Famous Virtumonde

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Lanterif, Aug 7, 2008.

  1. Lanterif

    Lanterif Private E-2

    Hi There,

    I lost about 3 days ago all my icons on my desktop. I understand that this may be related to Virtumonde as I also have received a few notification from Spybot that I had such a malware and also from Norton Antivirus.

    I followed the instructions on a previous post from TimW but it seems that after running MGtools the lines which were provided on the post and which should be fixed were not in the results of my scan of MGTools. I understand that it helps if I attach my combofix report. Can someone let me know after reviewing my combofix report what needs to be done to remove any problems.

    I would also like to know how to restore all the icons on the desktop including "My computer", "My documents", Windows live messenger and a few folders which I previously had on the desktop.

    Many thanks
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Never a good idea to try to apply someone elses fix to your computer.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode
     
  3. Lanterif

    Lanterif Private E-2

    Hi there,

    Thanks for the quick answer. I attach 3 of the logs. The 4th one will follow in the next post. Please let me know if any further action needs to be undertaken.

    Further, please let me know if there is a way to restore the original icons and the originals settings before the malware came into action.

    Many thanks
     

    Attached Files:

  4. Lanterif

    Lanterif Private E-2

    see attached last log.

    thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans did their job.....I'm not seeing any problems with your logs.

    What settings are you referring to, as some will revert when I give you the final cleanup.

    As for icons....you should be able to right click them / properties / change icon.

    Tell me what problems you are having.
     
  6. Lanterif

    Lanterif Private E-2

    Thank you for confirming that all is in order.

    In terms of "icons" and "settings", I used to have two profiles (2 fully authorised administrators) under XP. One for me and one for my girlfriend. The profile of my gf is fine. However, I can access my profile but all icons including the various shortcuts to "My Computer", "internet explorer", "My documents" disapppeared. Additionally, when I click "Start", all the shortcut to varioous programs are gone or when I try to open "Word" for instance, I receive the following message: "Windows cannot acess the specified device, path or file. You may not have the appropriate permission to access the item."

    Can all previous settings be restored or should I just delete my profile and recreate a new one and reinstall all programs. I used to have outlook with several contacts and it is gone too.

    Thanks
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you been running the scans under just the gf's account? You need to run both SAS and MWB's under your account also. Tell me if you can't ..attach the logs if you can.
     
  8. Lanterif

    Lanterif Private E-2

    Hi,

    I tried to run SAS and MWM from my profile but I cannot. I receive the following message anytime I am trying to run any programs: "Windows cannot acess the specified device, path or file. You may not have the appropriate permission to access the item."

    thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    TeaTimer is running on the other account so I assume it is also running on yours.

    Can you disable it?

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Can you run ComboFix on your account? (You should be able to move it from the other account desktop to your accounts desktop).

    Let me know if you can.
     
  10. Lanterif

    Lanterif Private E-2

    Hi,

    I disabled teatimer in Spybot.

    I could not run Combofix even after copying and pasting the program from my gf's profile.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try booting into safe mode and running Combo ....also check your account type while there. Can you run SAS and MWB's in safe mode?
     
  12. Lanterif

    Lanterif Private E-2

    Even in safe mode, I obtained the same message for Combo Fix, SAS and MB.
    Altough we used to be both admnistrators, it appears that my gf profile states administrator whereas my profile has just my name now.

    Should I revert my profile back to Adm? If so, can you please confirm how? Is it wise to run two adm profiles on one computer?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot into safe mode ....then go to user accounts in the control panel and change your account type.....and it is ok to run more than one admin account as long as they are password protected.
     
  14. Lanterif

    Lanterif Private E-2

    Hi,

    I just realised that there are actually 3 accounts when insafe mode: Adm, myself and my girlfriend. I cannot access the user account from my account and I received again the same message that I do not have proper authorisation to run this program. I checked under my gf profile for the rights assigned to my profile and both her and I have full administrator powers.

    thanks
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot to the administrator account in safe mode...then check the accounts.
     
  16. Lanterif

    Lanterif Private E-2

    I run in safemode under the admnistrator and both my gf profile and my profile is full administrator
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you move your personal data (files, etc.) to a new folder on your gf's profile, then still in safe mode, delete your account and create a new one.

    Then see if you can run the exe's.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds