View Single Post
Old 12-16-08, 12:32 AM   #8
NeonSamurai
Ocean Warrior
 
Join Date: Jan 2002
Location: Socialist Republic of Kanadia
Posts: 3,044
Downloads: 25
Uploads: 0


Default

I would bet money it didn't come from Filefront. One of my computers was also recently infected, and it also bypassed my firewalls and antivirus protection.

You defiantly have the Virtumonde trojan as was mentioned, and its a royal pain to get rid of if you don't know what your doing (and most virus and spyware scanners cannot directly fix it due to how the virus works). Its also very common for these things to delay activation by days, weeks or even longer to prevent the trojan from being traced back to the host site.

Now for getting rid of it...

Go to this site and download Spybot S&D
http://www.safer-networking.org/en/home/index.html
Have it update and run a scan
It should find Virtumonde, now look for the 2 .dll files that Spybot found (don't reboot). Go to the directory their in (/windows/system32) find them both (make sure you have unhidden the files) and rename them both to something else and remove the .dll extension. Now reboot, delete the renamed files by hand and have Spybot clean up the rest.

If you can't rename the files then use something like Dr. Delete to have the files deleted on system startup

Last edited by NeonSamurai; 12-16-08 at 12:34 AM.
NeonSamurai is offline   Reply With Quote