You guys rock

Discussion in 'Malware Help (A Specialist Will Reply)' started by DeeViper, Aug 28, 2007.

  1. DeeViper

    DeeViper Private E-2

    Much :heart for you guys. I followed all the steps in the "read me" and then went to the specialized section as directed for virtumonde and this nasty pop-up infested machine is C L E A N !!!

    MajorGeeks + me = :boxing Dirty Machines!

    Thanks guys!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you have run the full READ & RUN ME, I would suggest that you attach the logs from GetRunKey and ShowNew. Do this even if you think you are clean. Virtumonde can hide many files on your PC and the normal procedues (even with VundoFix) will not remove all of them.

    In fact it would be even a better idea to attach all 6 logs from the READ & RUN ME. To be specific, that list of logs is:
    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  3. DeeViper

    DeeViper Private E-2

    Alrighty. I'll do that tomorrow when I get into the office. I kept running the logs in BD until they were clean, using KB to remove files BD couldn't. I kept running HJT until nothing "odd" was showing up, looking at other posts with the same issues for similar entries to remove. Same with SpyBot, got stuck on Virtumonde but got that fixed with the fixer located on the special clean up page. Ran SB after that and cleared out the remaining files. The panda log may have found some stuff that I couldn't resolve w/o buying it... I forgot now though.

    So sure, I'll post up the logs tomorrow. Better safe than sorry. :cool
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If HJT is not renamed as requested, many Vundo related entries will not even show up so be sure you renamed it.
     
  5. DeeViper

    DeeViper Private E-2

    The Vundo removal thread did not say to rename HTJ. However, I did do that today and I don't think I found anything odd. Anyhow, attached are the logs for your perusal. Enjoy. :)
     

    Attached Files:

  6. DeeViper

    DeeViper Private E-2

    More. I will post the CounterSpy log once it is done with the scan.
     

    Attached Files:

  7. DeeViper

    DeeViper Private E-2

    CounterSpy log attached.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Because that link does not even mention HJT since it is not used in that procedure. The READ & RUN ME does tell you to rename it and so does the HJT Tutorial. ;)

    I'm looking at your logs now.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below supposed to be HijackThis?


    C:\Documents and Settings\KaThErInE TsOuGaRaKi\Desktop\fred123.exe

    This is located exactly where we specify not to install it and in addition. It will be treated by most scanners and also by people reading logs as malware. Please install it and rename it as suggested to avoid these problems and also other problems that can occur due to where you installed it. It should look like this:

    C:\Program Files\HijackThis\analyse.exe
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like you did not really have a real Vundo infection. What Spybot detected does not appear to be truly Virtumonde. You do have a couple other problems though.

    Please attach the C:\VundoFix.txt file I want to see what is in it.

    You can uninstall the CounterSpy trial now since we are finished with it.

    Delete the below files (use safe boot mode if you cannot delete in normal mode):
    C:\WINDOWS\system32\ierplc.dll
    C:\WINDOWS\system32\qmopt.dll
    C:\WINDOWS\system32\"B.tmp


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    You can also have HijackThis fix the below non-malware items. They are just unnecessary startups that waste system resources.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    After clicking Fix, exit HJT.

    Now attach a new logs from ShowNew and GetRunKey.
     
  11. DeeViper

    DeeViper Private E-2

    Ok, I fixed that.
     
  12. DeeViper

    DeeViper Private E-2

    Alright, will do all of that shortly and will report back.
     
  13. DeeViper

    DeeViper Private E-2

    Here's the Vundo file.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that shows that you did have Vundo but only a minor form of it. You need to complete my other instructions in message # 10.
     
  15. DeeViper

    DeeViper Private E-2

    Done. Logs attached.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  17. DeeViper

    DeeViper Private E-2

    Most excellent. I hope this was an easy case for you. ;) Thanks for the added help.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it was an easy one. ;)

    You're welcome. Surf safely.
     
  19. DeeViper

    DeeViper Private E-2

    Thanks again. Don't worry about me, I'm a computer nerd :cool that knows the perils of unsafe surfing. It's my manager's kids and her niece we have to be worried about! Kids click "yes" to the darnedest things...

    "Would you like to install a virus and make your computer a pop-up hell?"

    >>Yes<<


    Oh well, I'm still employed and now my boss owes me one! Not to mention, I've already fixed her other kids' computers a few times already and now I've got another one on deck. I might post some logs from that one if I run into anything weird.

    Cheers! :wave
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you have any other PCs to work on, start new threads for them and be sure to put into your message that it is another PC so it is not assumed to be the one in this thread.
     
  21. DeeViper

    DeeViper Private E-2

    Will do! :highfive
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds