Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 02-03-2009, 08:23 AM   #1 (permalink)
Registered User
 
Join Date: Feb 2009
Posts: 2
OS: XP Home SP 3, soon upgrading to Vista Ultimate


Virtumonde trogen, rootkit, keyloggers, and something that just won't go away

My shorthands:
SB=Spybot search and destroy
AVG= AVG 8.0 Free Edition
SRR= Some random rootkit scanner a fellow tech in training suggested.
XP= Windows XP Home Service Pack 3
A!= Avast!
TH=Trogen horse, namely the Virtumonde trogen
RK= The bad rootkit the SRR picked up.
RC= Registry Change, picked up by SB.
DL= Download
DL'd= Downloaded

I am not on my home computer with this thread, but it does have internet access.

Ok, so I'm IM'ing with a friend, and she wanted me to look at her new pictures she just put up. I knew it wasn't a bot, because of the conversation we were having. So she gives me 5 links, and i open every one, loading them all up on GC. The second link was triggered by GC as a bad web site. GC falsely triggered under facebook before, so since the website was something similar to facebook, i went in anyway.

All the sudden, my CPU gauge went way up, and then dropped, and jumped up again. AVG triggered a virus, which i deleted, but SB started getting all kinds of changes, each i denied, but they kept happening over and over and over. Looking closer at the registry changes, i saw something (this was a week or so ago, so my memory is shady), about a keygen, and a more common (this is still happening every 5 seconds) registry change (can give more details later if needed). Then something popped up talking about MS-2009, which needed to be DL'd to keep my computer safe, i didn't do anything about it because i suspected a keylogger at this point has been loaded into my system, and it asked for my credit, and i wouldn't want it anyway, seemed very suspicious.

I scanned with AVG, which only found three things, each deleted, and spybot found 10 threats, each the TH and it's variations.

I ran this scan probably a hundred times, and each time, the TH was still present.

So, at this point, I decided to ask some friends for ideas. I tried downloading A! and scanned with it. As soon as i installed it, it triggered for a virus, and never stopped. The virus can not be moved and renamed, it can't be moved into the vault, and it can not be the third button (forgot what it was :P), it can only be deleted or left alone. Then someone decided to suggest the SRR, so i DL'd it, and scanned, and well, it found the problem.

So you'd think the problems solved right? Wrong, it, like the TH, keeps becoming recreated.

Now at this point, i can't do anything without getting A! triggered with a virus, or SB finding a change in the registry.

I've tried to fix this myself, but I'm out of ideas, short of formatting the HDD. I'm also worried that my mothers computer (although we are not networked together) has caught the same bug as me.

Thanks for you time :)

Edit: by networked together i mean, we don't share files or of the such, and work independant from each other, but are connected physically by a switch.

Last edited by Ray661; 02-03-2009 at 08:25 AM.
Ray661 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-03-2009, 09:12 AM   #2 (permalink)
Registered User
 
Join Date: Feb 2009
Posts: 2
OS: XP Home SP 3, soon upgrading to Vista Ultimate


Re: Virtumonde trogen, rootkit, keyloggers, and something that just won't go away

the rootkit scanner was made by Sophos.
Ray661 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 02-03-2009, 09:57 AM   #3 (permalink)
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,476
OS: XP SP3


Re: Virtumonde trogen, rootkit, keyloggers, and something that just won't go away

Hello and welcome to TSF.

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:
Having problems with spyware and pop-ups? First Steps
link at the top of each page.

Please follow our pre-posting process outlined here:

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:37 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85