Jump to content
The Dark Mod Forums

My Epic Battle with the Vundo Trojan


SplaTtzZ

Recommended Posts

Bit of a silly post really but i just spent the last couple of hours trying to remove this thrice-damned trojan from my computer which was really starting to piss me off. I was kind of surprised though at the resilience of some viruses and trojans these days towards being removed. I unkowingly infected my computer when i downloaded a serial generator trying to start a network multiplayer game with a friend of mine. Since i refuse to buy another copy of a game i already own just to play on a LAN i needed a second key. The file i downloaded off some dodgy site was a .rar with a notepad fiel and an .exe called 'keygen'. I scanned the file twice with norton, both packed and unpacked and ran the .exe which promptly did nothing. I knew something was up then, but i first saw the effects when norton kept blocking access to trojan.vundo

 

Apparently this file shows pop-ups and sends your internet history away to some ip address. Norton kept blocking its attempts but refused to remove it even after doing a deep scan twice. Symantec basically describes it as 'easy to block, but very difficult to remove', and none of its custom removal tools were working. I ended up disabling it at startup using msconfig and deleting its registry entry, only to find that something kept creating a new entry over and over again. In fact, it kept creating a new dynamic link library file in the windows folder under different grabled names, and then creating an assoicated registry key. Form what i gather there are heaps and heaps of different .dlls it can create. In the end after continually deletign things and restarting my comp I went into safe mode, blocked network traffic, removed the startup entries, deleted any associated .dll's and wiped the registry entries out before restarting. So far so good as the file hasn't attempted to access the net anymore and there are no more registry keys or startup entries. Finger's crossed it remains that way :unsure:

 

Maybe I'm just dumb and there's is an easy way to fix this problem but I was surprised at its resilience and the fact that very few programs and fixes I downloaded seemed to work. Anyone else had some crazy virus or trojan that was hard to kill? Maybe someone had the same problem as i did? if so I'd like to hear how you dealt with it.

 

Moral of the story: if you want to play LAN buy a second game and don't do the dodgy :(

Link to comment
Share on other sites

Yeah, I had this kind of problem.

Basically I went to a special forum dedicated to dealing with malware:

http://forums.spywareinfo.com/

 

You can read about my escapade if you want:

http://forums.spywareinfo.com/lofiversion/...php/t51518.html

 

I think they have a pretty solid system because these guys handle these problems over and over every day. You get a program called "Hijack This", run it, then post the log ... then one of the resident experts can read it and, pretty much no matter what it is, they'll know exactly what the problem(s) are from the log. Then they give you step by step instructions to get rid of it. Edit: As you can see the instructions they gave me were pretty elaborate, it was also a tenacious Trojan that had to have all its grabby tentacles cut and deleted in a special way before you could delete the trojan itself in another special way. But it got rid of it absolutely.

 

What I like about the site, beyond the generous help they give you, is the whole spirit of the place. You get the idea these guys despise malware with great passion. So it's good to see another face, a sympathetic human face, to cyberspace. They have training courses people can take to slowly but surely become resident experts. If I had the time & initiative, I think it'd be pretty cool to be trained to be a malware destroyer ... few things can bring out our humanity better than knowing how to make vicious malware go away for people that aren't technical, like my parents, it's like their greatest, sickening horror come-true that they will literally suffer from for days. And to make that go away for them, with simple step by step instructions, is like an act of pure compassion. :laugh:

Edited by demagogue

What do you see when you turn out the light? I can't tell you but I know that it's mine.

Link to comment
Share on other sites

If I had the time & initiative, I think it'd be pretty cool to be trained to be a malware destroyer ... few things can bring out our humanity better than knowing how to make vicious malware go away for people that aren't technical, like my parents, it's like their greatest, sickening horror come-true that they will literally suffer from for days. And to make that go away for them, with simple step by step instructions, is like an act of pure compassion. :laugh:

I've slain a few viruses at work. They pop up every week or so. It's really not that rewarding. ;)

 

'Course, we don't get anything tenacious, since we have Sophos installed everywhere and always 100% up to date, and it stops known malware from even being opened in the first place - no chance for it to get its tentacles in. Bit different to battling an entrenched hydra.

My games | Public Service Announcement: TDM is not set in the Thief universe. The city in which it takes place is not the City from Thief. The player character is not called Garrett. Any person who contradicts these facts will be subjected to disapproving stares.
Link to comment
Share on other sites

Yeah formatted successfully and the trojan is gone as far as i can tell. No more attempts to connect to an ip address nor any popups etc.

 

A hydra is the perfect metaphor for it in the respect that it kept coming back in different ways despite deleting numerous files and entries. What really kind of freaked me out was after i thought it was gone and it tried to recconnect again; it must have been operating under a different set of registry entries (which i couldn't find) and it was no longer creating .dll's in the system32 folder but a temporary internet one. There was no startup entry either for it to run so i couldn't figure out how it was starting up. It was as though the trojan learned what i was doing to attack it and adopted new tactics. :ph34r:

 

Maybe it was doing those things all along and I'm just paranoid, a couple of times norton had deleted files in that same temporary internet folder; but the majority of the time it was system32. Added to this is the fact that there was no startup or registry keys that I could find, which was also weird. It's worrying that someone could code these programs to adapt in that way. it's like we're only one step away from uber-viruses destroying the planet or something :huh:

 

Still my bank account is ok and my computer didn't have anything important on it, and generally norton is ok; I rarely visit dangerous websites except in great need, i usually only get an intrusion from the phishing ones that attack when you mispell a URL and norton blocks those. I think it was because I didn't think and actually ran the executable that the trojan got in.

Edited by SplaTtzZ
Link to comment
Share on other sites

Bit different to battling an entrenched hydra.

 

Yeah, it depends on your experience. My first experience was awful ... hours of running this and that program, thinking it's gone but then it comes back, then finally finding that site and being asked to do arcane things like deleting a file and stuff from the registry, reboot, run some 10kb file so I could then run killbox to delete the same file I already deleted again! ... then delete the same stuff I already deleted from the registry again ... reboot ... all the while crossing my fingers that this time it'll be gone. Blech!

Edited by demagogue

What do you see when you turn out the light? I can't tell you but I know that it's mine.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recent Status Updates

    • The Black Arrow

      Hey @nbohr1morehow come the zombies in The Dark Mod don't have a "resurrection" mechanic to it, similar to how Thief has it?
      They're quite a weak creature as of right now, it's merely a walking corpse that slashes you, making attacking them to kill them an actual strategy.
      Would be better if they had some cool mechanism to it that truly makes them a danger, such as the resurrection idea itself.
      · 2 replies
    • Ansome

      Query: when was the last time a zombie in a video game was unnerving or scary to you? I'm chipping away at my anniversary submission and I've been trying to gather opinions on the subject. I'm perfectly capable of lighting them well, changing their sfx, and creating effective ambience, but I'm worried that zombies at their core are just too overdone to be an effective payoff to the tension I'm creating.
      · 4 replies
    • nbohr1more

      The Lieutenant 3 is out! Congrats Frost_Salamander! ( raising awareness )
      · 2 replies
    • OrbWeaver

      Has anyone had any luck with textures from Polyhaven? Their OpenEXR normal maps seem too washed out and give incorrect shading in the engine.
      · 5 replies
    • datiswous

      I tried to upscale the TDM logo video. First try:

      briefing_video.mp4 You can test it ingame by making a copy of the core tdm_gui.mtr and place it in your-tdm-root/materials/ , then edit line 249 of that file into the location where you placed the new briefing.mp4 file.
      What I did was I extracted all the image files, then used Upscayl to upscale the images using General photo (Real-Esrgan) upscale setting and then turn it back into a video.
      I might have to crop it a bit, the logo looks smaller on screen (or maybe it's actually better this way?). My video editor turned it into a 16:9 video, which I think overal looks better than 1:1 video of original.
      · 1 reply
×
×
  • Create New...