virtumonde/other problem? Logs attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Peewiglet, Nov 25, 2012.

  1. Peewiglet

    Peewiglet Private E-2

    Hi there, and thanks for any help.

    For a month or so my WinXP desktop has been getting slower, and having problems finding its internet connection (wireless) on re-boot. I didn't pay much attention at first because I normally use a different computer, but several days ago I re-booted and it came up showing just wallpaper with no icons. I Googled the problem, and got the icons back by doing a system restore. However, I realised that it was time for me to check for malware and so I came over here and worked through the 'How to Protect Yourself' thread.

    As part of that I installed and ran Malwarebytes and then Spybot Search & Destroy. The Spybot scan took ages, and I kept seeing references at the bottom of the box to virtumonde. I'd never heard of it before, but a Google suggested that it's a hard-to-clean trojan of some sort.

    I therefore worked through the 'Special Removal Procedures' thread, and generated various logs in accordance with instructions. I've re-booted several times, but the desktop is still coming up with icons very slowly i.e. almost a minute before the icons appear on the wallpaper. I'm sure that there are lots of legit things that are slowing my PC down (I'm sure it's time for a tidy up) but this problem i.e. icons not appearing/appearing very slowly is a new one, and I'm concerned that there's some sort of malware causing the problem.

    I noticed when running one of the scans that somehow the Ask toolbar had been installed, and since that's not something I wanted I went into Add/Remove and removed it. I hoped that might have been what was causing the problem, but re-booting was no better without it.

    I've attached various logs, and would be very grateful for any help you can offer. I do try to keep my PC clean, but I've fallen behind re: non-virus malware :(
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][SUSP PATH] HKCU\[...]\Run : SansaDispatch (C:\Documents and Settings\Shirl\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-3433576813-3147535169-4187042689-1006[...]\Run : SansaDispatch (C:\Documents and Settings\Shirl\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    Now run HitmanPro and remove all that it finds.

    Then re-scan with both RogueKiller and Hitman and attach those logs as well. Tell me what issues you have.
     
  3. Peewiglet

    Peewiglet Private E-2

    Hi, and many thanks for helping.

    I ran RogueKiller.exe as you instructed. It seemed to produce two logs ([2] and [3]) and I've attached both of them, just in case. Also, even though I definitely checked both of the detections you identified above it looked to me after running Delete that only one of them had been deleted. That may just be because I don't know how to interpret the log, though.

    I ran HitmanPro. It found one entry and I removed it. The two further RogueKiller and HitmanPro logs you asked for are also attached.
     

    Attached Files:

  4. Peewiglet

    Peewiglet Private E-2

    I forgot to say that on re-booting I'm still getting a blank desktop (i.e. just wallpaper) for almost a minute before the icons suddenly appear, all together. After that items load one at a time in the Systray. If this (i.e. slow loading) is because of some sort of housekeeping issue then I'm a bit confused, because I didn't have the problem at all until a week or so ago, after the occasion upon which I had only wallpaper and no icons would load no matter how long I left the computer.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. You need to pursue this issue in the software forum.

    You also should not have uTorrent running at start up.

    I suggest you go into msconfig and in the startup tab, disable it all. Then re-inable one at a time until you find what is slowing it down.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  6. Peewiglet

    Peewiglet Private E-2

    Thank you very much indeed for your help. I really appreciate you and your colleagues giving up your free time to help out on here.

    I've tried what you suggested re: msconfig, but although I disabled everything on re-booting I had exactly the same experience. I've tweaked uTorrent not to run on startup too. I'll go over to the software section as you suggested.

    Many thanks again.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome. I hope they can fix you up. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds