Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 11th, 2008, 04:49 AM
xsoft xsoft is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 3
Default Vundo virus

Greting,
before 3 days Ive got again Vundo virus.

This virus is there from 05/2008. Its a nasty one - it copy themself to \system32 as dandom dll, running from startup, register themself as IE7 plugin .. and showing some popups like "Buy new Antivirus 2009".

I have last version of ESET NOD 32 (updated to 8.8.2008), but still this virus gote me. I have send sample to virustotal.com (online virus test) and 13 antiviruses found it (from 36). NOD was NOT one of them. Neither Symantec antivirs or AVG. Thats a bit shame. Ive trusted those antiviruses and stilll they cant detect it. Ive send a sample before 2 months to NOD32 submit site, but still NOD cant detect this virus. Norman antivirus e.g. can, but this antivirus just cant run separately with NOD (tested on XP adn Vista). It look like every one want to "take control" over system and they freeze each other (=you can move mouse, but no reaction for click on keypress. If you wait 2-20 minutes, then you click will be proceed, but still you are at 99% lag. Nope, CPU is not at 100, its just look like frozen PC, but it isnt, If you play a movie, then player will fluently show movie and soub, but if you click on stop, (mouse/keyboard), then you need to wait 5 minutes).


Anyway. Can I please ask ESET about add Vundo virus detection into NOD32? Its 3 months old virus. Im not sure now if I will have some examples (Im glad that I deleted all of them).

Btw, Norman maybe detect and delete this virus, but their Vundo remove tool dont work (maybe there is a new mutation of virus) http://www.norman.com/Virus/Virus_removal_tools/en-us
  #2  
Old August 11th, 2008, 05:07 AM
nonoise's Avatar
nonoise nonoise is offline
Frequent Poster
 
Join Date: Jun 2008
Posts: 322
Default Re: Vundo virus

Read more about Virtumonde here:

http://www.eset.com/threat-center/ca..._July_2008.pdf

it really looks like a nasty little bugger. you can get rid of it with Malwarebytes' Anti-Malware and superantispyware home, both are free.
  #3  
Old August 11th, 2008, 05:19 AM
xsoft xsoft is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 3
Default Re: Vundo virus

Oh, thanks for suggestion.
I will try those antimalwares.

PS: Malwarebytes' Anti-Malware 1.24
Free to try; $24.95 to buy
  #4  
Old August 11th, 2008, 05:32 AM
PaulB2005 PaulB2005 is offline
Frequent Poster
 
Join Date: Apr 2005
Posts: 525
Default Re: Vundo virus

Quote:
Can I please ask ESET about add Vundo virus detection into NOD32? Its 3 months old virus

This virus has many variants. Some are 3 months old, but some maybe only 3 weeks, 3 days or even 3 hours old... The virus creators are constantly changing the files to evade detection. If you can identify the files submit them so Eset can update the detection of the variant you have.
__________________
ESET NOD32 Anti Virus 4.2.64.12
AMD 64 X2 4400+
Asus A8N-SLi Deluxe (Bios 1016)
3 Gb RAM
Sony DVD-RAM AW-G170A
Seagate ST3200820AS (200 Gb Main Drive)
  #5  
Old August 11th, 2008, 06:31 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: Vundo virus

Quote:
Originally Posted by xsoft
Greting,
before 3 days Ive got again Vundo virus.

This virus is there from 05/2008. Its a nasty one - it copy themself to \system32 as dandom dll, running from startup, register themself as IE7 plugin .. and showing some popups like "Buy new Antivirus 2009".

I have last version of ESET NOD 32 (updated to 8.8.200, but still this virus gote me. I have send sample to virustotal.com (online virus test) and 13 antiviruses found it (from 36). NOD was NOT one of them. Neither Symantec antivirs or AVG. Thats a bit shame. Ive trusted those antiviruses and stilll they cant detect it. Ive send a sample before 2 months to NOD32 submit site, but still NOD cant detect this virus. Norman antivirus e.g. can, but this antivirus just cant run separately with NOD (tested on XP adn Vista). It look like every one want to "take control" over system and they freeze each other (=you can move mouse, but no reaction for click on keypress. If you wait 2-20 minutes, then you click will be proceed, but still you are at 99% lag. Nope, CPU is not at 100, its just look like frozen PC, but it isnt, If you play a movie, then player will fluently show movie and soub, but if you click on stop, (mouse/keyboard), then you need to wait 5 minutes).


Anyway. Can I please ask ESET about add Vundo virus detection into NOD32? Its 3 months old virus. Im not sure now if I will have some examples (Im glad that I deleted all of them).

Btw, Norman maybe detect and delete this virus, but their Vundo remove tool dont work (maybe there is a new mutation of virus) http://www.norman.com/Virus/Virus_removal_tools/en-us

Hello,
Please send a log from ESET SysInspector to support[at]eset.com with this thread's url enclosed.

Also, please PM me your email address so that I can check the status of your samples.
  #6  
Old August 11th, 2008, 08:43 AM
xsoft xsoft is offline
Infrequent Poster
 
Join Date: Aug 2008
Posts: 3
Default Re: Vundo virus

Hi,
email sent. (it look that PM messages doesnt work - my mail was xsoft at seznam.cz).

Virus samples and log attached.
Thanks.
  #7  
Old August 11th, 2008, 09:50 AM
hex_614's Avatar
hex_614 hex_614 is offline
Regular Poster
 
Join Date: Jul 2008
Location: Manila, Philippines
Posts: 155
Default Re: Vundo virus

use superantispyware it will do the job. and install a behaviour base anti malware. like threat fire or norton antibot. it will further protect u.
__________________
REAL TIME PROTECTION
Norton antivirus 2009 + Norton Antibot 1.1.851

ON DEMAND SCANNER
SuperAntispyware 4.2
Malwarebyte's Antimalware
  #8  
Old August 11th, 2008, 10:09 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: Vundo virus

Quote:
Originally Posted by xsoft
Oh, thanks for suggestion.
I will try those antimalwares.

PS: Malwarebytes' Anti-Malware 1.24
Free to try; $24.95 to buy
They Have a free version as well.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:52 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums