No infection, just questions...

Discussion in 'Malware Help (A Specialist Will Reply)' started by cobrajet431, Sep 22, 2007.

  1. cobrajet431

    cobrajet431 Private First Class

    Hi Geeks. Not sure if this should be in malware or not since I don't really have any problems, so if you need to move this I understand.

    I'm just curious what the difference is between smitfraud infections and virtumonde (or is it Vundo?) infections; the relationship between Vundo and virtumonde (is a Vundo infection a type of Virtumond infection or vice-versa?) and how do "rogue" applications relate to the above.

    What I mean by all that: when I go to other malware forums there will be questions like..."I keep getting these pop-ups that say I'm infected and want me to buy..." Without seeing much appreciable difference between the symptoms, some people will call it a smitfraud infection and recommend smitfraudfix, some will call it a vundo infection and recommend vundofix; and other times someone will just proclaim it a "rogue antispyware" or whatever and recommend RogueRemover. (I'm assuming that RogueRemover shouldn't come into play unless someone actually installs one of the bogus apps, right?)

    So if someone could just give me a little info of how to know which is which, I'd feel like I learned something. As always, Thanks.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Vundo is short for Virtumonde! No they are not the same thing as what is classified as a SmitFraud infection.

    Many many things have been lumped into the SmitFraud family but the most typical thing you will see lumped in here is all of the rogue antispyware/antivirus type applications. These rogue tools are the typical cause of either a wallpaper that tells you that you are infected and or a ballon message that popups from the system tray telling you that you are infected.

    Many people do not really recognize the difference between a SmitFraud type infection and a Vundo infection (and Vundo has many forms to and a new one just came out about a week ago). If some one only says they are getting popups (which may include offers for WinAntiVirus) then it is more likely Vundo than SmitFraud (although other forms of malware cause popups too). Winlogonhook type infections are confused by many as being Vundo since there are a few similarities but there are many differences. I really don't have the time to truly go in a explain all of the differences but I will just say that you need to see all the registry keys and file names being deposited on a PC and then you can easily tell the differnece between Vundo, Winlogonhook, and SmitFraud.

    If you search this forum for some of these you will see when SmitFraudFix is run and when VundoFix, ComboFix (which will also fix some SmitFraud issues) and when manual steps are used to remove the many many files that can be deposited onto a PC from Vundo type infections.
     
  3. cobrajet431

    cobrajet431 Private First Class

    Thanks Chas. But what happens if someone's antispy, say Spybot or Ad-Aware was to find a Smitfraud or Virtumonde infection that isn't prodding the victim to buy something? From the bad-guy's point of view, what purpose is the malware serving? Can we assume it's working behind-the-scenes and phoning home?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ad-Aware rarely finds anything of consequence (the main reason we never use it anymore in the READ ME). Also Spybot and Ad-Aware rarely find any of the true real hardcore issues related to Vundo or SmitFraud anyway. They may make mention of the words SmitFraud or Vundo but they are not the normal main problems areas. Basically Spybot & Ad-Aware are not useful tools in detecting or removing true active Vundo or SmitFraud infections.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds