• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 3869
  • Last Modified:

Trojan.Vundo, Downloader.MisLeadApp, and Adware.Ezula Infection

My computer is infected with Trojan.Vundo, Downloader.MisLeadApp, and Adware.Ezula. I've an up-to-date version of Norton Antivirus running and on a daily basis it quarantines Vundo and Ezula. I get popups now and again. I have SpyBot running and every morning when I wake up I have a list of registry entry keys that the system is attempting to change. I have run scans of SpyBot and Ad-Aware and Netcom3 but haven't been able to remove the spawning application.

This happened last Friday (it is now Wednesday). I posted a HijackThis log here: http://www.techsupportforum.com/search.php?searchid=2367013. Perhaps you need a more up to date log? Please let me know what needs to be done. I freelance from home and this bug is eating away at my time. I have only myself to blame for snooping the internet - I have learned my lesson. But how much longer do I need to be wacked!!!!!

I appreciate your help. Regards...
  • 7
  • 5
7 Solutions
Vundo is stubborn and nasty. Can't see your log because you need to sign up at the sight.

Download and Run ComboFix (by sUBs)


Disable your Anti-virus and any real-time Anti-spyware monitors that are running.
Then double click Combofix.exe & follow the prompts.
When finished, it will produce a log for you. Upload that log in your next reply with a new HijackThis log. Please upload the log at EE-Stuff.com
Use the link below and login using your Experts-Exchange username and password.
Click on "Expert Area" tab
type or paste the link to your Question
"Browse" your pc to the location of your Hijackthis log and click "Upload"
Copy the resulting "url" and post it back here.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall.
Note 2: Remember to re-enable your Anti-virus and Anti-spyware.

NOTE: If you have issues connecting to your network or internet after running combofix you can either simply reboot, or do the following:
* Going to Control Panel > Network Connections.
* Right click on their Network icons & select "Repair"
Alternately, if the Network icon appears in the notification area in the lower right corner of Desktop, right-click it, and then click Repair from the shortcut menu.

Please also rename HijackThis to something else before running it and uploading your log.
joibrooksAuthor Commented:
i have sent the log files you requested. since i rebooted, i have another issue now. at a cold startup i get a rundll message:

Error Loading

when i click okay, the system boots.

thank you...
>""Error Loading

That is one of the Vundo files. It is in one of your run keys. More work to do with combofix. I will give you a CFScript to run that will fix that. Just give me a bit to comb through the log and I will post a script for you with instructions.
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

I would recommend you remove the Pando Toolbar and program. It is supported by Adware.
Also...Spyclean and or Netcom3 Cleaner is also a rogue Anti-Spyware application and should be removed.
You can try using Add or Remove Programs to get these first but we may need to make manual deletions.
I am going to include Spyclean removal in the combofix script.

1. Open Notepad.

2. Now copy/paste the text between the lines below into the Notepad window:



C:\Program Files\yzudexmv
C:\Program Files\Unezyuxj
C:\Program Files\Netcom3 Cleaner

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{299E86A2-BF77-41BC-84C2-FA57787C2BCE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{376F3CEB-BB08-4FA1-B7FC-168A61DFA458}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62780D18-D103-03D3-323A-01F43008B839}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79B3844B-6DAC-4B78-B0B8-C99D8BBDCD50}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{86F7CF81-69B0-4270-BC06-9D3D0CC42B87}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebbcdc]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


3. Save the above as CFScript.txt on your desktop.

4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please upload the following reports/logs.

-A new HijackThis log

joibrooksAuthor Commented:
okay. i've uploaded a new combo and hijackthis log file. doctor, what is the prognosis?
Looks better, how's it running?

A couple of Vundo files popped up or were missed. You can run another CFScript with them under files:, or just delete them manually.


Also, still a service present for that Spyclean garbage program.

To remove...

Click Start -> Run...
Enter the following commands one at a time into the window and click [b]OK[/b] each time.

sc stop Netcom3
sc delete Netcom3

Run HijackThis and fix this item:

O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing)
Sorry, left bbcode around "OK" above. There shouldn't be any [b]'s
joibrooksAuthor Commented:
okay. status:

after i ran sc stop and delete Netcom3, the comment doesn't show up in the HiJack log.

i created and ran the cfscript to delete the .dll files in the win system32 directory.

i'm very hopeful here!

should i get rid of  the SpyBot app?
>""should i get rid of  the SpyBot app?""<

No, well, up to you....Spybot S&D is good for one time scans. And TeaTimer works well if it's not too annoying. But the program has been around since the dawn of spyware and is good.
joibrooksAuthor Commented:
that's a roger on spybot.

i'm going to leave this ticket open for a day. i'm VERY hopeful. by tomorrow you oughtta be 500 points richer. and tonight, if your ears are ringing it is because i'll be praising you at dinner time prayers. thank you for hanging in there with me.

No problem jb, glad we could help and thank you (lord knows I need all the prayers I can get ;))
joibrooksAuthor Commented:
Prompt response, exceptional ability, professional and  knowledgable. Well deserved rating of  A++

Featured Post

SMB Security Just Got a Layer Stronger

WatchGuard acquires Percipient Networks to extend protection to the DNS layer, further increasing the value of Total Security Suite.  Learn more about what this means for you and how you can improve your security with WatchGuard today!

  • 7
  • 5
Tackle projects and never again get stuck behind a technical roadblock.
Join Now