<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Coevolving Innovations &#187; anti-virus</title>
	<atom:link href="http://coevolving.com/blogs/index.php/archive/tag/anti-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://coevolving.com/blogs</link>
	<description>... in Business Organizations and Information Technologies</description>
	<lastBuildDate>Thu, 19 Jan 2012 01:40:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/><cloud domain='coevolving.com' port='80' path='/blogs/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Slaying the virtumonde virus</title>
		<link>http://coevolving.com/blogs/index.php/archive/slaying-the-virtumonde-virus/</link>
		<comments>http://coevolving.com/blogs/index.php/archive/slaying-the-virtumonde-virus/#comments</comments>
		<pubDate>Sun, 23 Dec 2007 21:16:59 +0000</pubDate>
		<dc:creator>daviding</dc:creator>
				<category><![CDATA[technologies]]></category>
		<category><![CDATA[ad-aware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[virtumonde]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vundofix]]></category>

		<guid isPermaLink="false">http://coevolving.com/blogs/index.php/archive/slaying-the-virtumonde-virus/</guid>
		<description><![CDATA[Problem determination and disinfecting the virtumonde virus requires patience.]]></description>
			<content:encoded><![CDATA[<!-- RSPEAK_STOP --> <a href='http://wr.readspeaker.com/webreader/webreader.php?cid=ec34708b6af2bd314e8382b3a91c3f79&t=wordpress_free&url=http://coevolving.com/blogs/index.php/archive/slaying-the-virtumonde-virus/&title=Slaying the virtumonde virus' onclick='readpage(this.href, 116); return false;'> <img src='http://graphics.readspeaker.com/images/wr/listen_en_us.gif' style='border-style: none;' alt='Listen with webreader'></a><div id='WR_116'></div> <!-- RSPEAK_START --> <p>Brian phoned yesterday, to ask if Adam could take a look at Jasmine&#8217;s laptop. Adam wasn&#8217;t in, so Diana suggested that he talk to me. Brian initially said that he didn&#8217;t want to take my time looking at a PC with a potential virus on it.  I told him just to drop the machine off, and I would  add it to the other two computers on my desk. I&#8217;m second-level support for the eight computers we have in our house, so all of the hard problems come to me.</p>
<p>This laptop took forever to boot, and would come up with a message (as I had seen <a href="http://forum.bitdefender.com/index.php?showtopic=3561&amp;st=20&amp;start=20" title="forum.bitdefender.com/index.php?showtopic=3561&amp;st=20&amp;start=20">in the bitdefender forum</a>) of:</p>
<blockquote><p> Your system could become unstable</p>
<p>A potential problem has been detected and Windows has been shutdown buggy application to prevent damage to your computer.</p>
<p>****WXYZ.SYS &#8211; Address F73120AE base at C00000, DateStamp 36b072A3<br />
Kernel Debugger Using: COM2 (Port 0x28f, Baud rate 192000)<span id="more-116"></span></p></blockquote>
<p>Although the panel looks like a Windows error, the wording is pretty suspicious (and grammatically incorrect). It&#8217;s the virus talking, not Windows. (There&#8217;s no reason for the kernel to be going to a COM2 port, when you have high-speed Internet access!)</p>
<p>Other symptoms included thousands of pot???.tmp files in the root directory, and an inability to start up a command prompt, because the /windows/systems32/ directory was hidden.</p>
<p>First, I downloaded the <a href="http://www.atribune.org/content/section/4/30/" title="atribune.org/content/section/4/30/">VundoFix program from atribune.org</a> and ran that.  This program was <a href="http://www.atribune.org/content/view/38/2/" title="atribune.org/content/view/38/2/">last updated in January 2007</a>. It took a while, but VundoFix confirmed the Virtumonde virus. I followed through to clean up the virus, and it removed and patched a lot of files &#8230; except one. VundoFix said that this file would be removed after a reboot. I rebooted, VundoFix came up, and the last file was supposedly fixed. With another reboot, however, the system32 directory was still invisible, and another run of VundoFix disclosed an infected file. I retried the search, fix and reboot three more times, with the same result.</p>
<p>With another web search, I found that <a href="http://www.lavasoft.com/support/securitycenter/virtumonde_remover.php" title="lavasoft.com/support/securitycenter/virtumonde_remover.php">Lavasoft had developed a VirtuMonde remover</a>, and it has been incorporated into <a href="http://www.lavasoft.com/products/ad_aware_free.php" title="lavasoft.com/products/ad_aware_free.php">Ad-Aware 2007 (including the free version)</a>. I downloaded Ad-Aware 2007 Free, but when I tried to install it, the installation would fail because some other program was simultaneously being installed.</p>
<p>Looking at <a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/taskman_whats_there_w.mspx?mfr=true" title="microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/taskman_whats_there_w.mspx?mfr=true">Windows Task Manager &#8230; Processes &#8230;</a> I saw multiple instances of <a href="http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/msiexec.mspx?mfr=true" title="microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/msiexec.mspx?mfr=true">msiexec</a> running. One of these msiexec processes blocks other installation requests. I killed these processes, and Ad-Aware 2007 installed smoothly. Running Ad-Adware then not only found and isolated the files infected by Virtumonde, but also two other viruses &#8230; as well as the usual browser malware. I always thought that Ad-Aware was just for browsers &#8230; but I guess Lavasoft does much more than that!</p>
<p>When I could bring up a command prompt, it was a simple instruction to delete pot*.tmp, in two directories.</p>
<p>The laptop seems to be working fine, now. I&#8217;m 99% certain that I&#8217;ve killed the Virtumonde virus. The 1% uncertainty is that there are msiexec processes that come up after a cold boot. These could be normal processes (e.g. one turned out to be the anti-virus profiles from <a href="https://securityservices.sympatico.ca/ssp.do?lang=en" title="securityservices.sympatico.ca/ssp.do?lang=en">Sympatico Security Services</a> being refreshed) &#8230; or they could be the Virtumode virus continuing to lurk.</p>
<p>Brian picked up the machine this morning. I&#8217;ve advised him to back up all of the data files on CDROM, in the case that the virus isn&#8217;t really dead. He had been advised by a technician in a store to just reinstall Windows XP. For systems engineers from the mainframe generation, reinstalling an operating system is an extraordinary measure that isn&#8217;t taken lightly. In my opinion, the problem determination skills of PC-oriented technicians leaves much to be desired. The elapsed time &#8212; not working time, because it took so long for the programs to run, and the infected operating system to reboot &#8212; to fix the machine was probably 6 to 8 hours.</p>
<p>Most PC technicians are all about action, not thinking. Sticking to a problem for the better part of a working day requires patience.  I wish that university and college students could develop the good analytical discipline to figure out the one technical issue that is wrong, and put that right.</p>
 <!-- RSPEAK_STOP -->]]></content:encoded>
			<wfw:commentRss>http://coevolving.com/blogs/index.php/archive/slaying-the-virtumonde-virus/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
	</channel>
</rss>

