgn.dll.xor]
03009106 W32/Xor-encoded.A Virus No 0 No No C:\Users\D\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report5ebbb8e9\Report.cab[xrdwbfgn.dll.xor]
03009106 W32/Xor-encoded.A Virus No 0 No No C:\Users\D\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report06eb59c6\Report.cab[qmafxprs.dll.xor]
03009106 W32/Xor-encoded.A Virus No 0 No No C:\Users\D\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report06eb51a8\Report.cab[lfstbwvd.dll.xor]
;===============================================================================
=================================================================================
===================
SUSPECTS
Sent Location j��x��s5
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================
VULNERABILITIES
Id Severity Description j��x��s5
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================
Hijackthis Scan:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:36:16 PM, on 11/1/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Since they are in a cabinet file you can not directly delete them. You would have to extract them first, and you don't really want to do that. Let me look into it a bit. Is there anything else in that .cab file? If not you could just delete the .cab