VIRTUMONDE. I completed Try Me 1st and still no luck. Please help. Logs attached.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by loopyb, Dec 9, 2008.

  1. loopyb

    loopyb Private E-2

    I apologize for not thoroughly reading the forum. I was just so frustrated with this that I was not thinking straight. I performed all of the required tasks in the Try Me First, and I am still having issues. I keep getting unwanted pop ups even after all I have done up to this point. Please see attached for logs and thank you in advance for the help. Please let me know if there is anything else that you may require
     

    Attached Files:

  2. loopyb

    loopyb Private E-2

    Final Log Results
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, let's start with this:

    Please disable all anti-virus and anti-spyware programs while we do the following ( be sure to re-enable when we are finished):


    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\WINDOWS\pgxgxkn.exe
    C:\WINDOWS\System32\asycfilt.exe

    Reboot and make sure those files are gone.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. loopyb

    loopyb Private E-2

    Thank you so much for your help. Hopefully this does the trick. I noticed my Windows Update is now functioning again and I freed up about 1.5 GB of space on my hard drive after finishing the Try Me First. Unbelievable! Please see attached for new log files. Thanks again
     

    Attached Files:

  5. loopyb

    loopyb Private E-2

    I also ran Spy Bot again and Virtumonde was still in there. I have attached the logs for that as well.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem....

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Your logs are clean.

    If you are not having any other malware issues, then:

    **CAUTION: Using P2P programs and torrent downloads can be dangerous, as they by-pass your firewall and may contain malware.
     
  7. loopyb

    loopyb Private E-2

    Hello,

    So I ran SpyBot once again and the same Virtumonde is still there. I do not have note pad for some reason so I had to use wordpad. I was able to still follow your instructions and I merged it with the registry. I am not sure if this is the reason why it is still there but I figured I would let you know just in case. Everything else seems to be fine. Much faster and no more unwanted pop ups but I just can't seem to get rid of this particular Virtumonde and it is in the same place each time. Any help would be appreciated and I can't tell you how much you have helped up until this point. I have attached the results. Thanks again for your time and patience.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you still have combofix on your desktop:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    Registry::
    [-HKEY_CLASSES_ROOT\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now reboot and attach the log from combo.
     
  9. loopyb

    loopyb Private E-2

    I followed the instructions in your previous post. It still seems to be appearing there. I do not have NotePad so I had to use WordPad. Is this an issue? Should I download Notepad and then retry? Thanks in advance for your help. Please see attached for logs.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK...now I must ask, why do you not have notepad? You can download it HERE.

    Download and Install Registrar Lite.

    Now run Registrar Lite.

    Run Registrar Lite navigate to the following keys and take ownership of them (explained further

    HKEY_CLASSES_ROOT\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}

    To take ownership of the key do the following:

    * Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the regitry key.
    * Click-on Security in the Menu
    * Select Take Ownership
    * Now right click on the registry key and select delete
    * Tell me the results. Any errors?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not Windows Notepad. This is a third party replacement. Notepad.exe is already available of this PC as seen in the newfiles.txt log which shows the below:
    Code:
    "C:\WINDOWS\"
    notepad.exe   Apr 13 2008       69120  "notepad.exe"
     
  12. loopyb

    loopyb Private E-2

    WOHOO. I think that did it. I ran Spybot and Malwarebytes which have picked it up before and it did not appear. Looks like we zapped it. Thank you for all of your help. I really appreciate it. To answer your question about notepad, for some reason I could not access it from Programs/Accessories/Notepad. I ran it using the command prompt and it worked fine. This is the message I receive when I try to access it through Programs/Acc. etc:

    The drive or network connection that the shortcut 'Notepad.lnk' refers to is unavailable. Make sure the disk is inserted properly or the network resource is available. Not sure what that means but I think thats the reason. Thanks again and take care.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome.....you can pursue the notepad issue in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  14. loopyb

    loopyb Private E-2

    Thanks again for all of your help. I will follow the recommendations in the previous post. Enjoy the holidays and take care.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You too....and safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds