# Trojan Horse?

**URL:** https://boards.straightdope.com/t/trojan-horse/475437
**Category:** About This Message Board
**Created:** [December 3, 2008, 1:51am UTC](https://boards.straightdope.com/t/trojan-horse/475437 "2008-12-03T01:51:04Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![CandidGamera](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/candidgamera/32/2878_2.png) [@CandidGamera](https://boards.straightdope.com/u/CandidGamera)
#### Post date: [December 3, 2008, 1:51am UTC](https://boards.straightdope.com/t/trojan-horse/475437/1 "2008-12-03T01:51:04Z")

</div>

My Avast antivirus started throwing fits this evening as I browsed the Dope - lots of malicious temporary internet files showing up, and the installation without consent of some toolbar called ‘Mirar’. Anybody else having trouble?

---

<div class="post-metadata">

### Author: ![Flander](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Flander](https://boards.straightdope.com/u/Flander)
#### Post date: [December 3, 2008, 3:17am UTC](https://boards.straightdope.com/t/trojan-horse/475437/2 "2008-12-03T03:17:39Z")

</div>

What browser are you using? I’m using Firefox, Chrome, and Firefox 3.1beta (Minefield) and not getting any of that…also using AVG so don’t know.

---

<div class="post-metadata">

### Author: ![SkipMagic](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/skipmagic/32/20706_2.png) [@SkipMagic](https://boards.straightdope.com/u/SkipMagic)
#### Post date: [December 3, 2008, 3:31am UTC](https://boards.straightdope.com/t/trojan-horse/475437/3 "2008-12-03T03:31:30Z")

</div>

Nope, looks like you got infected from another site, e-mail, or suspicious download. You might give Spybot Search & Destroy and Ad-Aware a whirl (but not at the same time) to see if they clean your system up.

---

<div class="post-metadata">

### Author: ![Heffalump\_and\_Roo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/heffalump_and_roo/32/7691_2.png) [@Heffalump\_and\_Roo](https://boards.straightdope.com/u/Heffalump_and_Roo)
#### Post date: [December 3, 2008, 4:18am UTC](https://boards.straightdope.com/t/trojan-horse/475437/4 "2008-12-03T04:18:24Z")

</div>

I clicked on a link in MPSIMS and got the big danger, danger sign from my anti-virus. That doesn’t happen to me often here.

---

<div class="post-metadata">

### Author: ![CandidGamera](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/candidgamera/32/2878_2.png) [@CandidGamera](https://boards.straightdope.com/u/CandidGamera)
#### Post date: [December 3, 2008, 3:24pm UTC](https://boards.straightdope.com/t/trojan-horse/475437/5 "2008-12-03T15:24:06Z")

</div>

There’s one other site I consider a possible source on this - Mirar actually was the symptom, not the disease.

The disease is this nasty piece of work :

> **[Vundo](https://en.wikipedia.org/wiki/Virtumonde)**
>
> The Vundo Trojan (commonly known as Vundo, Virtumonde or Virtumondo, and sometimes referred to as MS Juan) is either a Trojan horse or a computer worm that is known to cause popups and advertising for rogue antispyware programs, and sporadically other misbehavior including performance degradation and denial of service with some websites including Google and Facebook. It also is used to deliver other malware to its host computers. Later versions include rootkits and ransomware.
> A Vundo infection ...

Avast, Spybot, and Ad-Aware haven’t gotten rid of it yet, but I’ve got one or two more ideas…

---

<div class="post-metadata">

### Author: ![Flander](https://avatars.discourse-cdn.com/v4/letter/f/8c91f0/32.png) [@Flander](https://boards.straightdope.com/u/Flander)
#### Post date: [December 3, 2008, 3:36pm UTC](https://boards.straightdope.com/t/trojan-horse/475437/6 "2008-12-03T15:36:54Z")

</div>

I’ve had that before. Run Spy-bot and your AV in safe mode. Should do the trick.

---

<div class="post-metadata">

### Author: ![Gfactor](https://avatars.discourse-cdn.com/v4/letter/g/9de053/32.png) [@Gfactor](https://boards.straightdope.com/u/Gfactor)
#### Post date: [December 3, 2008, 3:50pm UTC](https://boards.straightdope.com/t/trojan-horse/475437/7 "2008-12-03T15:50:45Z")

</div>

> [@CandidGamera](#):
>
> [Vundo - Wikipedia](http://en.wikipedia.org/wiki/Virtumonde)
> 
> Avast, Spybot, and Ad-Aware haven’t gotten rid of it yet, but I’ve got one or two more ideas..

Malwarebytes comes highly recommended. Or run Hijackthis and post your log here: [http://forums.spywareinfo.com/](http://forums.spywareinfo.com/)

---

<div class="post-metadata">

### Author: ![crowmanyclouds](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/crowmanyclouds/32/19884_2.png) [@crowmanyclouds](https://boards.straightdope.com/u/crowmanyclouds)
#### Post date: [December 4, 2008, 3:38am UTC](https://boards.straightdope.com/t/trojan-horse/475437/8 "2008-12-04T03:38:50Z")

</div>

Just in case you aren’t aware of the feature, avast! has a “Schedule Boot-Time Scan” in the menu. Much better to run it during boot-up then with Windows actually running.

CMC +fnord!  
ETA The avast! screen saver is really cool too!

---

<div class="post-metadata">

### Author: ![CandidGamera](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/candidgamera/32/2878_2.png) [@CandidGamera](https://boards.straightdope.com/u/CandidGamera)
#### Post date: [December 4, 2008, 2:54pm UTC](https://boards.straightdope.com/t/trojan-horse/475437/9 "2008-12-04T14:54:48Z")

</div>

Thanks for your thoughts, gentlemen, though I arrived at most of the same ideas by independent experimentation.

This is a newish strain of Virtumonde. Safe Mode + MalwareBytes + Spybot + Ad-Aware + Avast + SuperAntiSpyware = Failure.

It had a stealth DLL attached to all my SvcHost processes that would re-create deleted registry entries when they were removed, and the only thing Safe Mode bought me was that it couldn’t go out and re-create its auxiliary malicious files. None of the AV software found the DLL.

I was able to pin it down with Process Explorer and Autoruns, two utilities from SysInternals. This thing was attached in such a way that it could not be seen from Windows Explorer. (I don’t mean hidden file - I mean attached to the explorer process and preventing it from being seen.)

I was able to go into the command line, and rename the DLL. Then rebooted. Since its name had changed, the reg entries wouldn’t load it into memory, and then I was able to kill everything off.

---

<div class="post-metadata">

### Author: ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)
#### Post date: [December 4, 2008, 6:51pm UTC](https://boards.straightdope.com/t/trojan-horse/475437/10 "2008-12-04T18:51:48Z")

</div>

Just be careful with that. I got that strain myself, and it was somehow able to repopulate itself if I stayed online to long. I can’t really offer much advice, as I finally switched to Linux after all that mess. But it’s been suggested that it may have uninstalled some of your updates.

(Yes, I know I may have had concurrent infections. All the more reason for me to just nuke that partition.)

---

<div class="post-metadata">

### Author: ![Lordviper](https://avatars.discourse-cdn.com/v4/letter/l/a8b319/32.png) [@Lordviper](https://boards.straightdope.com/u/Lordviper)
#### Post date: [December 5, 2008, 1:54am UTC](https://boards.straightdope.com/t/trojan-horse/475437/11 "2008-12-05T01:54:22Z")

</div>

Hmm yeah I got a virus I can’t get rid of but can’t find it eather. I’ve ran Avast, Spybot, Malwarebytes though I have yet to us Hijack this so that might help. Cause I don’t have anything major to speak of at this point but for whatever reason can’t shut my IE off completely though I use a browser called Maxthon which basicly uses IE settings but is secure customizalbe like Firefox.

---

<div class="post-metadata">

### Author: ![CandidGamera](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/candidgamera/32/2878_2.png) [@CandidGamera](https://boards.straightdope.com/u/CandidGamera)
#### Post date: [December 5, 2008, 1:32pm UTC](https://boards.straightdope.com/t/trojan-horse/475437/12 "2008-12-05T13:32:09Z")

</div>

> [@BigT](#):
>
> Just be careful with that. I got that strain myself, and it was somehow able to repopulate itself if I stayed online to long. I can’t really offer much advice, as I finally switched to Linux after all that mess. But it’s been suggested that it may have uninstalled some of your updates.
> 
> (Yes, I know I may have had concurrent infections. All the more reason for me to just nuke that partition.)

It’s that pesky extra DLL. It’ll repopulate everything if you don’t get it, and anti-spyware software doesn’t get it.

My system scans clean now with SpyBot, Ad-Aware, MalwareBytes, and SuperAntiSpyware. It’s been online in normal mode for a day and a half. I’m pretty confident it’s gone.
