SI
SI
discoversearch

We've detected that you're using an ad content blocking browser plug-in or feature. Ads provide a critical source of revenue to the continued operation of Silicon Investor.  We ask that you disable ad blocking while on Silicon Investor in the best interests of our community.  If you are not using an ad blocker but are still receiving this message, make sure your browser's tracking protection is set to the 'standard' level.
Pastimes : Computer Learning -- Ignore unavailable to you. Want to Upgrade?


To: thecow who wrote (41365)5/25/2004 4:21:43 PM
From: Triffin  Respond to of 110652
 
Virtumonde.C and other nasty variants ..

Took me awhile .. but finally managed to rid myself
of this 'critter' and related 'friends'
I'm running Windows ME ..

You may want to do a file search for ..

dpusys.ini
sysupd.exe
_update.dat
cidrules.dll
bi.dll

If you've got'em you don't want'em ..

The main culprit is sysupd.exe which will
plant itself in your StartupList .. RegistryEdit
won't get rid of it either ..

What worked for me was to boot in 'safe mode'
ie .. start--run--msconfig--advanced--

Then use the registry editor at that point ..
Also double check using the file search function
under MS-DOS to find and delete these files ..
Then re-set your computer for a regular re-boot
before you do so ..

PestPatrol search function is very useful
with their suggested 'fixes' .. Just enter
any suspect 'file name' in the search function
and follow the advice ..

Triffin ..



To: thecow who wrote (41365)5/27/2004 2:52:02 AM
From: akpirate  Read Replies (3) | Respond to of 110652
 
re: Trojan Horse back door virus

What is interesting is that whatever damage the worm did, won't allow me to open up the link you gave me. I was able to use "Hijack this" and finally get the virus deleted. But I still cannot get to the popular virus websites - which means I can't update my Norton. I have run AVG (had disk) and the system says its clean.

Any idea why it won't let me go to the symantec website, etc?

Thanks,
Robert