Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Security and Firewalls
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Security and Firewalls Protecting you against unwanted people and programs

Reply
 
LinkBack Thread Tools
Old 06-01-2008, 02:42 PM   #1 (permalink)
Registered User
 
Join Date: Jun 2008
Posts: 1
OS: Windows Vista SP1


Trojan.Vundo compromised my browser?

Hey guys, there is a problem with my Vista laptop that started recently.

So a few days ago, on startup, a message popped up saying "MSWINSCK.OCX is missing or corrupt". I ignored it and everything else ran like normal. However, every time since then I started up, the same message showed up (again, nothing else wrong). Yesterday, however, my Norton 360 popped "Trojan.Vundo detected" and it began to remove the virus itself in the background as I was doing other things. Afterwards, it prompted me to reboot to complete the removal process. I did. After that, all of these symptons began to show up. I am not sure if these mean there is still a virus in my computer or whether these are the result of damage to the registry that the virus caused.

1. When I used IE7 or Firefox, the browser would work sometimes and other times would strongly lag or just start loading and continue to load ad infinitum until I closed it via task manager. Most notably, there were times the Google search engine was nonresponsive and I could not check my email. This is still going on.

2. This sympton actually happened AS Norton was "fixing" the virus, before the reboot. Whenever I would open folders such as "My Music" or "Documents", the browser would sometimes lag and freeze, then a message came up saying "Windows Explorer has stopped working" and it would prompt me to end Windows Explorer, causing my desktop to go blank and come back a second later. This is still going on.

3. I tried to fix the problem with a 360 Full System Scan, but the scan can never get completed. When it scans about 7 to 9,000 files, it mysteriously gets stuck and freezes. So I have never been able to run a full scan to see if the virus cleared or not. I'm not sure if this is the virus's doing or if Norton just sucks.

I took two actions to fix the problem (other than attempted Norton scans). Firstly, I went back and replaced the "Mswinsck.ocx" file from one I downloaded online and the startup message disappeared. Secondly, I downloaded Vundofix.exe and ran it. It found one file associated with Vundo that attached to a PowerISO registry file, which it deleted. However, all of the symptons still exist. Also, I un- and reinstalled both Firefox and Norton and the problems still exist. I know that Vundo causes damage to the registry so I'm not sure if the problem is that its still around but my Norton just can't do anything about it, or if its already gone and all of this is caused by registry damage. Thank you for any insight you can shed in advance. I'd like not to reformat, since it would be time consuming. Is there any alternative?
blackdiabound28 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 06-03-2008, 03:14 PM   #2 (permalink)
Moderator, Analyst, Security Team
 
TheBruce1's Avatar
 
Join Date: Oct 2006
Location: Důn Čideann,Scotland.
Posts: 5,093
OS: XP


Re: Trojan.Vundo compromised my browser?

Hello and welcome to TSF

Please follow our 5 Step process outlined here:

http://www.techsupportforum.com/secu...oval-help.html

After running through all the steps, please post the requested logs.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.
__________________
Member of ASAP since 2007
Member of UNITE since 2008


**Notice to BT customers**
BT to dump Phorm, see Here for more information. No DPI

If we have helped you in anyway, please consider Donating
TheBruce1 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 06-04-2008, 03:52 PM   #3 (permalink)
Registered User
 
Join Date: Nov 2007
Posts: 175
OS: Win XP/Vista


Re: Trojan.Vundo compromised my browser?

Quote:
Originally Posted by blackdiabound28 View Post
Hey guys, there is a problem with my Vista laptop that started recently.

So a few days ago, on startup, a message popped up saying "MSWINSCK.OCX is missing or corrupt". I ignored it and everything else ran like normal. However, every time since then I started up, the same message showed up (again, nothing else wrong). Yesterday, however, my Norton 360 popped "Trojan.Vundo detected" and it began to remove the virus itself in the background as I was doing other things. Afterwards, it prompted me to reboot to complete the removal process. I did. After that, all of these symptons began to show up. I am not sure if these mean there is still a virus in my computer or whether these are the result of damage to the registry that the virus caused.

1. When I used IE7 or Firefox, the browser would work sometimes and other times would strongly lag or just start loading and continue to load ad infinitum until I closed it via task manager. Most notably, there were times the Google search engine was nonresponsive and I could not check my email. This is still going on.

2. This sympton actually happened AS Norton was "fixing" the virus, before the reboot. Whenever I would open folders such as "My Music" or "Documents", the browser would sometimes lag and freeze, then a message came up saying "Windows Explorer has stopped working" and it would prompt me to end Windows Explorer, causing my desktop to go blank and come back a second later. This is still going on.

3. I tried to fix the problem with a 360 Full System Scan, but the scan can never get completed. When it scans about 7 to 9,000 files, it mysteriously gets stuck and freezes. So I have never been able to run a full scan to see if the virus cleared or not. I'm not sure if this is the virus's doing or if Norton just sucks.

I took two actions to fix the problem (other than attempted Norton scans). Firstly, I went back and replaced the "Mswinsck.ocx" file from one I downloaded online and the startup message disappeared. Secondly, I downloaded Vundofix.exe and ran it. It found one file associated with Vundo that attached to a PowerISO registry file, which it deleted. However, all of the symptons still exist. Also, I un- and reinstalled both Firefox and Norton and the problems still exist. I know that Vundo causes damage to the registry so I'm not sure if the problem is that its still around but my Norton just can't do anything about it, or if its already gone and all of this is caused by registry damage. Thank you for any insight you can shed in advance. I'd like not to reformat, since it would be time consuming. Is there any alternative?
Hi blackdiabound,

This is Mike from the Norton Authorized Support Team responding to your posting.

The Vundo infection is actually what is called a Trojan, and can embed itself deep into your system files.

You mention that you ran a Full System scan (actually called a "Comprehensive Scan" in Norton 360) and that it did not complete. This symptom points to a problem with the LiveUpdate module in Norton 360, which, may have been compromised by the Vundo infection. If LiveUpdate has been compromised then you may not have the latest program and definition files applied to your installation of Norton 360.

Please click on the following link and follow the instructions to run a tool that will launch LiveUpdate.

Fix Tool for when Norton 360 scan stops

After you have run this tool, please read the information in the following link that describes the Vundo infection. At the top of the page, click on "Download Removal Tool" and follow the instructions carefully.

Symantec Vundo Removal Tool

Please follow these instructions and let me know the outcome.

Thank you,
Mike
__________________
Michael York
Norton Authorized Support Team
Symantec Corporation
Michael York is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 10:30 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85