Having Fun-do with Vundo

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gankin247, Aug 11, 2008.

  1. gankin247

    gankin247 Private E-2

    Hello Abri and Chasling. You may recall about a month ago you both helped me remove vundo. Somehow I have become reinfected.

    The first symptom I noticed was that I began having a delay of about 5 seconds when I would start IE, the same delay I had with the previous infection, where the program starts but nothing appears in the address bar and the homepage does not appear for about 5 seconds. I am also experiencing slow browsing.

    I ran malwarebytes antimalware and it found and deleted vundo from the registry, however the browser problems, delay and slow browsing, still persist.

    During the previous infection, deleting the following files fixed the slow browser startup, but I do not currently have any of these files:

    c:\windows\newcamerapix.zip
    c:\windows\game.exe
    c:\programfiles\uninstall.exe
    c:\programfiles\uninstall.dat

    You may also remember I began having some issues with McAfee during the previous cleaning. I have since been able to reinstall McAfee and have not experienced any of the previous problems. Mafee's firewall is not installed.

    The Norton I have currently installed is the Utilities portion only and not the antivirus portion of the program. I use the Norton utilities since the defragmenter is better than window's defragmenter. Since I have utilities only installed, and not antivirus or firewall, I did not think I had to delete it. Please let me know if I have to do so anyway.

    I am going to post my logs. You will see that SASlog is missing. This is because I still cannot install superantispyware, as I still get the same error 1606. I hope you can still help me. Please let me know if there is an alternate program I can run that will accomplish what superantispyware does.

    The logs included are from malwarebytes, combofix, mglogs and smitfraudfix. I did not run the smitfraudfix cleaner because I can't tell if it found anything. I have include a combofix about quarantined files.

    Thanks.
     

    Attached Files:

  2. gankin247

    gankin247 Private E-2

    Other logs
     

    Attached Files:

  3. gankin247

    gankin247 Private E-2

    I forgot to say earlier that, unlike the first infection where the first symptoms were all sorts of bogus popups, then only symptoms I have had this time are the browser delay and slow browsing. I also forgot to say I ran Spybot, but it did not find anything.
     
    Last edited: Aug 11, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because this time you are not having malwar problems. The best guess is that your problems are due to the choice of running all the junk from Symantec while also installing McAfee's tools. Between the two of them, your PC is overloaded with processes and services. Just look at you HijackThis log and you will see the below from the two different companies:

    Symantec Related:
    McAfee Related:
    And when you add all the junk from Roxio, it makes things even worse.

    You can use HijackThis to fix the below lines but they are not malware and will not change anything:
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
     
  5. gankin247

    gankin247 Private E-2

    Thanks for your reply chaslang. I guess I lucked out this time in that Vundo didn't spread from the registry before malwarebytes antimalware removed the registry entry. So that is good.

    I'm going to use hijackthis to kill the extra symantec and roxio processes. If the programs no longer work, I will remove them.

    In either case, can you recommend a standalone program similar to Norton utilities that has a defrager that is superior to windows defrag, without all the extra junk processes? Can you also recommend something similar to Roxio that has excellent DVD backup and audio capture, which are the only two reasons I use Roxio.

    Thanks again. I'll post again in a few minutes to let you know what happens after I use hijackthis.
     
  6. gankin247

    gankin247 Private E-2

    Chasling,

    I removed Norton using the removal tool, and then removed Roxio using add/remove programs. I then ran CCleaner and registry cleaner.

    I still have the same delay when starting IE. If it is something unique to my computer, I can live with it. I just want to be sure, since malwarebytes did find vundo, that it's not malware related. I have attached a fresh set of mglogs. Thanks for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not malware. It may still be due to one of two things:
    • McAfee
    • or some browser addon that you have. You should try disabling all browser addons and see what happens. Also try a different browser.
    That was just a benign registry key. You did not have an active vundo infection.

    You did not successfully get rid of all of Symantec or all of Roxio. You will see the below in your HJT log:

    O4 - HKCU\..\RunOnce: [] C:\Program Files\Internet Explorer\IEXPLORE.EXE http://www.symantec.com/techsupp/se...0000070.0000014d&c=00000082.000000e6.0000026f
    O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe (file missing)

    You may be able to just fix both with HJT; however there is a chance that the O23 line for the service will not go away. You may have to stop and disable it first using services.msc from the Start, Run, box.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds