Trojan Question

Trojan Question

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trojan Question wipeout64@hotmail.com 04-27-2007
Posted by David H. Lipman on May 1, 2007, 4:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| alright well I can site an example the name is trojan vundo / virtumonde
| please research on that one for future reference

It is the Vundo Trojan and the Virtumunde Adware. They are related any are in
the same
family. Most often they are installed via exploutaion of vulnerabilities found
in Sun Java.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?TWlsbyAoIE1TUFNTKQ== on May 1, 2007, 4:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
yes sir you are right about that - its the means of the loader to infect, but
we missed out the end product of it when it went through anyones security
application - that why not one AV in the world can take it out for the very
same reason that you have to suspend something ( 2 - 3 items exactly at the
same time just so to remove it and its 4 - 7 file scattered else where )
--
Milo
MSPSS - ESCA


"David H. Lipman" wrote:

>
> | alright well I can site an example the name is trojan vundo / virtumonde
> | please research on that one for future reference
>
> It is the Vundo Trojan and the Virtumunde Adware. They are related any are in
the same
> family. Most often they are installed via exploutaion of vulnerabilities
found in Sun Java.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on May 1, 2007, 4:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| yes sir you are right about that - its the means of the loader to infect, but
| we missed out the end product of it when it went through anyones security
| application - that why not one AV in the world can take it out for the very
| same reason that you have to suspend something ( 2 - 3 items exactly at the
| same time just so to remove it and its 4 - 7 file scattered else where )

There are numerous variants of the Vundo/Virtumonde and the Vundo has morphed at
lweast
three time over the last 2 years.

Traditional anti malware utilities do poorly with it but Atribuine's VundoFix
does very well
and is updated regurly.

VUNDOFIX.EXE - http://www.atribune.org/ccount/click.php?id=4

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?TWlsbyAoIE1TUFNTKQ== on May 1, 2007, 5:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes sir thats removal tool is effective to the potency of Vundo esp with
class K but it the vundo has stayed in someones PC for quite a bit of a time
like a week or two and the ad pop-ups is rising at 5-7 prompts at a time then
manual removal is the only way.

The irony of things it has been 2 years already hahaha and still treading on
with evolution hahaha - the vundofix or vundoaway are not as stable as manual
removal since they are only dependent to the signature or so the pattern
combination of it.

Well by far only Windows Onecare can detect the main instances of all the
4-7 dummy dll file it creates if it went through your PC. but still has to go
to manual Troubleshooting.
--
Milo
MSPSS - ESCA


"David H. Lipman" wrote:

>
> | yes sir you are right about that - its the means of the loader to infect, but
> | we missed out the end product of it when it went through anyones security
> | application - that why not one AV in the world can take it out for the very
> | same reason that you have to suspend something ( 2 - 3 items exactly at the
> | same time just so to remove it and its 4 - 7 file scattered else where )
>
> There are numerous variants of the Vundo/Virtumonde and the Vundo has morphed
at lweast
> three time over the last 2 years.
>
> Traditional anti malware utilities do poorly with it but Atribuine's VundoFix
does very well
> and is updated regurly.
>
> VUNDOFIX.EXE - http://www.atribune.org/ccount/click.php?id=4
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on May 1, 2007, 5:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Yes sir thats removal tool is effective to the potency of Vundo esp with
| class K but it the vundo has stayed in someones PC for quite a bit of a time
| like a week or two and the ad pop-ups is rising at 5-7 prompts at a time then
| manual removal is the only way.
|
| The irony of things it has been 2 years already hahaha and still treading on
| with evolution hahaha - the vundofix or vundoaway are not as stable as manual
| removal since they are only dependent to the signature or so the pattern
| combination of it.
|
| Well by far only Windows Onecare can detect the main instances of all the
| 4-7 dummy dll file it creates if it went through your PC. but still has to go
| to manual Troubleshooting.

OneCare is *JUNK* !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Trojan AAQN - question from a newbie September 16, 2008, 5:45 pm
AVG Free question July 27, 2005, 4:58 pm
Multi AV Question October 28, 2005, 12:36 am
Re: WMF Exploit question January 5, 2006, 3:31 pm
Re: WMF Exploit question January 5, 2006, 4:33 pm
just a quick question January 7, 2006, 1:50 pm
Question about AVG or AVAST February 16, 2006, 5:10 am
Mr. Pandaman, a question for you ? March 4, 2006, 5:01 pm
[Question] Glob BO April 26, 2006, 4:58 am
computer question August 5, 2006, 4:14 pm

The site map in XML format XML site map

Contact Us | Privacy Policy