Go Back   Technology Questions > Software Questions > Operating System Questions > Vista Community > Windows Vista

Windows Vista Discuss the different versions of Windows Vista, Fuji, or Vienna

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 06-28-2008, 10:20 PM
Jay Moore
Tablet PC Guest
 
Posts: n/a
Trojan.Vundo kills activation?

Ok, somehow..and don't ask me how...vundo managed to slip into what i
thought was a secure system..sure, Defender detected it...but it missed the
4 other DLL's the process made and let them through...now i'm sitting here
unable to detect it with scanners.

Im determined to kill it, but as of now it's screwed with my windows
activation. I rebooted and got Error 0xC004D301 - The security processor
reported that the trusted data store was tampered.

Assuming I get this cleaned...how much of a PITA is it going to be to get my
vista back to validated or at this point am I totally screwed and it won't
be able to be reactivated?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 06-28-2008, 10:20 PM
Xploder HD Movie Player for PS3. Manage, convert and transfer media files between the PC and PS3.
  #2 (permalink)  
Old 06-28-2008, 11:40 PM
Jay Moore
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?

nevermind...

vista didn't let the infection of vundo spread too deep...just 4 registry
entries and some dll files in a temp directory. activation asked for product
key...and reactivated.

"Jay Moore" <dewdude******.com> wrote in message
news:0EF5F82E-53BA-4D95-AD91-F2C99F2C6B55@microsoft.com...
> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed
> the 4 other DLL's the process made and let them through...now i'm sitting
> here unable to detect it with scanners.
>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.
>
> Assuming I get this cleaned...how much of a PITA is it going to be to get
> my vista back to validated or at this point am I totally screwed and it
> won't be able to be reactivated?


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 06-28-2008, 11:40 PM
Kayman
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?

On Sun, 29 Jun 2008 02:17:18 -0400, Jay Moore wrote:

> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed the
> 4 other DLL's the process made and let them through...now i'm sitting here
> unable to detect it with scanners.
>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.
>
> Assuming I get this cleaned...how much of a PITA is it going to be to get my
> vista back to validated or at this point am I totally screwed and it won't
> be able to be reactivated?


How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo.
http://www.bleepingcomputer.com/forums/topic18610.html
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 06-28-2008, 11:40 PM
Mr. Arnold
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?


"Jay Moore" <dewdude******.com> wrote in message
news:0EF5F82E-53BA-4D95-AD91-F2C99F2C6B55@microsoft.com...
> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed
> the 4 other DLL's the process made and let them through...now i'm sitting
> here unable to detect it with scanners.


http://www.physorg.com/news98802904.html

If you're not practicing safehex, then anything is possible. If the software
doesn't know about the other parts period, such as a signature to detect
them, as an example, then how is it suppose to detect anything, like DLL(s).

What happened to the anti-virus software, if one was installed? Why didn't
it catch anything? No solution is a stops all and ends all solution. And if
you think it's a stops all and ends all solution, then you have a false
sense of security. If the O/S can be fooled, then anything that runs with
the O/S can be fooled too.

http://www.claymania.com/safe-hex.html

>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.


Things have been tampered with, then what else has been tampered with or
running that is undetected?

http://technet.microsoft.com/en-us/l.../cc512587.aspx
<http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_i n_a_Windows_Environment.html>
http://technet.microsoft.com/en-us/s...s/default.aspx

Currports (free) runs on Vista and Active Ports doesn't.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 06-29-2008, 06:40 AM
Jay Moore
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?


"Kayman" <kaymanDeleteThis@operamail.com> wrote in message
news:eLGJRmb2IHA.3884@TK2MSFTNGP05.phx.gbl...
> On Sun, 29 Jun 2008 02:17:18 -0400, Jay Moore wrote:
>


>
> How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo.
> http://www.bleepingcomputer.com/forums/topic18610.html


traditional methods DID NOT work. This is my second tango with this virus
dude.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #6 (permalink)  
Old 06-29-2008, 06:40 AM
V Green
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?


"Jay Moore" <dewdude******.com> wrote in message
news:0EF5F82E-53BA-4D95-AD91-F2C99F2C6B55@microsoft.com...
> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed the
> 4 other DLL's the process made and let them through...now i'm sitting here
> unable to detect it with scanners.
>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.
>
> Assuming I get this cleaned...how much of a PITA is it going to be to get my
> vista back to validated or at this point am I totally screwed and it won't
> be able to be reactivated?
>


Yeah, this is one sumbitch to deal with.

After YEARS of not having any problems, it slipped
in on me via an older JAVA runtime with known vulnerabiities.

Keep JAVA up to date.


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #7 (permalink)  
Old 06-29-2008, 06:40 AM
Jay Moore
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?


> What happened to the anti-virus software, if one was installed? Why didn't
> it catch anything? No solution is a stops all and ends all solution. And
> if you think it's a stops all and ends all solution, then you have a false
> sense of security. If the O/S can be fooled, then anything that runs with
> the O/S can be fooled too.



MS Defender did in fact pick up the original source dll..but the virus is
tricky and it actually can detect things like this....so it disguises
itself.

I've only found two or three AV programs that can pick up vundo. Norton,
McAfee, CA, Krapsersky....they will not. Spybot knows what it is, but can't
fix it.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #8 (permalink)  
Old 06-29-2008, 12:30 PM
Jay Moore
Tablet PC Guest
 
Posts: n/a
Re: Trojan.Vundo kills activation?

you know, i found it apparently wasn't that hard to deal with. this is my
first go around with an infection on vista....but my second dealing with it.

vundofix, which worked last time, didn't find it...and i've posted to thier
message board with a detailed description of what happened...awaiting a
possible response.

it appars to *me*, and this is my somewhat uneducated guess, the process
tries to execute and windows explorer would crash...sometimes it'd be a DEP
issue, sometimes it would just crash. i never saw the actual popups.

i believe it wasn't able to spread too far because of this...there were some
registry entries and files..never left the temp folder...i forcably removed
the files in safe mode and and got all kinds of errors about couldn't find
'em....i did miss one, and after finding out where it was in hijackthis..got
rid of it and it's registry entries.

I haven't had any problems since then...so i was able to get rid of it using
more traditional methods without it continuing to self-replicate....no
explorer crashes....everything's running fine.
"V Green" <vanceg@nowhere.net> wrote in message
news:eYNKmQf2IHA.4492@TK2MSFTNGP02.phx.gbl...
>
> "Jay Moore" <dewdude******.com> wrote in message
> news:0EF5F82E-53BA-4D95-AD91-F2C99F2C6B55@microsoft.com...
>> Ok, somehow..and don't ask me how...vundo managed to slip into what i
>> thought was a secure system..sure, Defender detected it...but it missed
>> the
>> 4 other DLL's the process made and let them through...now i'm sitting
>> here
>> unable to detect it with scanners.
>>
>> Im determined to kill it, but as of now it's screwed with my windows
>> activation. I rebooted and got Error 0xC004D301 - The security processor
>> reported that the trusted data store was tampered.
>>
>> Assuming I get this cleaned...how much of a PITA is it going to be to get
>> my
>> vista back to validated or at this point am I totally screwed and it
>> won't
>> be able to be reactivated?
>>

>
> Yeah, this is one sumbitch to deal with.
>
> After YEARS of not having any problems, it slipped
> in on me via an older JAVA runtime with known vulnerabiities.
>
> Keep JAVA up to date.
>
>


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
vundo virus richiegodsmack@hotmail.com Windows XP 27 09-02-2008 10:41 AM
Windows XP Virus with vturq.dll and qrutv.ini, Vundo Summercool Windows XP 7 10-26-2007 12:30 PM
Virus with vturq.dll and qrutv.ini, Vundo? Summercool Windows XP 7 10-14-2007 10:30 PM
Backdoor Win32/Vundo.G!dll Sandy Windows XP 8 03-17-2007 04:00 PM
Rodent Kills Harry Drane Windows Vista 5 02-03-2007 12:00 PM


All times are GMT -8. The time now is 02:26 AM.


2003 - 2008 All Rights Reserved. Technology Questions

SEO by vBSEO 3.1.0