PDA

View Full Version : VundoFix for the Virtumonde or Virtumondo


ajnin
07-29-2008, 12:16 PM
http://vundofix.atribune.org/

If that doesnt work.... wiki says to try:

If you wish to remove the virus completely on your own or if these methods do not work for you, you will need to determine which DLLs are being used by the virus and remove them. The DLL names can change since Vundo creates random names for its files. First off, run MSConfig. Check the Start Up and Services and disable anything with gibberish names. To be safe, run a Google search to determine if these are actually non virus related DLLs or not. In addition to disabling these, search for these DLLs on your machine and delete them. If you are unable to delete these files, keep track of them for deletion later. In any case, keep track of the DLL name for later. These are half of the DLLs associated with the virus.
The primary root of the problem lies in the BHO (Browser Helper Object) and this is the tricky part of removing the virus. You can determine which DLLs are tied to the virus by going to Tools->Internet Options->Programs->Manage Add-Ons (IE7). Scan through the list of add-ons and keep note of the suspicious ones. Again, do a quick search on Google to determine if these are legitimate DLLs. If not, then keep track of the name and location of those DLLs (though they are likely in Windows\System32). Disable these just in case.
Next, you'll need to reboot but utilize a clean bootup disk or alternative operating system (such as knoppix). Safe Mode may work for you, but some people will find Windows automatically loads the Browser Help Object DLLs even if you run in Safe Mode with Command Prompt only. In this case, it's impossible to remove those DLLs since they'll be "in use" and you must use a boot up disk or an alternative OS. Which ever the method you use, delete the all the DLLs you have noted as being associated with the virus.
Finally, reboot your machine in Windows normally. Run MSConfig to make sure nothing new is there (no more suspicious entries are enabled in your start up or services), then run Regedit. Run a search on every DLL associated with the virus and delete all keys tied to the DLL. Make sure you scan the entire registry for each one as they may show up more than once. Finally, do a search for "MS Juan" and delete all keys associated with that too. Reboot one more time and check to see if you can find any traces of the virus.


http://en.wikipedia.org/wiki/Vundo

Soren
07-29-2008, 12:30 PM
For people who dont know....

Signs of infection:

Usually when infected with Vundo the user is bombarded with popups for WinFixer, Amaena, WinAntiVirus, ErrorSafe, SystemDoctor and DriveCleaner. Downloading and running these Fraudware applications will result in a fake scan telling you that you are infected with malware then telling you that you need to buy their program to remove the malware that it found. DO NOT BUY THESE PROGRAMS. They are scams and will not remove anything but could possibly make your infection worse.

A slowdown in PC performance may also be noticed when Vundo is running as well as the possibility of random BSOD's.

Soren
07-29-2008, 12:32 PM
Another one to watch out for....

XP Antivirus 2008, XP Antivirus 2009, and XPAntiVirus are rogue antivirus programs that, when run, display false results as a tactic to scare you into purchasing the software. Older versions of XP Antivirus would create 9 entries in your Windows Registry that impersonate infections on your machine. In reality, though, these registry entries were harmless and had absolutely no effect on your computer. Instead, these entries were set so that XP AntiVirus can find them when scanning your computer and report them as infections. The newer of versions of the program , such as XP Antivirus 2008 and XP Antivirus 2009, instead just display false results when scanning your computer that state infections were found. In order to remove these fake infections, though, you would first need to purchase the software as the trial does not allow you to remove them.

Brewtt
07-31-2008, 06:36 PM
Who is the best? Soren is the best! [b]WHO is the best? SOREN is the best!!!

[/Brewtt sings]


Big thanks to Soren for killing a particularly nasty Virtumonde Trojen that I stupidly caught... plus some other horrible crap on my computer. Thanks also to ajnin for attack hints and some research when I was off-line and trying to kill this crap on my own. :)

YOU GUYS ROCK!

Love all you guys... great team... great family... FATAL!

Soren
08-06-2008, 10:03 PM
Use Superantispyware to remove these rootkits.

http://www.superantispyware.com/downloads/SUPERAntiSpyware.exe

Soren
08-26-2008, 10:03 AM
I've now been using superantispyware free for the last few weeks removing these spywares from my clients machines, works perfect... one complete scan wipes them all out. wooot!

HurtCow
08-29-2008, 03:05 PM
Thanks Soren! My office rig was acting stupid, superantispyware got it working right-

1 trojan
96 tracking cookies that Spybot didn't catch.