Help Greatly Appreciated for Malware Removal!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by PL_Bucs, Dec 11, 2008.

  1. PL_Bucs

    PL_Bucs Private E-2

    Hi guys

    It seems that my PC's been infected with a strand of the Virtumonde Trojan. As per usual, it made a lot of pop ups and when I booted my computer there would be a picture of a green field in the sunshine under a blue sky just before my desktop loaded.

    Well, to try and get rid of it, I've run scans on Spyware Doctor (full version), Spybot Search and Destroy, both of which claim to have removed some parts of the infection, and I've also tried to kill it using Vundofix and Registry Mechanic. I've also used Malwarebytes Anti-Malware programme and all of them appear to have done some kind of job, except for Vundofix which said that it found nothing.

    Basically, the pop ups don't appear any more, and 2 of the 3 processes which began to run upon startup have been removed I think. Also, the CPU doesn't seem to be as burdened as before. So some progress has been made. However, when I boot up my computer the picture of the nice landscape still appears before the desktop and is followed by an error message saying that one of the processes which the Trojan added can't run any more, which leads me to my next point:

    What still remains are 3 bastards in the Registry. When I try to manually delete them through regedit, but they just reappear.

    I read the Read Me post and followed it step by step, after which I tried to use all of my anti-malware/spyware arsenal above.

    I created a log file using hijackthis and also one using MBAM, both of which are attached below. The 3 'bastards' which I refer to above all begin with 04 - HKLM and contain the word "zofarimo" or "beponekume" (referring to HJT log, haven't read the MBAM one really)

    On a side note, I coincidentally tried to run Windows Update just because I felt I needed to after, and I wasn't able to because something had changed the entries in the 'services.msc' file ie. Autoupdate was set to "disabled" when, before I got this trojan the other day, Autoupdate would run regularly, once every other day or so. Does this have anything to do with the Virtumonde issue?

    If one of you computer wizards could find the time to help a relative noob like me I'd be most grateful.

    Thank you,
    Patrik.
     

    Attached Files:

  2. PL_Bucs

    PL_Bucs Private E-2

    "Error Loading C:\Windows\system32\zofarimo.dll Specified module couldn't be found"

    That's the error message that appears upon startup.
     
  3. PL_Bucs

    PL_Bucs Private E-2

    I've also discarded all out-of-date versions of Java through Add/Remove Progs.
     
  4. PL_Bucs

    PL_Bucs Private E-2

    Sorry I don't mean to be a pest but it looked like my thread got lost amid some older ones.

    I really appreciate what you guys are doing here and I would be ever so grateful for any assistance.
     
  5. PL_Bucs

    PL_Bucs Private E-2

    First, I hadn't read your policy on bumping so for that I apologize. I kinda freaked out initially because of the malware infection so yeah sorry for being impatient.

    However, I did what you guys said in the readme more thoroughly using all the programmes suggested (Combofix, MGTools) etc and it seems as if the sh*t may have gone. Through regedit I checked that all the bad "zofarimo" entries had gone, the pop ups have now ceased and when i boot the computer that sunny landscape picture doesn't appear before the desktop boots up. Bear in mind though that im writing this only after booting the pc once after using all the programmes so I suppose I can't be too sure.

    Anyhow, here are the log files that were created:
     

    Attached Files:

  6. PL_Bucs

    PL_Bucs Private E-2

    The last 2:
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In the future, I recommend that you not bump by posting additional messages. It took many days longer to get an answer because you kept posting.

    Also please only attach the logs we request. We do not want or need you to run Hijackthis on your own nor do we need logs from it. It is already embedded into our tools and logs.

    Do you still have any software installed from Symantec that you use? If not then run the below Norton Removal procedure.
    What is the below file for?
    Code:
    "C:\WINDOWS\"
    l2jsup~1      22 Mar 2008          57  "L2JSUPYDWDWGGM4G3E3E" 
    Also what is the below file for?
    Code:
    c:\windows\system32\Agent.OMZ.Fix.exe

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) 6 Update 10
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    Is the below R1 line something you configured and need? Is it something for Google Desktop? If not then fix it.
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/&s=m2vFakVXtDn6dIbcU6R6iDUaVbM


    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe


    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. PL_Bucs

    PL_Bucs Private E-2

    thanks for the help! Everything seems to be ok now, here are the logs:
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  10. PL_Bucs

    PL_Bucs Private E-2

    Once again, thank you so much for the help. Its great to know that there are guys out there willing to give up their own time free of charge for us when we run into trouble. Keep up the good work! :)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds