I use Spy-Bot S&D to get most of the malicious files that I knowingly put on my computer. I don’t have many to begin with, largely in part of my lack of IE use. But, when I open a zip and think that there’s a 60-40% chance that I’m just opening up a trojan, virus or worm of sorts, I know how to clean up my own mess. Example: If I get an email at work that says don’t open an attachment from a certain email, I’m kinda gonna open it. I can always play dumb if I really ruin anything.
Yesterday, I opened a file, OK, about five that I knew that they just might be malware. Turns out, they were! So I popped Spy-Bot open. Now, in the past there have been one or two things Spy-Bot just has had no luck in removing. VirtuMonde.c just happens to be one of the trojans that Spy-Bots is hit or miss on.
Vundo, or the Vundo Trojan (also known as Virtumonde or Virtumondo and sometimes referred to as MS Juan) is a Trojan horse that is known to cause popups and advertising for rogue antispyware programs, and sporadically other misbehavior including performance degradation and denial of service with some websites including Google.
Spy-Bot wanted to stop scanning to reboot and scan then. Fine! Go reboot and scan Spy-Bot. Whatever you want. But I knew if it needed to delete files on startup, it was going to be a bigger hassle than expected. It was. During the startup scan, Spy-Bot told me it would be best to reboot and scan at startup. Nice! Here’s your cookie Spy-Bot. Now go eat it in the corner while daddy fixes things you can’t. So I run to Google looking for my answer.
After a quick stop at Lavasoft’s non-compatible with Firefox web site, I stumbled upon Malwarebytes’ Anti-Malware.
Malwarebytes’ Anti-Malware is an anti-malware application that can thoroughly remove even the most advanced malware. It includes a number of features, including a built in protection monitor that blocks malicious processes before they even start.
I’ve heard of it before. Figured I’d give it a chance. Turns out, it’s pretty fucking bad ass. I mean it’s not something I need to run realtime. But it came through where Spy-Bot couldn’t. It even came with FileASSASSIN as a side tool.
FileASSASSIN is an application that can delete any type of locked files that are on your computer. Whether the files are from a malware infection or just a particular file that will not delete - FileASSASSIN can remove it. The program uses advanced programming techniques to unload modules, close remote handles, and terminate processes to remove the particular locked file. Please use with caution as deleting critical system files may cause system errors.
Anti-Malware ran and gave me a report of what if found and if it needed to reboot to delete any files. I ran it three times. My fault. First run was a quick scan. Which actually was quick. Like 5 minutes. It rebooted to remove files. Then I ran full scan again. It found a couple other things. Good. It didn’t need to reboot this time so ran full scan again for the hell of it. It found nothing.
I thought I’d just install it, run it and remove it. I think I’ll keep it a bit longer.
Popularity: 12% [?]