in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Watch out for the newest version of VirtuMonde adware/trojan

Last post 12-01-2007 4:34 PM by Blue1978. 2 replies.
Page 1 of 1 (3 items)
Sort Posts: Previous Next
  • 11-30-2007 7:49 AM

    • bob p
    • Top 25 Contributor
    • Joined on 06-19-2007
    • San Diego, California
    • Posts 48

    Watch out for the newest version of VirtuMonde adware/trojan

    Be on the watch for the latest version of VirtuMonde Trojan. I've tried everything I can think of to get rid of it.
     
    Unfortunately, I can't find any reference to in in the eEye forums (if I am wrong, please show me where). I have scaned repleatedly with Blink, which didn't find it. I used PC Tools Spyware Doctor, which found it, but didn't fix it. I then tried NDO32 (had to temprarily shut Blink down), AVG AntiSpyware, Spybot, AdAware, Windows Defender, VundoFix.exe, etc. Some scans saw it, said they deleted it, then on restart (with system restore off), it's still there, playing havoc with Firefox and IE7. Symptoms are rogue spyware ads appearing. And with IE7, the privacy settings are turned OFF(!), which also affects Outlook.
     
    Apparentlty, there is an infected dll file in the system32 folder called called "rqropnm.dll" (maybe a unique name to this computer), which corresponds to a file that appears in the C:\ root directory that logs the events simply called "Log.txt." There are also some odd temp files that appear at the same time.  
     
    Scan reports indicate this:  
     
    1.) The exact reference earlier today to Virtumonde trojan was this:
    C:\windows\system32\GFPJTFHG.DLL  "Win32/Adware.Virtumonde application
     
    2.) I also cannot remove "crvtpwgk.dll" from the msconfig/system startup.
    (To be exact, it's: Rundll32.exe "C:\Windows\system32\crvtpwgk.dll",s)
     
    3.) C:\Widnows\system32\rqroprm.dll (size 37376) was first quarantined by anti-malware, and is reported as "probably a variant of Win32/Genetik trojan"
     
    So, beware, and if Blink has a remedy, I'd LOVE to hear about it.
     
    Thanks,
    Bob
     
     
     
  • 11-30-2007 10:02 AM In reply to

    • bob p
    • Top 25 Contributor
    • Joined on 06-19-2007
    • San Diego, California
    • Posts 48

    Re: Watch out for the newest version of VirtuMonde adware/trojan

    Postscript: I think I fixed it by carefully following the directions found here: http://wiki.castlecops.com/Malware_Removal:_Virtumundo  

  • 12-01-2007 4:34 PM In reply to

    Re: Watch out for the newest version of VirtuMonde adware/trojan

    bob p:
    So, beware, and if Blink has a remedy, I'd LOVE to hear about it.
     

     

         Did you send all of the files to eEye so they can send it to Norman?  All of those files that you pointed out, zip them in a zip file, password protect it, and then  I think the address you can send them to is malware@eeye.com.  I would also let Nicula know about it at:  lnicula@eeye.com

Page 1 of 1 (3 items)
© 1995 - 2009 eEye Incorporated