Author Topic: Not confused but concerned....Adware.Vundo-Variant  (Read 7066 times)

0 Members and 1 Guest are viewing this topic.

Offline sasysusie

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 371
Not confused but concerned....Adware.Vundo-Variant
« on: November 18, 2007, 09:14:19 PM »
Hi all... yikes its me again....... computer seems to be running ok but.... I just ran a SuperAntispyware scan and I had somthing in it that has concerned me... I am going to attach the log... I quarantined it all..The part that has me concerned is

Adware.Vundo-Variant
   C:\SYSTEM VOLUME INFORMATION\_RESTORE{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP14\A0003198.DLL
Does this mean I have something bad again in my restore?? Do I need tombe concerned or is this something i don't need to worry about as long as I know have it quarantined??

Ive been being ver carful but I am very gun shy after my last episode the the Grandaddy Troajan and all his family friends and neighbors i wound up with!

Thanks for looking at this for me. 
Susie

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #1 on: November 18, 2007, 09:33:13 PM »
It was just in your system restore point. SAS caught it, bbut you might want to create a new clean point and remove the others.

Create a new restore point

You must be logged on to an administrator account
Go to Start - All Programs - Accessories - System Tools System Restore.
Click Create a restore point, and then click Next.
In the text box labeled Restore Point Description, type a name for this restore point

Remove old restore points

Disk Cleanup - Launch the Disk Cleanup tool and then select the more options tab. On this tab you will find a section for System Restore. If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.


Offline sasysusie

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 371
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #2 on: November 18, 2007, 09:59:43 PM »
Ok did that... how do i get those anyway.. is that something computers just get... or is it me and mine in particular?
Thanks once again im trying to keep a close eye on things!
Susie

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89222
  • No support PMs thanks
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #3 on: November 18, 2007, 10:14:28 PM »
If you don't disable system restore and something is detected from the system folders then system restore saves a copy in the system volume restore _restore point.

It isn't much of a problem there, but if you use system restore some time in the future you could be reinfecting your system. Even then as has been said in the past a file without a run command, etc. it not active, so it shouldn't present the same level of risk/potential. But it is better out of your system than sitting dormant waiting to be detected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

rdmaloyjr

  • Guest
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #4 on: November 18, 2007, 10:17:46 PM »
Ok did that... how do i get those anyway.. is that something computers just get... or is it me and mine in particular?
Thanks once again im trying to keep a close eye on things!
Susie
If Opera was your browser & you used a real-time anti-spyware program like SuperAntiSpyware Professional (not free) or Spyware Terminator (free), you might not have become infected.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #5 on: November 18, 2007, 10:24:29 PM »
Ok did that... how do i get those anyway.. is that something computers just get... or is it me and mine in particular?
Thanks once again im trying to keep a close eye on things!
Susie

It may have been a piece of vundo that SAS didn't pick up before. SAS has probably added 20 or more vundo detections since we cleaned out your computer. Your SAS log was very clean with that one exception. If you do a scan on a regular basis and watch what's going on you should be fine.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89222
  • No support PMs thanks
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #6 on: November 18, 2007, 10:29:37 PM »
Ok did that... how do i get those anyway.. is that something computers just get... or is it me and mine in particular?
Thanks once again im trying to keep a close eye on things!
Susie
If Opera was your browser & you used a real-time anti-spyware program like SuperAntiSpyware Professional (not free) or Spyware Terminator (free), you might not have become infected.

That is a pretty bold statement considering you have no idea how that entry in the system volume information folder got into her system in the first place.

It is perfectly possible to remain safe without Opera and resident anti-spyware, but you do have to take precautions.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline sasysusie

  • Avast Evangelist
  • Sr. Member
  • ***
  • Posts: 371
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #7 on: November 18, 2007, 10:33:47 PM »
Thank you all and yes I am and will continue to run the SAS on a regular basis.  I appreciate your responses it helps me to know I  am OK and don't need to panic!  Your all great ty yet again. Hope you all have a good week and for those of you living here in the States as I am, Happy Thanksgiving Day to you all, hope you all enjoy some great food, good company and just a great day overall!
Take care,
Susie

rdmaloyjr

  • Guest
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #8 on: November 18, 2007, 11:04:22 PM »
Ok did that... how do i get those anyway.. is that something computers just get... or is it me and mine in particular?
Thanks once again im trying to keep a close eye on things!
Susie
If Opera was your browser & you used a real-time anti-spyware program like SuperAntiSpyware Professional (not free) or Spyware Terminator (free), you might not have become infected.

That is a pretty bold statement considering you have no idea how that entry in the system volume information folder got into her system in the first place.

It is perfectly possible to remain safe without Opera and resident anti-spyware, but you do have to take precautions.
DavidR,
Please note that I said "might not have become infected".  I think it is fair to say a fw & antivirus isn't enough today.  A real-time antispyware is recommended.  Opera has built in defenses (so do IE & FF). I think Opera is better.  My sig has the security software that has been successful in keeping my computer from getting infected.  Therefore I recommend them.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89222
  • No support PMs thanks
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #9 on: November 18, 2007, 11:32:21 PM »
Might not, can also have a positive connotation especially when there is no information as to how they were infected and how they 'might have' avoided that particular infection. To me it almost read as an advert for both products.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #10 on: November 18, 2007, 11:51:15 PM »
I don't want to turn this into a p..... contest about what's better or what's worse.

For my 1.5 cents, the infection likely came via messenger and with out a good firewall, it was free to invite others over for the weekend. If SAS had been resident, it may have stopped it. Providing the first ones in the door where ones SAS could detect. About 50+ files where removed after a SAS scan.

There is no doubt that a resident scanner is better than an on demand scanner. But it's not infallible. People still have to watch what they are doing and check as soon as they suspect something is up.

Look at my sig, what you see is what I got. The worst I ever had was a toolbar. and you don't want to know where I've been.  :-[
« Last Edit: November 19, 2007, 12:36:03 AM by oldman »

rdmaloyjr

  • Guest
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #11 on: November 18, 2007, 11:58:21 PM »
Not to argue, but when you don't know how you were infected, it's logical to cover all the bases you can or know how to.  Therefore I recommend more than a fw & av.  The economical way is with the best freeware available.

What do you think of Returnil?  It is the only freeware of it's type.

rdmaloyjr

  • Guest
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #12 on: November 19, 2007, 12:40:48 AM »
To all that are reading this thread: DavidR & I aren't having a p______ contest.  This is a healthy discussion.  Sasysusie asked a good question.  Many don't know how they became infected.  A better understanding of how can help keep from getting infected.  The old saying "an ounce of prevention is worth a pound of cure" is true.  Safe surfing is as important as protective software.  Oldman is right, good security software isn't infallable.  It has to be constantly updated to be protective.  In between we can be infected.

DavidR & Oldman can give better insight on this subject than I can.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #13 on: November 20, 2007, 07:51:15 AM »
What do you think of Returnil?  It is the only freeware of it's type.

I don't know. It could be of use, depending on what you where doing.

Updates would have to be done either manually or with it turned off and anything you wanted to download would have to be to another partition.

Seems to be similar to another one called sandboxie, I guess the bottom line would be if it suited your needs, go ahead and try it.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Not confused but concerned....Adware.Vundo-Variant
« Reply #14 on: November 20, 2007, 07:31:45 PM »
What do you think of Returnil?  It is the only freeware of it's type.
Very good and stable. Worth a try. Worth to be used when testing software. I've used on XP. Thanks for remembering me to check if it is Vista compatible...
The best things in life are free.