My Win32.virtob Experience

AMD K6
edited August 2008 in Malware talk

Hi.


I would like to share an experience that in my 10 years of computing never encountered.


I purchased a used Dell computer on Ebay around 2 months ago. The computer's hard drive was wiped clean in the description and, only required an operating system. When it arrived I installed Windows XP as I've done many of times and, installed my additional internal hard drive for it was going to be my primary Internet PC.


Or so I hoped.......


Upon installing the Ethernet drivers, I was greeted with XP Anti Virus 2008 Icon on my desktop. I thought this was very weird concidering none of the programs I used were that current. I fire up Adaware, finds the trojans, deletes them and that's that.


Or so I assumed........


I begin to modify the registry so the response time is faster than Windows default, restart the computer and what am I greeted with? A red X located in the lower right hand corner stating your computer is infected, click here to remedy the problem.


Not falling for that routine, I go directly into Windows system32, and begin tracing what was installed by time and date. I was astonished with the amount of things installed without my knowing.


I proceed to delete certain items and, of course some would return upon pressing F5 where as others wouldn't delete because they were in use. Fine. Off to Adaware I go and, proceed to clean the drive from trojans again. It removes the trojans as it did previously. This time, I run my registry cleaner to make sure all strings are cut or deleted. Everything turns out squeaky clean and, I reboot the computer.


Would you believe the bloody AntiVirus XP 2008 returns with more friends?


I reformat, and install Windows XP all over again. However, this time I leave the Internal drive inside to save time, and, I am again greeted upon a fresh install once installing the Ethernet driver Anti Virus XP 2008.


Needless to say, I am very frustrated and, pull the internal drive out of the Dell, go back to my HP, and put the Dell on the side.


So, I install the internal drive in the HP, and would you believe Anti Virus XP 2008 is now on this computer??!!!


I wipe the HP computer clean and reinstall Windows 2000 and all of a sudden the internal drive will not work. I pull out the drive and install it in my oldest Compaq offering Windows 2000 and the drive is readable. Noticing, that some of the folder dates were altered as with Windows System32 on the Dell, I decide to pull the non effected folders from the drive on to a CDR.


The burner halts stating it cannot find the files.


So, I reformat the drive erasing all my work.


I go back to my Dell seeing this was the root of the problem, reformat and, install Windows XP again.


Sucess finally!


Oh so it seemed.


Upon installing the Ehternet I was now greeted with Anti Virus XP 2008. By this time I really felt this computer was possessed. So, I install Adaware again updated the definitions and, did a deep scan. This time it worked.


I install browsers, Microsoft Word and, the newly formated internal drive. Everything works. Finally no Anti Virus 2008!


Feeling something is up, I start searching for other Anti Virus software and remember hearing about Bitdefender after seeing such high reveiw ratings. My eyes opened widely once I seen they offered a free version. So, I pranced on it. I installed the software and let it scan for trojans.


It found 734 infections and 8 viruses. Once it cleaned the computer, I restarted the computer and guess what?


It wouldn't boot beyond the Welcome. I do remember it moving lots of Windows system files that could not be corrected.


So, I reinstalled Windows XP again however, this time I installed Bitdefender again from the internal hard drive I reformated on my Compaq. I also had Adaware and, my bookmarks as well on the drive.


Bitdefender states the definitions are corrupted and it needs to delete them and, download them again. I click "OK." It begin scanning the computer again and I starts to delete files.


Would you believe Adaware and, 70 of my bookmarks was infected??!!!


It seems Win32.Virtob attacks everything in the computer and, I corrupted all three swapping the Internal drive from the Dell, to the HP and, finally the Compaq.


I am happy to say, that I am typing this on the Dell with BitDefender Free edition active and the computer is working trouble free.


Cheers to the BitDefender developers for if it weren't for your sofware, I would have never had an opportunity to enjoy this Dell computer.