Hit By Vundo And Winantispy

this Topic has been closed.

I know that there is additional trash in the registry - but it does not appear to matter.

Writeup By: Henry Bell and Eric Chien Summary| Technical Details| Removal Search Threats Search by nameExample: [email protected] INFORMATION FOR: Enterprise Small Business Consumer (Norton) Partners OUR OFFERINGS: Products Products A-Z Services GEOGRAPHICAL DISTRIBUTION Symantec has observed the following geographic distribution of this threat. Hope these thoughts help. This was found via Google WinFixer 2005 free download.

The mass-mailing worms [email protected] and [email protected] are known to download variants of this threat family on to compromised computers. This trace was made 01-21-06 - it is similar to the SystemDoctor trace made 11-09-06 tracert winfixer.com Tracing route to winfixer.com []

Turn off (or reset) the machine. Infection Trojan.Vundo, also known as VirtuMonde, VirtuMundo, and MS Juan, typically arrives by way of spam email or is hoisted onto the user’s computer by a drive-by download that exploits a Of course, unless you search the internet for the correct terms, there is no way to know how to uninstall this crap. (I eventually figured it out) The Antivirus Crowd In https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Trojan%3AWin32%2FVundo.gen!AU The adminstrators there are working to get rid of it.

and they simple stole lots of money. say 200-400??? It contacts remote the host nx1.mslivelogin.com in order to receive directives.

This program will allow you to identify and kill new variants. A few minutes later, it changed back to the old address. Of course, clicking on renew sent you to a bogus site ...

Apparently, if the 3 above are commented out, then this has no effect. [HKEY_LOCAL_MACHINE\Software\CLASSES\MSEvents.MSEvents] @="MSEvents Object" [HKEY_LOCAL_MACHINE\Software\CLASSES\MSEvents.MSEvents\CLSID] @="{B313D637-F405-4052-AC37-E2119AB3C8F8}" [HKEY_LOCAL_MACHINE\Software\CLASSES\MSEvents.MSEvents\CurVer] @="MSEvents.MSEvents.1" There is probably also a typeLib entry, but I ignored it. Then Windows automatically deletes the key.

In addition, the computer would not keep an internet connection (because its IP address would automatically change) and the system needed to be restarted several times a day. Bochner also claims to have uncovered a probable link between Symantec and WinFixer.

The system returned: (22) Invalid argument The remote host or network may be down. site WinSoftware Ltd. Installation When executed, Trojan:Win32/Vundo.gen!AU drops a randomly named DLL in the  if the user is an administrator.

I think!

Bochner that they were not interested in protecting the American people. The program then prompts the user to purchase a registered version of the software in order to remove the reported threats. I've finally come to the conclusion that Anti-virus software is practically useless against any elective installed Malware like these variants of Vundo.

Box 3 Kiev, NA UA +(380) 97 939 09 44 Fax: +(380) 97 939 09 44 Reverse DNS provides box43.yyz1.setupahost.net [] This has the same snailmail address as winfixer.com. Having identified the virus, I tried the usual stuff Delete the file - failed because the program was running Over write the file - failed for the same reason Comment out

The RunOnce key provided the key to the problem. WinFixer 2005 is a useful utility to ...

The article gives details on the scams Author: Robert Clemenzi URL: http:// mc-computing.com / Parasites / WinFixer_parasite.html ERROR The requested URL could not be retrieved The following error not a private lawyer. It is known to be distributed through spam email, peer-to-peer file sharing, drive-by downloads, and by other malware. Create Account How it Works Javascript Disabled Detected You currently have javascript disabled.

Files are downloaded to the %temp% or using a randomly generated local filename starting with the prefix "__c00"For example: \__c00B2310.exe or \__c009DCD4.dat Display pop-ups. When I checked the McAfee site for info on Vundo, I found the instructions to manually remove the program.

setupahost.net From their web page Setup A Host, Inc P.O Box 2122 Peterborough, Ontario K9J 7Y4 Canada +1 (905) 248-3003 From a *whois* site OrgName: SetupAHost OrgID: SETUP Address: 157 Adelaide

setupahost.net From their web page Setup A Host, Inc P.O Box 2122 Peterborough, Ontario K9J 7Y4 Canada +1 (905) 248-3003 From a *whois* site OrgName: SetupAHost OrgID: SETUP Address: 157 Adelaide Spyware Alert: WinFixer Almost Tricked Us - pcmag, Jan 14, 2006 - This refers to WinFixer as spyware.