VirtueMond & Win32.banker problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jikamm, Mar 5, 2009.

  1. Jikamm

    Jikamm Private E-2

    Hey, I posted about this yesterday but my topic seems to have disapeared into a black hole, probably caused by the hadron collider, but anyway...

    explorer.exe was detected by AVG to have packed upack, so I uploaded it to virustotal and esafe said it had Win32.Banker, so I cleaned that up by removing explorer.exe and "sfc /scanall" with my Win XP CD to replace it, then I started scanning with the tutorial provided and found out I had "Virtuemond" virus in like 4 system files, I had to go into safemode to run the scans with MBAM and it found 6 and quarantined them I replaced again with sfc /scanall (just incase they were system files), I think I've cleaned everything up though! Can you guys check my logs to make sure everythings fine, I'd really appreciate it!

    (I just reinstalled my OS yesterday)

    I think I got all the logs you wanted.

    All these scans were done after cleaning everything up, they're from diagnostic startup into windows (not safemode)
     

    Attached Files:

  2. Jikamm

    Jikamm Private E-2

    Here's the MGlog and Combofix
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you reinstalled your OS, what are you doing wanting us to check your logs?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  4. Jikamm

    Jikamm Private E-2

    Err, sorry I worded that confusingly, I meant I had reinstalled the OS just a couple of days ago, then I got the virus (convenient timing, right?)
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well....your logs are clean, so I imagine MBAM removed any infection. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds