Please help. Virumondo keeps coming back!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nanziman, Nov 6, 2005.

  1. nanziman

    nanziman Private E-2

    Hi, I have completed steps 1 thru 6 of READ & RUN ME FIRST several times, but no luck so far. Virtumondo keeps coming back.

    1) In normal mode, only MS Antispyware caught it.
    2) Switched to safe mode with networking support:
    - Ad Aware caught it and confirmed deletion.
    - MS Antispyware caught it again and confirmed deletion.
    3) Rebooted again to normal mode and Virtumondo is back.
    4) Repeated 1 - 6 in safe mode again, but Virtumondo is back again.

    This awvvt.dll file keeps coming up as a malware by MS Antispyware, but I'm afraid to delete it manually without some expert guidance.

    Can you please help? I have only been able to retrieve the MS Antispyware log, which is listed first below and followed by the HJT log.

    Thanks in advance for your help!!!

    • Edit by bjgarrick: Unrequested, Inline HJT & MSAS log removed!
     
    Last edited by a moderator: Nov 6, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download this trial version of Ewido Security Suite

    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:


    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report


    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report along with a fresh HJT log.
     
  3. nanziman

    nanziman Private E-2

    Many thanks for getting back on this. Ran (twice) Ewido per your instructions, but it could not eliminate Virtumondo. Below are the two log files that you requested.


    • Edit by bjgarrick: Inline HJT log removed!
     
    Last edited by a moderator: Nov 7, 2005
  4. nanziman

    nanziman Private E-2

    Sorry forgot to mention:
    * Ran Ewido scanner in normal mode first.
    * Then ran Ewido scanner in safe mode w/networking support (twice).

    Cannot run in plain safe mode!
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    From now on please attach ALL logs as attachments to your post.


    Please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     
  6. nanziman

    nanziman Private E-2

    Hi.

    Spysweeper seems to have removed this nasty bug, judging from the attached log files. Since I'm not an expert, can you verify this?

    To spare resources I would like to keep running Norton Anti-virus and Spysweeper, and uninstall the other programs. Any suggestions?

    MANY... MANY... THANKS!!!!
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That's fine, I will give you a list of programs for protection after we get your system clean.

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  8. nanziman

    nanziman Private E-2

    Hi and thanks for your continued help!!!

    Ran all steps per your last instructions from Safe Mode, rebooted to Normal Mode, ran HJT and saved the attached HJT log.

    I look forward to your protection software recommendations.

    Many thanks again!
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds