Trojan.Vundo won't die

Discussion in 'Malware Help (A Specialist Will Reply)' started by voicecats, Dec 2, 2007.

  1. voicecats

    voicecats Private E-2

    Kinda confused here.

    Symantec autoprotect keeps finding trojan.vundo viruses every day or so and says reboot required to fix it. Sometimes I reboot, sometimes I don't, it comes back again either way.

    Google led me to your "Special Removal Procedures" page and I went through the one for Virtumonde/Trojan Vundo. However, the fixvundo.exe application keeps telling me that vundo was not found on my system. Yet, trojan.vundo keeps popping up in Symantec.

    I'm so confused.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. voicecats

    voicecats Private E-2

    My apologies for posting before looking through all the other stuff on the board. Chalk me up as another one in too much of a hurry to do stuff right.

    I saw the Read & Run Me First post shortly after posting this thread. Logs/reports are attached.


    Little further info on the symptoms:
    Every once in a while, my taskbar and desktop icons disappear for 10-15 seconds and then come back. I'm also getting IE pop-ups even though I use Firefox. I honestly wouldn't know if those are because of the vundo or because of something else entirely, but they seem to have all showed up at the same time.

    Also, upon reboot after running combofix, an IE shortcut had appeared on my desktop. Is this normal?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure at this point.

    While I look thru all of your logs, please do the below. Do not skip the reboot.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not seeing any true signs of Vundo on your PC. If Symantec detects anything again you will have to provide a log that shows exactly what and where it is finding this.

    Does Spybot detect anything? Sometimes leftover and somewhat benign registry keys related to Vundo are laying around and it seems than many scanners cannot remove them for some reason (probably a registry permissions issue).


    I suggest you do the below so we can be sure that it is not something being detected in System Restore.

    Do you know what the below file is from? Does the date coincide with the start of your problems?
    Code:
     
    "C:\WINDOWS\"
    wpd99.drv     Nov 26 2007          59  "wpd99.drv"

     
  6. voicecats

    voicecats Private E-2

    I did the following:
    Uninstalled J2SE Runtime 5.0
    Rebooted
    Installed Sun Java Runtime
    Disabled System Restore
    Rebooted
    Enables System Restore



    Spybot did not detect anything when I ran it just now. However, last night, it detected Virtumonde and said that it fixed it. However, this had happened several times before with Spybot saying it had fixed it, but the problem popping up again.


    I will see if Symantec continues to detect vundo files. If it does, I will attach logs.



    I believe wpd99.drv is a driver associated with pdf995, the program I use to print other types of files to PDF files. The Nov 26 date coincides with the last time I had used pdf995 to create a PDF (and the last time wpd99.drv had been modified coincided to the minute with the creation of my most recent PDF). Just now, I created a test PDF, and sure enough, the "Last modified on:" date for wpd99.drv updated to that moment. While Nov 26 is relatively near the start of my problems (though still a couple days before, I believe), I'm pretty sure that's a coincidence. I'm fairly certain wpd99.drv is not malicious, but I could be wrong.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That would be good but sometime Symantec can be rather poor at indicating exactly where things are found.

    This is probably correct. I had seen it associated with PDFs too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds