Posted 27 December 2008 - 10:49 AM
My Windows XP Media Edition PC is infected with something. The most obvious symptoms are:
1) When using Firefox, new browser windows will randomly open -- to URLs that seem random. This happens often.
2) On occasion, audio will start playing -- as if some streaming internet audio was playing. I do not recognize the audio.
The above behavior started yesterday, Dec 26. Until then, I had no knowledge that something was wrong. However, once this started, I looked at Norton's log. (I have Norton 2008 running on the system.) On Dec 22, Norton discovered Virtumonde -- and thought it had removed it. On Dec 23, Norton again discovered Virtumonde and again thought it removed it. Since then, Norton does not find Virtumonde.
After I discovered that my system was having problems, I took the following steps:
Yesterday (Dec 26) I installed Spybot S&D. Spybot discovered Virtumonde (even though Norton no longer does). Spybot thought it successfully removed the infected keys. On a subsequent reboot, Virtumonde was again detected by Spybot.
I then installed MBAM. MBAM found additional evidence of Virtumonde. MBAM removed what it found. Subsequent reboots and rescans show that MBAM and Spybot think my system is clean of all issues they can detect.
Nonetheless, my system is continuing to exhibit the behaviors listed at the top. (#1, for sure; I do not yet know if #2 is resolved.)
The PC is networked in a LAN; the LAN is connected to the WAN via a DLink router. Two other Windows PCs are on the LAN (one Vista, the other XP Home). One Linux laptop is also connected to the LAN, wirelessly.
The system is set up with multiple user accounts -- both of which are Administrators. One account is hardly ever used. All of the above have been done logged in as one of the users -- the typical user of the system.
I have the MBAM log that shows the original Virtumonde infections (and subsequent logs that show that MBAM no longer detects anything). I also have a HijackThis log, that I collected this morning. I will them per your subsequent directions.
I would truly appreciate any help. Thanks in advance!