| SuperMWindow - A New Vundo |
|
|
|
| Written by Atribune | |
| Sep 22, 2007 at 11:57 AM | |
|
I received an email last week from a person who had picked up a particularly nasty vundo infection. I vnc'd into his machine and pulled some samples and found that they weren't hooking winlogon.exe like the usual vundo we see, instead they were hooked into lsass.exe. I managed to get it ripped out of the users machine and get him back on his merry way. Since then I have had time to test out this new variant and figure out how it was loading and have now added removal of it to Vundofix. Vundofix and instructions on how to use it are available from http://vundofix.atribune.org Good Luck and Safe Surfing, Atri |
|
| Last Updated ( Sep 22, 2007 at 12:08 PM ) |




