All times are UTC




Post new topic Reply to topic  [ 9 posts ] 
  Print view

Virtumonde killing my comp
Author Message
PostPosted: Wed Aug 20, 2008 10:43 am 
Offline
"Ding Dong" Overlord
"Ding Dong" Overlord
User avatar

Joined: Sun Aug 03, 2008 12:14 am
Posts: 576
Location: USA
If you don't know, this is a dangerous, medium risk trojan that infected your comp w/ a bunch of ad pop up .
The dangerous part was I d/l vundofix and virtumundobegone and it didn't even wipe out all of it. Weird thing was I scan using spybot Search and Destroy and I kept getting the registry about it but there is only 2 . I then proceed to delete the registry only to find out upon reboot that it will appear again.
Man, anyone actually know how to kill this thing .

http://en.wikipedia.org/wiki/Vundo_trojan
Bummer, it attach to winlogon, wtf ? :|

_________________
Who need a room ? Rent a Bush, Buy a Blanket .
Talk is Cheap because Supply exceed Demand .


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Wed Aug 20, 2008 11:10 am 
Offline
"Ding Dong"-ing Administrator
"Ding Dong"-ing Administrator
User avatar

Joined: Sun Jun 10, 2007 8:18 am
Posts: 3135
Location: Neo Sealand
I have Pmed you with various free offers from various security softwares

_________________
ImageImage

Image

Ultra mega CDJapan and YesAsia specials-orz! Click here!


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Wed Aug 20, 2008 11:30 am 
Offline
Casual Music Fan
Casual Music Fan
User avatar

Joined: Tue Aug 05, 2008 5:18 pm
Posts: 36
Well, according to the wiki, i suggest you first install safari for web browsing temporarily.
Then, you could try installing litestep, a replacement for explorer.exe.. maybe that'll help in some way with the virus replicating. (I don't know of any ways to bypass/replace winlogon).

The only thing that I can think of that might work is downloading an ubuntu livecd, running linux on boot before winlogon, and then manually browsing through system32 and etc in linux and deleting everything.


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Wed Aug 20, 2008 11:32 am 
Offline
"Ding Dong"-ing Administrator
"Ding Dong"-ing Administrator
User avatar

Joined: Sun Jun 10, 2007 8:18 am
Posts: 3135
Location: Neo Sealand
I Pm'ed him links to download Spysweeper, it tends to have great results with Vundo (google search), then again if I got something like that I would end up reformatting, since I would never ever feel the computer is '100% clean', maybe it's because I'm paranoid -_-

_________________
ImageImage

Image

Ultra mega CDJapan and YesAsia specials-orz! Click here!


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Wed Aug 20, 2008 12:23 pm 
Offline
"Ding Dong" Overlord
"Ding Dong" Overlord
User avatar

Joined: Sun Aug 03, 2008 12:14 am
Posts: 576
Location: USA
Yeah last thing I would want to is reformat O_O . I got like 1TB of file there >< .
I will try spysweeper though :) . Although I think I manage to cripple that sucker . I even found MS Juan (wtf is this crap) key in my registry . I read on one of the site provided in wiki that the trojan sometimes name itself as Juan so I delete it. But man, I must have got one of their latest variation or something .
I think it was long ago more than a month that I click one of the pic that open to a site which had nothing on it. Must have got it through there .

_________________
Who need a room ? Rent a Bush, Buy a Blanket .
Talk is Cheap because Supply exceed Demand .


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Wed Aug 20, 2008 8:58 pm 
Offline
Casual Music Fan
Casual Music Fan
User avatar

Joined: Tue Aug 05, 2008 5:18 pm
Posts: 36
What browser do you use? Most wouldn't download something like that..

And I've never heard of MS Juan O.o, it must be almost 100% the trojan.


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Sat Aug 23, 2008 4:15 am 
Offline
"Ding Dong" Overlord
"Ding Dong" Overlord
User avatar

Joined: Sun Aug 03, 2008 12:14 am
Posts: 576
Location: USA
Grapefruit2 wrote:
What browser do you use? Most wouldn't download something like that..

And I've never heard of MS Juan O.o, it must be almost 100% the trojan.

It's Virtumonde trojan but when it get to your registry, it embedded itself as if it was your OS :) . It then started to create a bunch of random name dll that loaded everytime you log into window.
I used Firefox btw .

_________________
Who need a room ? Rent a Bush, Buy a Blanket .
Talk is Cheap because Supply exceed Demand .


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Sun Aug 24, 2008 10:45 pm 
Offline
"Ding Dong" Overlord
"Ding Dong" Overlord
User avatar

Joined: Sun Aug 03, 2008 12:14 am
Posts: 576
Location: USA
Bummer, got infected again .
But I know the cuprit now, it's a ratiofaker program that I d/l long ago but never actually use it. Today I go on to clean my comp and found that program, then I click, next thing I known is that I am now hiding behind the safe mode trying to kill it. Even spy sweeper cant kill it all now or found some of its remaining O_O .

It's activate like a doomsday device, where you kill the exe/dll on the task bar and then they pop up with many pop up asking you to buy a program, enter a key. Funny thing was some of them, you can't even close it, it confine your mouse to a small little screen of there.
PS : No wonder my d/l speed going down these past weeks. Anyway, see ya guy, will see what I can do after I get home :) .

_________________
Who need a room ? Rent a Bush, Buy a Blanket .
Talk is Cheap because Supply exceed Demand .


Top
 Profile  
 

Re: Virtumonde killing my comp
PostPosted: Sun Sep 07, 2008 1:31 am 
Offline
"Ding Dong"-ing Administrator
"Ding Dong"-ing Administrator
User avatar

Joined: Sun Jun 10, 2007 8:18 am
Posts: 3135
Location: Neo Sealand
Format your computer, don't even backup anything xD Or if you're really paranoid, get that harddrive and throw it in the trash xD

Reinstall your OS, it's the only thing you can do when you get a virus =(

_________________
ImageImage

Image

Ultra mega CDJapan and YesAsia specials-orz! Click here!


Top
 Profile  
 

Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  

Advertisements that support Japanimusic! (Check them out!)

Ads