Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > Trojan.Vundo kills activation?

Reply
Thread Tools Display Modes

Trojan.Vundo kills activation?

 
 
Jay Moore
Guest
Posts: n/a

 
      06-29-2008
Ok, somehow..and don't ask me how...vundo managed to slip into what i
thought was a secure system..sure, Defender detected it...but it missed the
4 other DLL's the process made and let them through...now i'm sitting here
unable to detect it with scanners.

Im determined to kill it, but as of now it's screwed with my windows
activation. I rebooted and got Error 0xC004D301 - The security processor
reported that the trusted data store was tampered.

Assuming I get this cleaned...how much of a PITA is it going to be to get my
vista back to validated or at this point am I totally screwed and it won't
be able to be reactivated?

 
Reply With Quote
 
 
 
 
Jay Moore
Guest
Posts: n/a

 
      06-29-2008
nevermind...

vista didn't let the infection of vundo spread too deep...just 4 registry
entries and some dll files in a temp directory. activation asked for product
key...and reactivated.

"Jay Moore" <> wrote in message
news:0EF5F82E-53BA-4D95-AD91-...
> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed
> the 4 other DLL's the process made and let them through...now i'm sitting
> here unable to detect it with scanners.
>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.
>
> Assuming I get this cleaned...how much of a PITA is it going to be to get
> my vista back to validated or at this point am I totally screwed and it
> won't be able to be reactivated?


 
Reply With Quote
 
Kayman
Guest
Posts: n/a

 
      06-29-2008
On Sun, 29 Jun 2008 02:17:18 -0400, Jay Moore wrote:

> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed the
> 4 other DLL's the process made and let them through...now i'm sitting here
> unable to detect it with scanners.
>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.
>
> Assuming I get this cleaned...how much of a PITA is it going to be to get my
> vista back to validated or at this point am I totally screwed and it won't
> be able to be reactivated?


How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo.
http://www.bleepingcomputer.com/forums/topic18610.html
 
Reply With Quote
 
Mr. Arnold
Guest
Posts: n/a

 
      06-29-2008

"Jay Moore" <> wrote in message
news:0EF5F82E-53BA-4D95-AD91-...
> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed
> the 4 other DLL's the process made and let them through...now i'm sitting
> here unable to detect it with scanners.


http://www.physorg.com/news98802904.html

If you're not practicing safehex, then anything is possible. If the software
doesn't know about the other parts period, such as a signature to detect
them, as an example, then how is it suppose to detect anything, like DLL(s).

What happened to the anti-virus software, if one was installed? Why didn't
it catch anything? No solution is a stops all and ends all solution. And if
you think it's a stops all and ends all solution, then you have a false
sense of security. If the O/S can be fooled, then anything that runs with
the O/S can be fooled too.

http://www.claymania.com/safe-hex.html

>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.


Things have been tampered with, then what else has been tampered with or
running that is undetected?

http://technet.microsoft.com/en-us/l.../cc512587.aspx
<http://www.windowsecurity.com/articles/Hidden_Backdoors_Trojan_Horses_and_Rootkit_Tools_i n_a_Windows_Environment.html>
http://technet.microsoft.com/en-us/s...s/default.aspx

Currports (free) runs on Vista and Active Ports doesn't.

 
Reply With Quote
 
Jay Moore
Guest
Posts: n/a

 
      06-29-2008

"Kayman" <> wrote in message
news:...
> On Sun, 29 Jun 2008 02:17:18 -0400, Jay Moore wrote:
>


>
> How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo.
> http://www.bleepingcomputer.com/forums/topic18610.html


traditional methods DID NOT work. This is my second tango with this virus
dude.

 
Reply With Quote
 
Jay Moore
Guest
Posts: n/a

 
      06-29-2008

> What happened to the anti-virus software, if one was installed? Why didn't
> it catch anything? No solution is a stops all and ends all solution. And
> if you think it's a stops all and ends all solution, then you have a false
> sense of security. If the O/S can be fooled, then anything that runs with
> the O/S can be fooled too.



MS Defender did in fact pick up the original source dll..but the virus is
tricky and it actually can detect things like this....so it disguises
itself.

I've only found two or three AV programs that can pick up vundo. Norton,
McAfee, CA, Krapsersky....they will not. Spybot knows what it is, but can't
fix it.

 
Reply With Quote
 
V Green
Guest
Posts: n/a

 
      06-29-2008

"Jay Moore" <> wrote in message
news:0EF5F82E-53BA-4D95-AD91-...
> Ok, somehow..and don't ask me how...vundo managed to slip into what i
> thought was a secure system..sure, Defender detected it...but it missed the
> 4 other DLL's the process made and let them through...now i'm sitting here
> unable to detect it with scanners.
>
> Im determined to kill it, but as of now it's screwed with my windows
> activation. I rebooted and got Error 0xC004D301 - The security processor
> reported that the trusted data store was tampered.
>
> Assuming I get this cleaned...how much of a PITA is it going to be to get my
> vista back to validated or at this point am I totally screwed and it won't
> be able to be reactivated?
>


Yeah, this is one sumbitch to deal with.

After YEARS of not having any problems, it slipped
in on me via an older JAVA runtime with known vulnerabiities.

Keep JAVA up to date.


 
Reply With Quote
 
Jay Moore
Guest
Posts: n/a

 
      06-29-2008
you know, i found it apparently wasn't that hard to deal with. this is my
first go around with an infection on vista....but my second dealing with it.

vundofix, which worked last time, didn't find it...and i've posted to thier
message board with a detailed description of what happened...awaiting a
possible response.

it appars to *me*, and this is my somewhat uneducated guess, the process
tries to execute and windows explorer would crash...sometimes it'd be a DEP
issue, sometimes it would just crash. i never saw the actual popups.

i believe it wasn't able to spread too far because of this...there were some
registry entries and files..never left the temp folder...i forcably removed
the files in safe mode and and got all kinds of errors about couldn't find
'em....i did miss one, and after finding out where it was in hijackthis..got
rid of it and it's registry entries.

I haven't had any problems since then...so i was able to get rid of it using
more traditional methods without it continuing to self-replicate....no
explorer crashes....everything's running fine.
"V Green" <> wrote in message
news:...
>
> "Jay Moore" <> wrote in message
> news:0EF5F82E-53BA-4D95-AD91-...
>> Ok, somehow..and don't ask me how...vundo managed to slip into what i
>> thought was a secure system..sure, Defender detected it...but it missed
>> the
>> 4 other DLL's the process made and let them through...now i'm sitting
>> here
>> unable to detect it with scanners.
>>
>> Im determined to kill it, but as of now it's screwed with my windows
>> activation. I rebooted and got Error 0xC004D301 - The security processor
>> reported that the trusted data store was tampered.
>>
>> Assuming I get this cleaned...how much of a PITA is it going to be to get
>> my
>> vista back to validated or at this point am I totally screwed and it
>> won't
>> be able to be reactivated?
>>

>
> Yeah, this is one sumbitch to deal with.
>
> After YEARS of not having any problems, it slipped
> in on me via an older JAVA runtime with known vulnerabiities.
>
> Keep JAVA up to date.
>
>


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Pop Up hodges Windows Vista Security 4 06-17-2008 02:50 PM
MS Update kills MS IE7 Bob Windows Vista Performance 15 06-16-2008 09:05 AM
Help with a trojan Hope Windows Vista Security 2 03-10-2008 11:25 AM
trojan ghost Windows Vista Security 4 12-19-2007 06:08 PM
trojan? bigtez Windows Vista Security 6 08-29-2007 05:25 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59