Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
How did I get Trojan.Vundo?

Reply  
Thread Tools
ACA529's Avatar
Computer Specs
Distinguished Member with 6,186 posts.
 
Join Date: Nov 2005
Experience: Intermediate
21-Dec-2008, 09:03 PM #1
How did I get Trojan.Vundo?
I haven't used my desktop computer for quite some time so I decided to turn it on today and all of a sudden I got a whole bunch of pop ups.

I did a scan with Malwarebytes to see what was there and it picked up Trojan.Vundo.

I then did a scan with ComboFix and it seemed to take care of it. Malwarebytes no longer picks anything up.

I haven't browsed any malicious websites or anything so I'm wondering how I got it in the first place?

Thanks.


EDIT: I didn't wait 'till the scan completed, and it did pick up more of it:

Malwarebytes' Anti-Malware 1.31
Database version: 1528
Windows 5.1.2600 Service Pack 3

2008-12-21 20:07:14
mbam-log-2008-12-21 (20-07-14).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 210928
Time elapsed: 1 hour(s), 0 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Last edited by ACA529; 21-Dec-2008 at 11:43 PM..
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
22-Dec-2008, 01:29 AM #2
Do your Windows Update now. Since you havent turned on your PC for a while.

Normal websites can get hacked, and could be set to push malware onto visiting PCs. Especially to PCs that haven't been patched.
ACA529's Avatar
Computer Specs
Distinguished Member with 6,186 posts.
 
Join Date: Nov 2005
Experience: Intermediate
22-Dec-2008, 11:04 AM #3
Quote:
Originally Posted by lunarlander View Post
Do your Windows Update now. Since you havent turned on your PC for a while.

Normal websites can get hacked, and could be set to push malware onto visiting PCs. Especially to PCs that haven't been patched.
The only update I saw was the important one for Internet Explorer. I updated it.

I don't use IE anyways so I can't see why that would be the cause.

Thanks for your reply.
mrss's Avatar
Registered User with 722 posts.
 
Join Date: Jun 2007
22-Dec-2008, 01:07 PM #4
From what I've heard, vundo used vulnerabilities in Java, so if you were using a non-patched version in your browser, it could get in just by browsing to an infected website.
ACA529's Avatar
Computer Specs
Distinguished Member with 6,186 posts.
 
Join Date: Nov 2005
Experience: Intermediate
22-Dec-2008, 02:01 PM #5
Quote:
Originally Posted by mrss View Post
From what I've heard, vundo used vulnerabilities in Java, so if you were using a non-patched version in your browser, it could get in just by browsing to an infected website.
I actually noticed the Java logo in the taskbar load when I was on a site and then this strange email window popped up. I closed it and then all of a sudden I got all the pop ups.

I was using Firefox.

EDIT: The pop ups were using both IE and Firefox.

Last edited by ACA529; 22-Dec-2008 at 03:06 PM..
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 11:40 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.