B
Baudouin de Spa
Hi all,
I got the Virtumonde malware, and have succeeded to get rid of it.
There's only one point left: when using Autoruns from Sysinternals (now
Microsoft), I can see there is something left in
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages
That's a way to run C:\Windows\system32\byXQJYpP (which is a random file
name given by Virtumonde, but I have deleted this file long time ago, which
gives in Autoruns the message "File not found:
C:\Windows\system32\byXQJYpP".
I've disabled this entry in Autoruns, but if I delete it, it comes back
again at next reboot (still disabled though).
So there must be something left from Virtumonde somewhere trying to
reinitiate the process, without succeeding in it.
I tried searching the registry for anything special, without success.
I also tried some Virtumonde removers, but they don't find anything: so I'm
left here with the "root" of Virtumonde still trying, but not able to
activate because it has been removed at 99%. I would like to try to delete
the remining 1%, to have a perfectly clean MS-Vista.
Can anyone help? Thank you.
I got the Virtumonde malware, and have succeeded to get rid of it.
There's only one point left: when using Autoruns from Sysinternals (now
Microsoft), I can see there is something left in
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages
That's a way to run C:\Windows\system32\byXQJYpP (which is a random file
name given by Virtumonde, but I have deleted this file long time ago, which
gives in Autoruns the message "File not found:
C:\Windows\system32\byXQJYpP".
I've disabled this entry in Autoruns, but if I delete it, it comes back
again at next reboot (still disabled though).
So there must be something left from Virtumonde somewhere trying to
reinitiate the process, without succeeding in it.
I tried searching the registry for anything special, without success.
I also tried some Virtumonde removers, but they don't find anything: so I'm
left here with the "root" of Virtumonde still trying, but not able to
activate because it has been removed at 99%. I would like to try to delete
the remining 1%, to have a perfectly clean MS-Vista.
Can anyone help? Thank you.