Author Topic: yayaysqq.dll warning  (Read 3473 times)

0 Members and 1 Guest are viewing this topic.

theoldthug

  • Guest
yayaysqq.dll warning
« on: June 30, 2009, 12:20:44 AM »
Just got this warning today from avast that this file has a Win32.vitumonde-US trojan, when i said to put it in the chest it said that it was being used and couldnt be done.  So I hit the no action button, which said it wouldnt be activated.  Looks like it was created in feb 09 so not sure why it is just now telling me.  Any ideas.  it is in the windows\systems32 directory.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: yayaysqq.dll warning
« Reply #1 on: June 30, 2009, 12:38:58 AM »
Are you using Windows XP/Vista?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.
If infected files are found, it's safer to send them to Chest instead of deleting them.
This way you can further analysis them.

Virtumonde is a very dangerous infector. Backup your documents and data asap.
The best things in life are free.

theoldthug

  • Guest
Re: yayaysqq.dll warning
« Reply #2 on: July 01, 2009, 02:31:08 AM »
I am using XP I did a scan and I moved all problems to chest.  I dont quite understand your instructions,

Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.

What does the boot mean? Do u mean do that and then restart computer or what?  I see scan local disks, scan archive files, then click schedule?  Does this reboot computer or what?  I also ran spybot and it did some removal.  I ran Avast and moved all to chest that it said.

cinchez

  • Guest
Re: yayaysqq.dll warning
« Reply #3 on: July 01, 2009, 03:10:43 AM »
Boot means computer start up procedure: the process of starting or restarting a computer and loading the operating system^^

Boot+Scan=Boot scan^^

Restart ur PC if u want the boot scan to work^^

-AnimeLover^^

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: yayaysqq.dll warning
« Reply #5 on: July 01, 2009, 01:35:17 PM »
Hi  theoldthug,

Here are vundo removal instructions: http://www.bleepingcomputer.com/virus-removal/remove-vundo-virtumonde

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

John2009

  • Guest
Re: yayaysqq.dll warning
« Reply #6 on: July 03, 2009, 07:36:38 PM »
Vitumonde is Win32 Vundo, or MS Juan.