Virtumonde, or Vundo for short

by Stangmar

Back to The Real World.

Stangmar2009-03-06 22:18:33
So, my dad's business computer got Virtumonde. That virus is a pain in the rear. The worst virus I have run into bar none. I have run Adaware, spybot, and defender and it will not go away. We need this thing off of there pronto. We would like to avoid formatting if we can. What are your recommendations?
Nocht2009-03-06 22:20:56
MalwareBytes

I've run into the exact same thing in the schools where I work. This program always seems to get it, and I've had more luck with it than Spybot.
Stangmar2009-03-06 22:56:30
Hmm, sounds interesting. Right now I'm trying a process I found online where you basically run a scan just to find the names of the DLL's, boot from your Windows CD and go into repair mode, and manually delete all the infected DLL's. If that doesn't work I'm backing everything I need up and reformatting.

This is the biggest problem I've ever had with XP. It's generally been good to me so far.
Unknown2009-03-07 01:43:13
Lol Stang happydance.gif

Unplug your connection.

Reboot in safemode.

Run Malwarebytes (if not starting, change .exe file to .com)

Run Spybot S&D.

Run SuperAntiSpyware.

Run a good antivirus like AVG free, Avira, Eset.

Run CCleaner.

Tada!
Stangmar2009-03-07 14:36:32
Well, i ran Malwarebytes last night, and I am now cautiously optimistic that it worked. Will observe for a few more hours before deciding to proceed. May just be screwing with me like it has when i run Spybot(Will run great aftewards for about 5 hours, making me think the virus is gone, then it will come back).
Stangmar2009-03-08 05:06:56
Okay, I've loaded into safe mode(after updating all those programs and disconnecting my ethernet), I ran MalwareBytes(frustrating, I had to babysit it because it would keep pausing and giving me an alert), I then ran Spybot. Both of those programs claim to have removed it so far. I currently have a SuperAntiSpyware scan going. I will check on it in the morning if i have time, and then run AVG and CCleaner. Hopefully this works once and for all.
Unknown2009-03-08 05:29:18
Avira and Eset are actually better than AVG FREE, but whatever. Also make sure you run a FULL virus scan. Whats causing Vundo to keep popping up is a trojan. Deep-cleaners like Avira and Eset ( Eset is the best imo) specialize in finding trojans.
Isuka2009-03-08 06:39:47
QUOTE (B_a_L_i @ Mar 7 2009, 09:29 PM) <{POST_SNAPBACK}>
Avira and Eset are actually better than AVG FREE, but whatever. Also make sure you run a FULL virus scan. Whats causing Vundo to keep popping up is a trojan. Deep-cleaners like Avira and Eset ( Eset is the best imo) specialize in finding trojans.

What's your basis for saying that? I've always had great luck with AVG.
Unknown2009-03-08 09:54:07
AVG is fine, but if you ask anyone with some technical knowledge on the subject they'll probably recommend Eset over AVG. I have a friend who manages networks and he has nothing but good things to say about it.

http://www.anti-malware-test.com/?q=taxonomy/term/17/

Also, unlike AVG, those programs aren't takeover happy and aren't a pain in the butt to uninstall.
Daganev2009-03-08 16:58:59
QUOTE (B_a_L_i @ Mar 8 2009, 01:54 AM) <{POST_SNAPBACK}>
AVG is fine, but if you ask anyone with some technical knowledge on the subject they'll probably recommend Eset over AVG. I have a friend who manages networks and he has nothing but good things to say about it.

http://www.anti-malware-test.com/?q=taxonomy/term/17/

Also, unlike AVG, those programs aren't takeover happy and aren't a pain in the butt to uninstall.


That link shows Avira being best, why do you say Eset is?
Unknown2009-03-09 02:34:18
QUOTE
AVG is fine, but if you ask anyone with some technical knowledge on the subject they'll probably recommend Eset over AVG. I have a friend who manages networks and he has nothing but good things to say about it. (Eset Nod32)


Biased I guess tongue.gif
Stangmar2009-03-09 23:57:58
Well, I took Bali's advice(That's scary ain't it?)

It seems to have worked so far. That CCleaner program looks fancy.