Monday, December 6, 2010

Virtumonde Back in Stealthy- Difficult-to-Remove Status

Virtumonde is back in its ugly form as hard to identify and if identified the antimalware cannot remove it. The Vundo trojan with its name-like Virtumondo can be hard to stop without the latest "fix" which may not be available for 24 hours or more. Spybot nor SuperAntiSpyware and many other scanners have been able to help as this trojan runs in memory upon startup it is tough. Spybot could Identify malware but not remove it with the accompanying messages stating, 'you do not have administrative rights...can we run on reboot'; clicking 'yes' and Spybot would not autorun on reboot.

Finally, with a more recent update of Malwarebytes and signatures from Nov. 30, 2010 I was able to break the back of the trojan and finally able to now access "safe mode". I just decided to try 'safe mode' and was able to access and now decided to run Spybot in 'safe mode' and Spybot was not able to identify more malware and was ablet to "Fix the Problem".

Hopefully more security vendors will get the fix so the recent Vundo trojan can be more easily disabled.

No comments: