A Virtumonde variation?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ptpt, Dec 21, 2008.

  1. ptpt

    ptpt Private E-2

    Hi,

    I was infected with that virus yesterday. Found your site and did the READ AND RUN FIRST (see attached files). The process managed to remove Smitfraud and Virtumonde generic along another one I can't remember (I think).

    But I redid a Spybot scan, and Virtumonde still show up. Spybot can't fix the problem since it says it's still in the memory (SEE JPG SCREEN CAP) and it should be resolved by making an automated scan upon reboot. So I restarted the computer, Spybot makes a (lenghty) scan, returns me to the program's interface without letting me know if something was fixed or not. I scan again to verify, and Virtumonde is still there...

    And I disabled the Windows Messenger thing too awhile ago but it didn't do any good, so now before trying all these other solutions listed in other posts, I'd rather know if my problem is more particular and needs a specific and different solving approach.

    Thanks in advance!

    PT
     

    Attached Files:

  2. ptpt

    ptpt Private E-2

    Here are my other files.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
    After you attach these two logs we will continue with any fixes required based on you first set of logs.
     
  4. ptpt

    ptpt Private E-2

    Hi again,

    Did all the steps, but it seems to still be there. Even did a Spybot scan afterwards and I get the exact same Virtumonde notice that the program can't remove, even after a reboot (see previous spybot screencap).

    However, since that last 1rst cleanup, pop-ups have not resurfaced and all seems to be working properly. Although I must say that I hear a standard windows warning sound coming out of nowhere and without popping a warning notice (about 5 to 10 minutes after a regular opening of the pc, or maybe longer, haven't noticed the exact timing)... Doesn't seem to affect the computer, but it's strange nonetheless.

    So as much as things look like working ok, I'd still be much more reassured if those malignant remnants were completely out of my system.

    Thanks for your continuing help,

    Pat
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have asked the people at SUPERAntiSpyware to check this out. We have had good luck with the new version you just ran on many other PCs. Not sure why this particular one is slipping thru.

    But in the meantime, let's manually fix other items I saw in your logs that the scans were not picking up. Perhaps this will help us. Not sure why the scanners are missing these obvious AppInit_DLLs key and task job infections.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll (file missing)
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll (file missing)
    O20 - AppInit_DLLs: grdila.dll xgscwa.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now try running SUPERAntiSpyware again. It will be necessary to run it twice. The second time after a reboot. This is the only true way to see if the infection comes back or not.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe from the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • the two new SUPERAntiSpyware logs
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 1, 2009
  6. ptpt

    ptpt Private E-2

    I know, I know, I know, it's been a million years. No excuses.

    BUT, I finally did this procedure.

    I wanted to have a clean pc since I'm having problems with another program.

    And all I can say, is that Spybot no longer finds that irremovable Virtumonde thing. So it's done, it's gone!

    Many thanks for your great help and support!

    I'm including the files anyway.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You waited too long and your copy of ComboFix was thus way out of date causing it to run in Reduced Functionality mode. Just to be safe, you need to download the current version of ComboFix and run the fix again.

    Is everything running okay now?
     
  8. ptpt

    ptpt Private E-2

    Everything was fine, but I did download and did the check up with the new Combofix to be on the safe side like you said. Log file included.

    I'm currently having issues with After Effects and doubt at this point that my problem is related to a virus or anything of the sort. YET, for the first time a bizarre message prompted an AE tab with this name "Droverlord frame window". First time I'm seeing this and there's literally no answer or info on this AE error only that a person suggested (without any backing) it could be a virus... Must admit it does sound more like a virus name then a typical After Effects error message... Ever heard of this name?

    Other than that, all feels totally fine!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you did not rerun the fix using CFScript.txt. You just ran ComboFix which is not what you needed to do. However I have something else to fix so let's create a new fix and I will add the old items to it just to be safe. As far as problems with a After Effects, I suggest that you post in the Software Forum as that means nothing to me. I believe it may have something to do with Adobe.



    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )





    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 2, 2009
  10. ptpt

    ptpt Private E-2

    Ok, so I've done the steps. Here are the results.

    Things have been running alright since the last checkup. I believe all is good, unless you find something in those included log files.

    Thanks alot for your help again!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds