<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Virtumonde, would someone please shoot these guys? in Security</title>
<link>http://www.dslreports.com/forum/r19702820</link>
<description></description>
<language>en</language>
<pubDate>Wed, 10 Feb 2010 04:31:06 EDT</pubDate>
<lastBuildDate>Wed, 10 Feb 2010 04:31:06 EDT</lastBuildDate>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19902561</link>
<description><![CDATA[<A HREF="/useremail/u/1524851"><b>RonnieO</b></A> : Ok Grrrrrrrr  I got it (well my daughter got it for me) how can I get rid of this POS. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19902561</guid>
<pubDate>Wed, 30 Jan 2008 12:08:40 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19758977</link>
<description><![CDATA[<A HREF="/useremail/u/1303852"><b>zteardrop</b></A> : <div class="bquote"><small>said by steve 123 :</small><br><br>supz all. i recently got back from christmas and i downloaded a few movies with mininova.org soon after i went to check progress of dls found this wierd crap on ma comp all icons were highlighted and little red x in taskbar. having been infected by this retarded thing b4 i ran adaware found was virtomonde again so ran vundofix as already had it. says it found it removerd it rebooted was still on comp. i was looking in the regisrty there was a gebcb,dll or something that i cannot get rid of. looking on internet all the forums i guess new version  of this bullshit is out thre. ive tried prob 9 diff spyware removal programs none work. how the fuck do i get rid of this thing have 4 comps all together this the only one thats infected thank god. help plz<br> </div>What security product were you running when you got infected ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19758977</guid>
<pubDate>Tue, 08 Jan 2008 00:07:19 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19753546</link>
<description><![CDATA[<A HREF="/useremail/u/1515854"><b>darthboy</b></A> : Some pirated movies require a license to play. Meaning: they're protected by DRM. (note the irony)<br><br>The Windows Media Player will popup a screen when phoning home to retrieve a license. You'll see porn ads in this screen, and there may be many popups to websites that contain malicious code aka drive-by attack.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19753546</guid>
<pubDate>Mon, 07 Jan 2008 06:57:34 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19718420</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : <div class="bquote"><small>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Do you know how you got it (or rather the machine on which you found it?)  Most cases I have seen are a result of downloading pirated software and/or P2P networks downloaded files.<br></div>Keygen downloads from some wellknown offending sites-(Crack.exe+install.exe+serial.exe+keygen.exe)= around187kb<br><br>Install.exe is Virut and keygen.exe is the Vundo dropper;) <br><br>(keygen.exe+patch.exe+serial.exe)= around 187kb again<br><br>Again Keygen.exe is the Vundo dropper.<br><br>LMK if you don't recognize the file series and i will collect together a list of offending urls for you:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19718420</guid>
<pubDate>Tue, 01 Jan 2008 11:43:13 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19715767</link>
<description><![CDATA[<A HREF="/useremail/u/864682"><b>ghost16825</b></A> : <div class="bquote"><small>said by  NyQuil Kid <A HREF="/useremail/u/280527"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>There is no "one size fits all" solution - some infections are worth the time to clean, others aren't - any position to the contrary merely reflects a degree of laziness or an inability to effectively deal with this problem.</div>Today, a flatten and rebuild should be the preferred course of action and any kind of malware 'clean' an exception rather than a rule. Things have changed - now there is usually not enough certainty that a compromised box, after a 'clean' is still fully under your control.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19715767</guid>
<pubDate>Mon, 31 Dec 2007 19:19:38 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19715409</link>
<description><![CDATA[<A HREF="/useremail/u/197199"><b>Doctor Four</b></A> : This ought to include Innovative Marketing, the lowlifes<br>behind all the WinFixer variants, many of which often get<br>distributed with Vundo.<br><br>Incidentally, Virtumundo.com, a website known in the past<br>for spamming (they still do), is noted in the MVPS hosts<br>file as being associated with Virtumonde - the comment next<br>to that entry reads Panda.Virtumonde.C. Yet neither McAfee<br>Siteadvisor nor Google flags the site as being potentially<br>harmful - the former even gives it a green rating.<br><small>--<br>"The trouble with computers, of course, is that they are very sophisticated idiots." - Doctor Who (from Robot)<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19715409</guid>
<pubDate>Mon, 31 Dec 2007 18:19:40 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19715103</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : I would <b>never</b> depend on the browser as a tool of last resort against the zero-day (so-called) exploit.<br><br>Some solutions:<br><br>1) A Sandbox-type application will contain/remove the exploit<br><br>2) Configuring Software Restriction Policies<br><br>3) Less complex would be to set up the user with a Limited User account<br><br>4) Also simple: application with protection against the downloading/installing/running of non-White Listed executables<br><br>In the above cases, any remote code executed malware that gets past the browser is prevented from doing any damage. <br><br>These have been tested by myself and others at known malware sites -- in some cases, with unpatched IE browser to permit the exploit to attempt to run the payload.<br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19715103</guid>
<pubDate>Mon, 31 Dec 2007 17:31:36 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19714961</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>This is the easiest attack to prevent via numerous solutions; that's why I said there is no reason for it to happen.<br><br>----<br>rich<br> </div>Until, of course, the next zero-day drive-by exploit is delivered AND the browser(s) is patched. That could be weeks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19714961</guid>
<pubDate>Mon, 31 Dec 2007 17:01:05 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19714452</link>
<description><![CDATA[<A HREF="/useremail/u/280527"><b>NyQuil Kid</b></A> : By your reaction, the following is pretty clear:<br><br>a) I'm right<br>b) I'm funny<br>c) You were dropped as a baby, or were born near power lines<br><br>Thank you for proving my point.<br><br>[8F] The NyQuil Kid<br><small>--<br>[8F] The NyQuil Kid comes into town not looking for trouble...n00bz gang up, but he ain't seein' double,...pulls and draws, his deagles two...n00bz litter the ground you know it's true.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19714452</guid>
<pubDate>Mon, 31 Dec 2007 15:32:22 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19714270</link>
<description><![CDATA[<A HREF="/useremail/u/804362"><b>qrkx</b></A> : <div class="bquote"><small>said by  NyQuil Kid <A HREF="/useremail/u/280527"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>There is no "one size fits all" solution - some infections are worth the time to clean, others aren't - any position to the contrary merely reflects a degree of laziness or an inability to effectively deal with this problem.<br><br>[8F] The NyQuil Kid<br> </div>Ok. Fair enough.<br><br>I thought there was a very simple "one size fits all" solution to a compromised host. Once again - I was terribly wrong. The old school is dead!<br><br>rgds]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19714270</guid>
<pubDate>Mon, 31 Dec 2007 15:01:47 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19714242</link>
<description><![CDATA[<A HREF="/useremail/u/280527"><b>NyQuil Kid</b></A> : Because it can be almost as time consuming to back up data, wipe the drive, reinstall ALL your applications, then copy your data back and tweak all your settings.  Computer savvy people may not mind doing that, but the average Joe (which is usually the main victim/target of such infections) with thousands of family pics, files etc isn't in a position to do the aforementioned procedure every time they get an infection.<br><br>There is no "one size fits all" solution - some infections are worth the time to clean, others aren't - any position to the contrary merely reflects a degree of laziness or an inability to effectively deal with this problem.<br><br>[8F] The NyQuil Kid<br><small>--<br>[8F] The NyQuil Kid comes into town not looking for trouble...n00bz gang up, but he ain't seein' double,...pulls and draws, his deagles two...n00bz litter the ground you know it's true.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19714242</guid>
<pubDate>Mon, 31 Dec 2007 14:57:43 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19714172</link>
<description><![CDATA[<A HREF="/useremail/u/804362"><b>qrkx</b></A> : <div class="bquote"><small>said by  trparky <A HREF="/useremail/u/161242"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Would someone please shoot these guys?  They need to be shot at dawn!<br></div>Don't shoot just yet!<br><br>These "guys" are doing us a great favour. I love malware that is so noisy you don't have to make any effort to identify its presence. Once the aforementioned accomplished - wipe zee box und start all over - until lesson learned. Rinse and repeat.<br><br>Why would you even try to "clean" a compromised host is the question at hand...<br><br>rgds]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19714172</guid>
<pubDate>Mon, 31 Dec 2007 14:47:18 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713886</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  TheRul <A HREF="/useremail/u/1487982"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br><div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>  :</small><br><br>No reason for that to happen, ever.<br><br>----<br>rich<br> </div>Tell me that was sarcasm. </div><br>It was not meant to be.<br><br><div class="bquote"><small>said by  TheRul <A HREF="/useremail/u/1487982"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br> You have dealt with end users at one time in your life, right? </div><br>I have and still do. My comment was about getting malware through remote code execution, aka, drive-by downloads.<br><br>This is the easiest attack to prevent via numerous solutions; that's why I said there is no reason for it to happen.<br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713886</guid>
<pubDate>Mon, 31 Dec 2007 13:57:13 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713704</link>
<description><![CDATA[<A HREF="/useremail/u/1487982"><b>TheRul</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>No reason for that to happen, ever.<br><br>----<br>rich<br> </div>Tell me that was sarcasm.  You have dealt with end users at one time in your life, right?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713704</guid>
<pubDate>Mon, 31 Dec 2007 13:26:42 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713584</link>
<description><![CDATA[<A HREF="/useremail/u/280527"><b>NyQuil Kid</b></A> : You forgot to mention how the AV companies, in conjunction with the Mafia and Cuba, shot JFK, faked the moon landing, and  caused 9-11....<br><br>By the way, were you born near power lines or perhaps dropped as a baby by your parents....<br><br>[8F] The NyQuil Kid<br><small>--<br>[8F] The NyQuil Kid comes into town not looking for trouble...n00bz gang up, but he ain't seein' double,...pulls and draws, his deagles two...n00bz litter the ground you know it's true.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713584</guid>
<pubDate>Mon, 31 Dec 2007 13:02:10 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713285</link>
<description><![CDATA[<A HREF="/useremail/u/770196"><b>major marco</b></A> : <div class="bquote"><small>said by  trparky <A HREF="/useremail/u/161242"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>No time in history have I ever wanted to say that a group of people needs to be put in front of a firing squad and shot at dawn, but this has got to be it.<br><br>Would someone please get the people who wrote this nasty thing and shoot them at dawn?<br><br> </div>You'd be decimating an entire industry if the virii writers were executed!  Besides, who do you think these folks work for?  That's right, say it with me:  The AV companies.  McAfee, Norton, et al. <br><small>--<br><b><A HREF="http://icasualties.org/oif/BY_DOD.aspx">The Toll</a></b><br><br>Let's Go Flyers!<br></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713285</guid>
<pubDate>Mon, 31 Dec 2007 12:09:59 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713256</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  TheRul <A HREF="/useremail/u/1487982"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>My guess is that it was not only movies that he dl's.  He just found it while dl'ing the movies. </div><br>If so, a malicious executable file downloaded by remote code execution.<br><br>No reason for that to happen, ever.<br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713256</guid>
<pubDate>Mon, 31 Dec 2007 12:05:18 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713224</link>
<description><![CDATA[<A HREF="/useremail/u/1037783"><b>Woody79_00</b></A> : Yes i have ran into this nasty and let me tell you, it is definitely no picnic to remove. Since im computer savy enough to handle editing the registry manually and such, i have been able to get rid of them...although it takes a long time<br><br>I have seen a few of these nasties hidden with a rootkit...really sucks let me tell ya..need something like Icesword or something similar to sniff that thing out 1st...since what is hidden keeps re spawning the infection.<br><br>Believe it or not...Windows Defender from Microsoft is pretty darn effective against Vundo in my expereince..it seems it fares better against it than any of the other apps ie SuperAntiSpyware, webroot, etc...Microsoft gets a 1up on everyone because they find out about new nasties before anyone else it seems...probably because of tech support calls and other methods.<br><br>As crazy as it sounds, I know Windows Defender is able to delete and clean files other apps can;t..Microsoft probably has a reserved set of api's for it or something who knows, but i have found Windows Defender can delete files in use that apps like Webroot, SuperAntiSpyware and others can't<br><br>Other than Windows Defender, The app i recommend using to fight this nasty Trojan is none other than A2...its a dedicated Anti-Trojan..well over a million pieces of malware in its database..chances are these Vundo infections are known about it its database<br><br>If you are infected, Update a2 boot into safe mode and run a deep scan...more than likely a2 will be able to wipe it out most of the time...i'd say 9/10 times...the other 1 time...Windows Defender...i know it sounds nuts, But Windows Defender scans work quite well against Vundo for some reason....it sounds crazy, but it does<br><br>Good luck to all in fighting this nasty thing...i absolutly cringe everytime i see a comp infected with this darn thing.<br><br>Please note i have cleaned Vundo off of pc's that it completly "crippled" apps like McAfee and Norton, real protection disabled and not able to be turned back on..also these Vundo's have crippled their firewall as well.<br><br>That why i "never" ever execute unsafe files from sources im not sure of..jotti and virus total to check them out, search for forums, ask opinions, etc..make informed decisions before executing any file.<br><br>my rule of thumb..treated "every"web site and file like a criminal until it is proven it is trust worthy]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713224</guid>
<pubDate>Mon, 31 Dec 2007 11:59:31 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713174</link>
<description><![CDATA[<A HREF="/useremail/u/1487982"><b>TheRul</b></A> : My guess is that it was not only movies that he dl's.  He just found it while dl'ing the movies.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713174</guid>
<pubDate>Mon, 31 Dec 2007 11:49:13 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19713002</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by steve 123 :</small><br><br> i downloaded a few movies with mininova.org soon after i went to check progress of dls found this wierd crap on ma comp ... i ran adaware found was virtomonde again... </div><br>How does this virus get installed as a movie is being downloaded?<br><br>----<br>rich]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19713002</guid>
<pubDate>Mon, 31 Dec 2007 11:13:56 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19712508</link>
<description><![CDATA[<A HREF="/useremail/u/1150241"><b>wxboss</b></A> : A trek to the Security Cleanup forums is in order. &raquo;<A HREF="/forum/cleanup">Security Cleanup</A><br><br>This sucker is pretty nasty, and you'll need their expertise to get rid of it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19712508</guid>
<pubDate>Mon, 31 Dec 2007 09:17:41 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19712485</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : supz all. i recently got back from christmas and i downloaded a few movies with mininova.org soon after i went to check progress of dls found this wierd crap on ma comp all icons were highlighted and little red x in taskbar. having been infected by this retarded thing b4 i ran adaware found was virtomonde again so ran vundofix as already had it. says it found it removerd it rebooted was still on comp. i was looking in the regisrty there was a gebcb,dll or something that i cannot get rid of. looking on internet all the forums i guess new version  of this bullshit is out thre. ive tried prob 9 diff spyware removal programs none work. how the fuck do i get rid of this thing have 4 comps all together this the only one thats infected thank god. help plz]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19712485</guid>
<pubDate>Mon, 31 Dec 2007 09:12:03 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19707559</link>
<description><![CDATA[<A HREF="/useremail/u/161242"><b>trparky</b></A> : <div class="bquote"><small>said by  mysec <A HREF="/useremail/u/1295721"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Meanwhile -- There is really no reason for anyone to be a victim of Virtumonde/Winfixer or anything similar. We can help by informing those users/clients we work with.</div>I tell people that most ads (95%) that you see on the Internet for antivirus or antispyware software is bad and that they shouldn't listen to them.<br><br>A legitimate antivirus or antispyware company wouldn't advertise in that way.<br><small>--<br>Tom</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19707559</guid>
<pubDate>Sun, 30 Dec 2007 09:33:25 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19706088</link>
<description><![CDATA[<A HREF="/useremail/u/1295721"><b>mysec</b></A> : <div class="bquote"><small>said by  trparky <A HREF="/useremail/u/161242"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>    :</small><br><br>Apparently there is a new variant of this crap that uses a different way to infect startup applications, namely the "trillain .exe" thing. </div><br>There are at least three methods of installation that we can make users aware of.<br><br>The first two, Calamity Jane has mentioned. If a user was compromised in those ways, well, what can one say? You have to know your sources.<br><br>Another way is being tricked by remote code execution, aka Drive-by Download.<br><br>Prior to Winfixer/Virtumonde, numerous exploits abounded preying on users being tricked by pop-up ads, or banner ads.<br><br>etrust spyware described one:<br><br>    <blockquote><small>quote:</small><hr>The ad appears to be an application interface, when in fact it is a popup ad in which the entire gif file is a hyperlink. Whether intentionally or unintentionally, clicking on the popup ad leads to the forced install of <b>BundleAJ_W1.exe</b>, which includes MySearch Toolbar and Registry Cleaner, an adware application that claims to find errors in the system's registry. <hr></blockquote><br><br><br>This is the code:<br><textarea name="code" class="text" cols=50 rows=10>script&#012;sClickUrl = 'http://certified-safe-downloads.com/adserver/BundleAJ_W1.exe &#012;sTrackingUrl = 'http://certified-safe-downloads.com/&#012;</textarea><!--end code block--><br><div class="bquote"><small>said by badmondo    :</small><br><br>People need to know that their "trusted" real-time antivirus antispyware will not protect them against this, </div><br>Since the forced install is an executable -- as <b> trparky <A HREF="/useremail/u/161242"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A></b> notes the presence of "trillian.exe" -- then solutions are obvious. If XP, running as Limited User, or with SRP stops this method in its tracks. I understand Vista has something similar.<br><br>A third party execution prevention application also stops this, as my screenshot shows using the example described by etrust.<br><br><div class="bquote"><small>said by  trparky <A HREF="/useremail/u/161242"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>   :</small><br><br>Would someone please get the people who wrote this nasty thing and shoot them at dawn?</div><br>Someone else would just take their place!<br><br>Meanwhile -- There is really no reason for anyone to be a victim of Virtumonde/Winfixer or anything similar. We can help by informing those users/clients we work with.<br><br>----<br>rich<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/19706088?c=1257431&ret=L2ZvcnVtL3IxOTcwMjgyMC54bWw%3D"><IMG class="apic" BORDER=0 TITLE="31118 bytes" WIDTH=600 HEIGHT=385 SRC="/r0/download/1257431.thumb600~d9e82004c7ed8bf9ef4f551ed803768d/virtum_2.gif/thumb.jpg" ALT="Click for full size"></A><br>Blocking BundleAJ_V1.exe</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19706088</guid>
<pubDate>Sat, 29 Dec 2007 22:51:12 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19706051</link>
<description><![CDATA[<A HREF="/useremail/u/1016963"><b>Anonymous</b></A> : All they have to do is follow the money. Someone is paying these guys to show their ads.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19706051</guid>
<pubDate>Sat, 29 Dec 2007 22:42:52 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19705305</link>
<description><![CDATA[<A HREF="/useremail/u/161242"><b>trparky</b></A> : <div class="bquote"><small>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Do you know how you got it (or rather the machine on which you found it?)  Most cases I have seen are a result of downloading pirated software and/or P2P networks downloaded files.</div>I've never got it myself but I've had to, on more than a couple of occasions, remove it from computers that I've worked on.<br><br>This thing is a royal PITA to remove.<br><br>Apparently there is a new variant of this crap that uses a different way to infect startup applications, namely the "trillain .exe" thing.<br><br>I have an idea about how it's loading into the system, specifically the AppInit section of the registry.  This isn't the first time that viruses have done this, this is nothing new.  I've seen it before.  That's how it loads the DLLs into the thread space of various programs.<br><br>I'd like to get a sample of this nasty in a ZIP file just to see what AV/AS software packages find it.<br><small>--<br>Tom</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19705305</guid>
<pubDate>Sat, 29 Dec 2007 20:11:15 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19704095</link>
<description><![CDATA[<A HREF="/useremail/u/1278118"><b>ftthz</b></A> : well... the difference between a rootkit and virtumonde is that a rootkit will try to run undetected so the user does not suspect they are infected while virtumonde will blast ads and popups to you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19704095</guid>
<pubDate>Sat, 29 Dec 2007 15:33:39 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19703546</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I agree.  It seems most anitvirus/antispyware fail miserably anainst virtumonde, especially the new variants.  I am not sure why this does not get more attention, as a large percentage of infections is due to this.  We worry about rootkits but virtumonde infections are causing the majority of borked computers compared to other types of malicous stuff.  If I am wrong on this let me know.  It is a dirty little secret the vendors of antivirus/antispyware sofware do not want the home user to know.<br><br>It would be good/interesting to know which antivirus and anitspyware apps are best at 1)preventing 2)identifying and 3)removing known variants especially the new ones.  This will show how miserably they all fail to protect your pc.  This might shame a few of the vendors into action.<br><br>People need to know that their "trusted" real-time antivirus antispyware will not protect them against this, and that once you get it removal will be a pain.  This has helped create specialized malware removal forums on the web.<br><br>The true seriousness of this threat needs to be addressed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19703546</guid>
<pubDate>Sat, 29 Dec 2007 13:15:27 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19703074</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Yep, it's a new variant of Vundo that infects startup programs and other files and it is a bear to remove for sure.<br><br>Do you know how you got it (or rather the machine on which you found it?)  Most cases I have seen are a result of downloading pirated software and/or P2P networks downloaded files.<br><br>We've been dealing with this for about a month now and it's getting really worse.  Here is one of the first writeups on it by our member here  Schouw <A HREF="/useremail/u/818836"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.  This was the first nasty variant of this file infector - it is now using the method of creating those files you see with spaces in the name rather than in the temp folder.<br><br>From Kaspersky researcher Roel Schouwenberg aka Schouw:<br> &raquo;<A HREF="http://blogger.xs4all.nl/klab/archive/2007/12/02/329779.aspx" >blogger.xs4all.nl/klab/archive/2&middot;&middot;&middot;779.aspx</A> <br>   <blockquote><small>quote:</small><hr>Virtumonde/Vundo goes file infector <br> <br>Last night I was having a look at the latest developments coming from the<br>Virtumonde authors.<br>The latest trick is using file infection to make removal even more<br>difficult. Coming from one of the most notoriously tricky to remove malware<br>I was expecting quite the handful.<br> <br>Like some other malware this version of Virtumonde enumerates which files<br>are being run at Windows startup. It will check the files and if deemed OK<br>for infection it will start the infection routine.<br> <br>What Virtumonde is basically doing is creating a Trojan-Dropper. It will<br>drop the original host file into %temp% and start the file from there. Next<br>to that it will drop the Virtumonde component into the system directory.<br> <br>The dropped DLL in the system directory will do its Virtumonde-like thing as<br>well as look for files to infect(from startup). So, this is not a patcher.<br>This is a virus.<br> <br>About 4KB of dropper code is prepended in front of the host file. The<br>Virtumonde DLL gets appended to the host file. The DLL is about 32KB large,<br>but the exact size of appended code may vary. It also makes use of an<br>infection marker in the resource section to make sure it does not reinfect<br>the same file time and time again.<br> <br>The original host file sits unaltered inside the newly created exe which<br>makes disinfection quite easy.<br>Something tells me that their next attempt is going to be more tricky to<br>handle. <br> <hr></blockquote><br><br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19703074</guid>
<pubDate>Sat, 29 Dec 2007 11:30:50 EDT</pubDate>
</item>

<item>
<title>Re: Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19702939</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : and you can see the nasty being battled and the amount of effort required to defeat it<br>&raquo;<A HREF="/forum/cleanup">Security Cleanup</A><br><br>Cudni]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19702939</guid>
<pubDate>Sat, 29 Dec 2007 10:59:06 EDT</pubDate>
</item>

<item>
<title>Virtumonde, would someone please shoot these guys?</title>
<link>http://www.dslreports.com/forum/remark,19702820</link>
<description><![CDATA[<A HREF="/useremail/u/161242"><b>trparky</b></A> : No time in history have I ever wanted to say that a group of people needs to be put in front of a firing squad and shot at dawn, but this has got to be it.<br><br>Would someone please get the people who wrote this nasty thing and shoot them at dawn?<br><br>I'll be the first to admit that I've done removals of viruses and other kinds of malware quite easily but this has got to be the worst, most insidious piece of malware yet.<br><br>If you don't know the extent of how far this thing goes, I'll explain.<br><br>If you have a machine that's infected with Virtumonde and you have the proper tools to see the infection in action, you'll notice several different rogue threads in processes such as SVCHOST.EXE, winlogon.exe, Explorer.exe, and other various system processes.  Yep, this insures that if you delete the files in question, they get put right back on the machine after you reboot.  I don't know right now if the thing re-infects the machine in real-time, if it does... then it's worse than I thought since now you can't even do the removal in normal Windows.<br><br>Oh, and don't get me started on the fact that this thing actively creates what are called "wrapper" executables in which say you have a program called Trillian, meaning trillian.exe.  If you have a machine infected with Virtumonde, it renames the main trillian.exe to "trillian .exe" (take note of the space in the file name) and creates a new file of the same name which is nothing more than a execution wrapper file that gets loaded, re-infects the machine, and executes trillian.exe.<br><br>Yep, that's right... you could get the whole machine clean but if you don't get every single of one these wrapper executables you'll have a re-infected machine on your hands in a heartbeat.<br><br>Would someone please shoot these guys?  They need to be shot at dawn!<br><small>--<br>Tom</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,19702820</guid>
<pubDate>Sat, 29 Dec 2007 10:33:42 EDT</pubDate>
</item>

</channel>
</rss>
