Specialty Forums
Security and Virus
General Hardware
CPUs/Overclocking
Networking
Digital Photo/Video
Office Software
PC Gaming
Console Gaming
Programming
Database
Web Development
Digital Home

General Forums
Windows XP
Windows Vista
Windows 95/98
Windows Me
Windows NT
Windows 2000
Win Server 2008
Win Server 2003
Windows 3.1
Linux
PDAs
BeOS
Novell Netware
OpenVMS
Solaris
Disk Op. System
Unix
Mac
OS/2

Drivers
Driver Scan
Driver Forum

Software
Automatic Updates

BIOS Updates

My Computing.Net

Solution Center

Free IT eBook

Howtos

Site Search

Message Find

RSS Feeds

Install Guides

Data Recovery

About

Home
Reply to Message Icon Go to Main Page Icon

Trojan Duncan Process

Original Message
Name: Matthewitt
Date: August 13, 2007 at 13:00:13 Pacific
Subject: Trojan Duncan Process
OS: XP Prof
CPU/Ram: AMD 64X2 Dual Core 4000+
Comment:
I keep getting new dll's in system32 on startup that then connect my internet and pop up anti spyware ads. I can clear them with Superantispyware but they return under a different dll name at the reboot. I run Spybot and it finds Virtumonde. I have done everything on all the other Virtumonde replies on here and it keeps coming back. I managed to get rid in safe mode but on the reboot to normal windows it was back. There is nothing in the registry under any of the entries people advise to delete either. Would appreciate some help. Thank you.

Report Offensive Message For Removal


Response Number 1
Name: Pappy
Date: August 13, 2007 at 20:46:42 Pacific
Subject: Trojan Duncan Process
Reply: (edit)
Instructions for removal at Bleepingcomputer:

http://www.bleepingcomputer.com/forums/topic18610.html


Report Offensive Follow Up For Removal

Response Number 2
Name: btk1w1
Date: August 13, 2007 at 21:17:24 Pacific
Subject: Trojan Duncan Process
Reply: (edit)
Have you turned off system restore prior to scanning in safe mode then turning system restore back on afterwards?

Report Offensive Follow Up For Removal

Response Number 3
Name: Matthewitt
Date: August 14, 2007 at 04:25:31 Pacific
Subject: Trojan Duncan Process
Reply: (edit)
Yes I did turn it off and on.

Cheers for the advice so far. I am trying the bleeping thing today.


Report Offensive Follow Up For Removal

Response Number 4
Name: Matthewitt
Date: August 14, 2007 at 04:44:54 Pacific
Subject: Trojan Duncan Process
Reply: (edit)
Tried that. I have even more dll's popping up now. Superantispyware is showing at least 6 cases of Trojan Duncan Process whereas yesterday it was only one.

Report Offensive Follow Up For Removal

Response Number 5
Name: Matthewitt
Date: August 15, 2007 at 04:19:36 Pacific
Subject: Trojan Duncan Process
Reply: (edit)
Got it! I ran Vundo fix from Bleeping computers then went to safe mode and ran VirtumondeBeGone from Bleeping computer. Back in normal windows I ran Superantispy and then Spybot. They both found aspects of the virus that they weren't finding originally and when they deleted these it was gone.

Cheers for the help and good luck to anyone else trying to get rid of this thing.


Report Offensive Follow Up For Removal


Response Number 6
Name: btk1w1
Date: August 16, 2007 at 00:41:12 Pacific
Subject: Trojan Duncan Process
Reply: (edit)
Thats awesome!, thanks for the follow-up post with successful removal method

Report Offensive Follow Up For Removal



Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Trojan Duncan Process

Comments:

 
  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 


Data Recovery Software




My PC has been hijacked!

Lexmark 2600 Printer Issues

btk1w1 infected start here post

Unwanted message remians on screen

Slow boot time


The information on Computing.Net is the opinions of its users. Such opinions may not be accurate and they are to be used at your own risk. Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE

All content ©1996-2007 Computing.Net, LLC