Jump to content
The Dark Mod Forums

My Epic Battle with the Vundo Trojan


SplaTtzZ

Recommended Posts

Bit of a silly post really but i just spent the last couple of hours trying to remove this thrice-damned trojan from my computer which was really starting to piss me off. I was kind of surprised though at the resilience of some viruses and trojans these days towards being removed. I unkowingly infected my computer when i downloaded a serial generator trying to start a network multiplayer game with a friend of mine. Since i refuse to buy another copy of a game i already own just to play on a LAN i needed a second key. The file i downloaded off some dodgy site was a .rar with a notepad fiel and an .exe called 'keygen'. I scanned the file twice with norton, both packed and unpacked and ran the .exe which promptly did nothing. I knew something was up then, but i first saw the effects when norton kept blocking access to trojan.vundo

 

Apparently this file shows pop-ups and sends your internet history away to some ip address. Norton kept blocking its attempts but refused to remove it even after doing a deep scan twice. Symantec basically describes it as 'easy to block, but very difficult to remove', and none of its custom removal tools were working. I ended up disabling it at startup using msconfig and deleting its registry entry, only to find that something kept creating a new entry over and over again. In fact, it kept creating a new dynamic link library file in the windows folder under different grabled names, and then creating an assoicated registry key. Form what i gather there are heaps and heaps of different .dlls it can create. In the end after continually deletign things and restarting my comp I went into safe mode, blocked network traffic, removed the startup entries, deleted any associated .dll's and wiped the registry entries out before restarting. So far so good as the file hasn't attempted to access the net anymore and there are no more registry keys or startup entries. Finger's crossed it remains that way :unsure:

 

Maybe I'm just dumb and there's is an easy way to fix this problem but I was surprised at its resilience and the fact that very few programs and fixes I downloaded seemed to work. Anyone else had some crazy virus or trojan that was hard to kill? Maybe someone had the same problem as i did? if so I'd like to hear how you dealt with it.

 

Moral of the story: if you want to play LAN buy a second game and don't do the dodgy :(

Link to comment
Share on other sites

Yeah, I had this kind of problem.

Basically I went to a special forum dedicated to dealing with malware:

http://forums.spywareinfo.com/

 

You can read about my escapade if you want:

http://forums.spywareinfo.com/lofiversion/...php/t51518.html

 

I think they have a pretty solid system because these guys handle these problems over and over every day. You get a program called "Hijack This", run it, then post the log ... then one of the resident experts can read it and, pretty much no matter what it is, they'll know exactly what the problem(s) are from the log. Then they give you step by step instructions to get rid of it. Edit: As you can see the instructions they gave me were pretty elaborate, it was also a tenacious Trojan that had to have all its grabby tentacles cut and deleted in a special way before you could delete the trojan itself in another special way. But it got rid of it absolutely.

 

What I like about the site, beyond the generous help they give you, is the whole spirit of the place. You get the idea these guys despise malware with great passion. So it's good to see another face, a sympathetic human face, to cyberspace. They have training courses people can take to slowly but surely become resident experts. If I had the time & initiative, I think it'd be pretty cool to be trained to be a malware destroyer ... few things can bring out our humanity better than knowing how to make vicious malware go away for people that aren't technical, like my parents, it's like their greatest, sickening horror come-true that they will literally suffer from for days. And to make that go away for them, with simple step by step instructions, is like an act of pure compassion. :laugh:

Edited by demagogue

What do you see when you turn out the light? I can't tell you but I know that it's mine.

Link to comment
Share on other sites

If I had the time & initiative, I think it'd be pretty cool to be trained to be a malware destroyer ... few things can bring out our humanity better than knowing how to make vicious malware go away for people that aren't technical, like my parents, it's like their greatest, sickening horror come-true that they will literally suffer from for days. And to make that go away for them, with simple step by step instructions, is like an act of pure compassion. :laugh:

I've slain a few viruses at work. They pop up every week or so. It's really not that rewarding. ;)

 

'Course, we don't get anything tenacious, since we have Sophos installed everywhere and always 100% up to date, and it stops known malware from even being opened in the first place - no chance for it to get its tentacles in. Bit different to battling an entrenched hydra.

My games | Public Service Announcement: TDM is not set in the Thief universe. The city in which it takes place is not the City from Thief. The player character is not called Garrett. Any person who contradicts these facts will be subjected to disapproving stares.
Link to comment
Share on other sites

Yeah formatted successfully and the trojan is gone as far as i can tell. No more attempts to connect to an ip address nor any popups etc.

 

A hydra is the perfect metaphor for it in the respect that it kept coming back in different ways despite deleting numerous files and entries. What really kind of freaked me out was after i thought it was gone and it tried to recconnect again; it must have been operating under a different set of registry entries (which i couldn't find) and it was no longer creating .dll's in the system32 folder but a temporary internet one. There was no startup entry either for it to run so i couldn't figure out how it was starting up. It was as though the trojan learned what i was doing to attack it and adopted new tactics. :ph34r:

 

Maybe it was doing those things all along and I'm just paranoid, a couple of times norton had deleted files in that same temporary internet folder; but the majority of the time it was system32. Added to this is the fact that there was no startup or registry keys that I could find, which was also weird. It's worrying that someone could code these programs to adapt in that way. it's like we're only one step away from uber-viruses destroying the planet or something :huh:

 

Still my bank account is ok and my computer didn't have anything important on it, and generally norton is ok; I rarely visit dangerous websites except in great need, i usually only get an intrusion from the phishing ones that attack when you mispell a URL and norton blocks those. I think it was because I didn't think and actually ran the executable that the trojan got in.

Edited by SplaTtzZ
Link to comment
Share on other sites

Bit different to battling an entrenched hydra.

 

Yeah, it depends on your experience. My first experience was awful ... hours of running this and that program, thinking it's gone but then it comes back, then finally finding that site and being asked to do arcane things like deleting a file and stuff from the registry, reboot, run some 10kb file so I could then run killbox to delete the same file I already deleted again! ... then delete the same stuff I already deleted from the registry again ... reboot ... all the while crossing my fingers that this time it'll be gone. Blech!

Edited by demagogue

What do you see when you turn out the light? I can't tell you but I know that it's mine.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recent Status Updates

    • nbohr1more

      The FAQ wiki is almost a proper FAQ now. Probably need to spin-off a bunch of the "remedies" for playing older TDM versions into their own article.
      · 1 reply
    • nbohr1more

      Was checking out old translation packs and decided to fire up TDM 1.07. Rightful Property with sub-20 FPS areas yay! ( same areas run at 180FPS with cranked eye candy on 2.12 )
      · 3 replies
    • taffernicus

      i am so euphoric to see new FMs keep coming out and I am keen to try it out in my leisure time, then suddenly my PC is spouting a couple of S.M.A.R.T errors...
      tbf i cannot afford myself to miss my network emulator image file&progress, important ebooks, hyper-v checkpoint & hyper-v export and the precious thief & TDM gamesaves. Don't fall yourself into & lay your hands on crappy SSD
       
      · 7 replies
    • OrbWeaver

      Does anyone actually use the Normalise button in the Surface inspector? Even after looking at the code I'm not quite sure what it's for.
      · 7 replies
    • Ansome

      Turns out my 15th anniversary mission idea has already been done once or twice before! I've been beaten to the punch once again, but I suppose that's to be expected when there's over 170 FMs out there, eh? I'm not complaining though, I love learning new tricks and taking inspiration from past FMs. Best of luck on your own fan missions!
      · 4 replies
×
×
  • Create New...