PDA

View Full Version : New virus: vundo/virtumonde


Meatwad
26-06-2007, 09:20 PM
And I'm infected. it dramatically decreases system response time, as well as sending random popups. since I've had this, I've also spotted some files from other well known spyware/malware such as zedo, whenu save, coolwwwsearch, and smitfraud-c.

now, removal of viruses isn't really usually an issue for me, but this one really is. there's a few files that are associated with vundo/virtumonde, usually gebcy.dll and khfecax.dll in system32.

the main problem with removing it isn't finding the file and removing it, it's getting it to stop coming back. You can easily remove it with the fix ad-aware made, but it comes back. And when it comes back, it cripples your antivirus/scanners. It's getting incredibly annoying/frustrating. Can't even do anything about it in safe mode, since it attaches to winlogon.exe.

There's several "fixes" you can find on google, but none of them work. so I'm asking for help here. can anybody think of ANYTHING? I've exhausted every single option I can think of to no avail. HALP

The Visioneer
26-06-2007, 09:26 PM
I know it'd obvious, but have you tried doing it in safe mode? That way, the virus isn't opened on start up, and shouldn't be able to come back in theory

Meatwad
26-06-2007, 10:04 PM
It injects itself into winlogon.exe

safe mode was useless, and was infact the first thing I tried.

Mercury126
26-06-2007, 10:14 PM
I think its nearly impossible to remove manually, does this (http://www.broadbandreports.com/faq/13331) help by any chance?

Meatwad
26-06-2007, 11:51 PM
Already tried vundofix, but it wasn't meant for the newest variation of vundo/virtumonde. They've had old adware/malware in the past, but nothing like this.

I might just have to reformat soon if it doesn't go away....

Bewildebeast
26-06-2007, 11:54 PM
Repair Install?

Meatwad
26-06-2007, 11:55 PM
that's worth a shot, I'll go have a whack at that.

The Grim Reaper
27-06-2007, 05:20 AM
NOD32 ftw :)

How did you get it?

Meatwad
27-06-2007, 06:14 PM
not sure. woke up one morning, and there it was. Was probably an extra surprise in something I downloaded

Pilk Man
27-06-2007, 11:38 PM
Repair Install?
sounds useful to know, how does one do such?

Timmeh
27-06-2007, 11:51 PM
Tried a boot disk to a command line OS like DOS? You should be able to remove all the nasties there without it being able to inject itself into winlogon.

johnny homicide
01-07-2007, 08:50 PM
harken to me!!!!! you must download AVG!!!! the lord of all virus removal go to

grisoft.com/doc/31/us/crp/0

download the free version and you can also get the anti-spyware version and with them you can tackle any foken virus or spy ware you get