Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.
Trojan Duncan Process
Name: Matthewitt Date: August 13, 2007 at 13:00:13 Pacific OS: XP Prof CPU/Ram: AMD 64X2 Dual Core 4000+
Comment:
I keep getting new dll's in system32 on startup that then connect my internet and pop up anti spyware ads. I can clear them with Superantispyware but they return under a different dll name at the reboot. I run Spybot and it finds Virtumonde. I have done everything on all the other Virtumonde replies on here and it keeps coming back. I managed to get rid in safe mode but on the reboot to normal windows it was back. There is nothing in the registry under any of the entries people advise to delete either. Would appreciate some help. Thank you.
Name: btk1w1 Date: August 13, 2007 at 21:17:24 Pacific
Reply:
Have you turned off system restore prior to scanning in safe mode then turning system restore back on afterwards?
0
Response Number 3
Name: Matthewitt Date: August 14, 2007 at 04:25:31 Pacific
Reply:
Yes I did turn it off and on.
Cheers for the advice so far. I am trying the bleeping thing today.
0
Response Number 4
Name: Matthewitt Date: August 14, 2007 at 04:44:54 Pacific
Reply:
Tried that. I have even more dll's popping up now. Superantispyware is showing at least 6 cases of Trojan Duncan Process whereas yesterday it was only one.
0
Response Number 5
Name: Matthewitt Date: August 15, 2007 at 04:19:36 Pacific
Reply:
Got it! I ran Vundo fix from Bleeping computers then went to safe mode and ran VirtumondeBeGone from Bleeping computer. Back in normal windows I ran Superantispy and then Spybot. They both found aspects of the virus that they weren't finding originally and when they deleted these it was gone.
Cheers for the help and good luck to anyone else trying to get rid of this thing.
0
Response Number 6
Name: btk1w1 Date: August 16, 2007 at 00:41:12 Pacific
Reply:
Thats awesome!, thanks for the follow-up post with successful removal method
Summary: Ok, sorry this took so long, i've been so busy. I've done exactly as you describe, but i'm curious, is it correct that you want me to post the DrWeb log file from the scan i did before rebooting? Or ...
Summary: I am having some severe trouble with the WORM_ASSARM.A trojan. My CD drives won't recognize CDs, I can't use Windows Media Player, and the trojan's process (SVCHOST.EXE) is eating up tons of my RAM. M...