Vundo woes

BlindedByScience

More Human than Human
Joined
May 26, 2000
Messages
9,225
Guys - greetings. I'm pretty good with the hardware side of things but maybe you can teach me a thing or two about Vundo and the "AntiSpyware2008" crap that seems to be going 'round.

We have a vanilla NAT router and I've been running McAfee V8.0 as my virus scanner. I've been running Firefox as my browser and hadn't even seen a virus in years. Guess my luck finally ran out. Last week, I got hit with the Vundo malware and about two days later, got hit with the "AntiSpyware2008" variant. I ran Windows Defender and MBAM several times with the system restore turned off (XP Pro here) and deleted all the cache files in both Firefox and IE. I ran MBAM in safe mode and it didn't find jack, but when I ran it under "normal" Windows, it found what I'd expect it to find for these trojans and deleted them. Interesting, but deleted is deleted. Figured I was good.

I am pretty sure I left Firefox running overnight and I am assuming that's how the trojan got in. Am I right?

Woke up this morning and Defender had found and deleted Vundo again. Now, I'm very sure that the browser and e-mail were both off last night and there was no internet connectivity.....that I'm aware of. So, I guess there are at least a couple of possibilities;

- The trojan(s) installed a back door that's running and letting this crap in.
- I didn't manage to get it fully cleaned up and it went active again.

Any suggestions and learning you guys could offer would be appreciated; thanks in advance.
 
Search the forum....from this network forum, to the operating system forum, to the software forum..there's usually about 5 of these posts per week.

Common answers....

Delete system restore
Run CCleaner
Spybot S&D
MalwareBytes
SuperAntispyware
Antivir or NOD32

If you can slave the drive to another healthy PC, do so, and scan using above tools

Sometimes some special tools like SDFix.exe or Combofix.exe help (Google from BleepingComputers)..but newer variants are escaping those old tools..since the ZLob trojan has several new variants per day released.
 
I followed StoneCat's instructions and all seems well again.

My question - how do these get in? Are they browser exploits, e-mail exploits, or...??

I do know I left my browser up all night before this all happened and I'm assuming it allowed something to get in...??
 
I followed StoneCat's instructions and all seems well again.

My question - how do these get in? Are they browser exploits, e-mail exploits, or...??

Several different methods, including
*Yes, websites get hijacked..and the installer code for drive by installs gets hacked into the site
*Video Codecs are common, as many people will eagerly click "Yes" to install those into their browsers to watch some online video
*P2P/torrent distibution. That song you think is just a song, or that movie, or "free" software you want to download...guess what..there's a nice little treasure packed inside. When you play that song or video....it often uses a media player exploit to hit your system and install the trojan.
 
Back
Top