vundo.jl

Discussion in 'Malware Help (A Specialist Will Reply)' started by GoodZwell, Jan 1, 2010.

  1. GoodZwell

    GoodZwell Private First Class

    Hi,

    Having problems with my computer running very slow.

    WinXp Pro vs. 2002 Service Pack 3

    Pentium 4 3.oo ghz
    1.5 g or ram

    On boot up (about 50 % or the time) AVG says it's realtime protection is turned off, but if I reboot it almost all the time fixes that problem. During the boot up I frequently have to hit F1 or F2 to set up the bios.

    One day I was booting up the system and received an avg report stating that "vundo.jl" was found and was a virus. I searched the area with AVG again but it found nothing. I game a lot and have been experiencing very slow loading of maps.

    I've tried to follow the instructions in previously posted problems with this vundo, but I don't seem to be able to see the first part of the posts.

    All the virus scans I've done have found nothing but tracking cookies, and I've done online scans too. Please help.

    Thanks for your help,


    Goodzwell
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First just an up front warning that most "slow PC problems" are due to what is being run not malware.


    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide



    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. GoodZwell

    GoodZwell Private First Class

    Thanks for your help. I'm not sure I've gotten rid of all the problems, I've just finnished running the programs you sudjested. Here are my logs:

    RootRepeal.exe didn't seems to load correctly as I received and error while installing. I printed screen so you can see. I'll attach it to the following post.

    Thanks again for your help. You guys are awsome. :)
     

    Attached Files:

  4. GoodZwell

    GoodZwell Private First Class

    RootRepeal error message.

    opps. I guess you can't use .jpg.

    The message says:

    RootRepeal Error
    error - invalid PE image found!
     
    Last edited: Jan 4, 2010
  5. GoodZwell

    GoodZwell Private First Class

    UPdate on how my computer is working.

    I've used the computer for most of the day today and for the most part things seem to be working ok but still kind of slow, especially when loging out of Steam. After loging out of steam my screen takes a while to get back into the correct resolution and sometimes, like today, the desktop picture I have only covers part of the screen. When I try and fix it I lose that picture all together. In fact last week when it did the same thing I lost the picture completely, the picture I was using for my desktop was completely obliterated from my hard drive. Any how more food for thought.

    Thanks guys, your the best. ;)


    GoodZ
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    RIght now it does not appear that you are having malware problems, but to continue, we require the log from MGtools that was requested. This is the C:\MGlogs.zip file.

    Also note, everytime you add a post, you bump your thread to the bottom of the work queue making it take longer to get a reply. See: Don't Bump! It Only Hurts You!!! Intentional or not, every post causes a bump.
     
  7. GoodZwell

    GoodZwell Private First Class

    Sorry didn't think updating what was happening to my computer was bumping. Opps thought I did gave you that file to look at, my bad. Thanks for you help. :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The effect is still the same as noted in the sticky.

    Based on your logs, you are not having malware problems. AVG may be the cause of your performance issues. It is quite a resource hog. Try uninstalling it and see if things improve. If they do then try a different free antivirus program like Avira or Avast.

    It looks like ComboFix incorrectly identified a bunch of the files for you Creative Labs hardware as malware. Most likely this is due to the poor choice of location. Creative Labs should not be storing their file in folders that belong to Windows. Do the below to restore these.


    Now we need to use ComboFix to restore false detecions.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. GoodZwell

    GoodZwell Private First Class


    I have uninstalled AVG. Things might be working faster a little bit but it's very hard to tell. I've run combofix as instructed however, when the computer rebooted at the end it seemed to hang. I left it alone thinking it was just combofix but after a half hour I decided it wasn't the case, so I hit the reset button becuase the "shutting windows down" screen wouldn't let me do a "ctrl-alt-del" to see if windows had stoped responding. In the combofix text file I noticed that it says windows shut down, not the case. Any ways here's the files you requested.

    Thanks for your help.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but I asked for the wrong follow up log from ComboFix in my last message. It should have been DeQuarantine.txt but it does not look like the restore worked properly. Check your C:\WINDOWS\system32\Data\ folder and see if those .dat files were properly restored without the .vir extension. Make sure that you are not interferring with ComboFix after the reboot. Give it adequate time to restore all the files and make a log.
     
  11. GoodZwell

    GoodZwell Private First Class

    This could be a problem as there is no folder called Data in the System32 folder.

    :cry
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a problem. Just create one. All of those file that were removed from this folder by ComboFix can be copied back from the ComboFix Quarantine and then renamed to remove the added .vir file extension. Since ComboFix did not run properly for you last time, you may have to do this manually. The files I'm referring to can be found in the below folder:

    C:\Qoobox\Quarantine\C\WINDOWS\system32\Data\
     
  13. GoodZwell

    GoodZwell Private First Class

    Sorry it's taken me so long to reply.

    Update. After consideration and the lack of ability on my part, I decided to go out and buy a new hard drive and start over from scratch. Things just weren't speeding up my computer like I thought they should. Any how. Sorry I didn't mean to waste your time and effort.

    Things seem to be working ok now but things are still loading slow, pages don't open as quickly as they use to, programs don't seem like they run as quick as they use to. Now today I've got a new problem.


    Avast detected a problem and I had to quarinteen a file which was detected in my Creative Labs forlder. It was called win32:malware-gen. I guess I should start another thread eh? This is why I think I may have bigger problems then once thought, I think I've got a root infection. Any how let me know if you want me to start another thread.

    Thanks for your help.

    GoodZ
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably your connection, your router or something else you are running. As stated in my 1st message to you, slow PC problems are not always due to malware and your logs were clean.

    Most likely a false detection, especially since you just reinstalled, but without a log showing exactly what was detected, I cannot say for sure. Names of infections are almost useless to us. We need the names and paths to the files or registry keys that are being detected along with the supposed infection name.
     
  15. GoodZwell

    GoodZwell Private First Class

    Thanks for you help. Is there a section here in these forms that could help me determine if I have internet connection problems, seems to me that I've been sparaticaly losing connection for short burst maybe. I say that because I'm a gamer and the game, L4D2, seems to be losing connection to the Steam server a lot lately.

    Goodzwell :)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you are having problems with Games, try the Games forum. Otherwise perhaps the Networking forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds