PDA

View Full Version : how does virtumonde get in?



nsga1
2008-01-16, 19:49
I am having a major problem with virtumonde removal. I am just curious how it gets in your system. Around the sametime as infection, I installed an HPPhotosmart wireless network printer on my home network and added my daughter's ipod touch to the network. I may have adjusted some security settings to get the network to recognize and communicate with her ipod touch. I am just curious if either of these new additions to my wireless network (which is secured) could've had anything to do with the infection? Any feedback is appreciated!The printer is hardwired to the infected pc. The ipod touch is hooked to the infected pc sometimes. Do ipod touch carry virus infections?

tashi
2008-01-16, 20:11
Hello. :)

As the Tavern is not for support or malware removal advice, I will point you in this direction:

Please follow the procedure in this link:
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a helper will advise you when available.

Cheers.

XstormX
2008-01-16, 21:48
unpatched exploits in java and/or IE, flashplayer etc...
its just like that Smitfraud infection who enters through java bugs...

tashi
2008-01-16, 23:03
unpatched exploits in java and/or IE, flashplayer etc...
its just like that Smitfraud infection who enters through java bugs...
To clarify a little, :) SmitFraud is generally a term used to cover infections where fake security alerts appear in your taskbar stating that you are infected.

The Smitfraud family of rogue anti-spyware programs changes the user's desktop to display false warnings stating the computer is infected with spyware; in order to frighten the user into paying for the program.

Vundo/Winfixer infections:
Sun Microsystems~Java. Security vunerability in older versions left on system (http://forums.spybot.info/showpost.php?p=12880&postcount=2)

Zlob:
Warning: Infection via bad CODEC installs. Zlob (http://forums.spybot.info/showthread.php?t=7344)

Cheers.