Virtumonde is killing me!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by JR Maston, Sep 2, 2007.

  1. JR Maston

    JR Maston Private E-2

    Ok, I know a lot of people have this problem. The Symantec VirtuMonde fix didn't do anything... it told me it couldn't find Virtumonde. Every time I run SB S&D though, it brings it up. I ran ATF Cleaner already, and I'll attach a HiJack This log. Please help!!!
     
    Last edited by a moderator: Sep 2, 2007
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. JR Maston

    JR Maston Private E-2

    Sorry, man. Ok, I ran through the Malware removal thing. I'm not convinced this is Virtumonde after all... it happens for the most part on my wife's login, and the Virtumonde removal tools I ran found nothing. I'm going to post my log files from the scans... I couldn't get an Activescan log, it kept prompting me to buy the full version. Please look them over and see if anything pops out. Thanks for all your help with this!
     

    Attached Files:

  4. JR Maston

    JR Maston Private E-2

    And here's a couple more. Thanks for your time.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you or your wife do any online business?
    If so, you need to change passwords and (if you use a credit card or give out routing and account numbers) alert your banks.

    Please use add/remove programs to uninstall:
    DrvCareXP v4.2
    Java 2 Runtime Environment, SE v1.4.2_03
    Reboot and install:
    Java Runtime 6

    Now:
    1. Click on the Start button.

    2. Click on the Run option.

    3. In the Open: field type "cmd /k sc delete $sys$aries" (without quotes) and press the OK button.

    4. Reboot your computer

    5. Delete C:\%WinDir%\system32\$sys$filesystem\aries.sys (Replace %WinDir% with the directory that Windows is installed on your computer)

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now after reboot, please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.
    Attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger
     
    Last edited: Sep 3, 2007
  6. JR Maston

    JR Maston Private E-2

    I've done all of that, but I can't seem to post attachments. I'm in advanced mode, so I don't know what's wrong. I'll return to this in an hour and see if it's just a glitch.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure they are new logs and not the same old logs. Also if that is not the problem, dump your browser cache (see below) and then click refresh a couple of times

    1. Run Internet Explorer
    2. Click Tools and select Internet Options
    3. Now on the General tab, click Delete Files and select Delete all Offline content too on the next window, Click OK. When it finishes Click OK.
     
  8. JR Maston

    JR Maston Private E-2

    Ahh, thanks. I think the problem was I was in Firefox. IE seems to handle that better. Here's the logs...
     

    Attached Files:

  9. JR Maston

    JR Maston Private E-2

    And the HJT log, too. Thanks for your help guys!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You had HJT in the right place the first time:
    C:\Program Files\analyze.exe
    Why did you uninstall and then reinstall here (where we specifically tell you not to):
    C:\Documents and Settings\Jeff\Desktop\Anti-Virus Tools\analyze.exe

    Were you able to delete this:
    C:\%WinDir%\system32\$sys$filesystem\aries.sys

    Please Disable Spybot's TeaTimer

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Now:
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Please attach new logs for:
    ShowNew
    GetRun
    HJT
    Avenger

    Tell me how things are running!
     
  11. JR Maston

    JR Maston Private E-2

    Ok, I looked everywhere in C: and couldn't find: "C:\%WinDir%\system32\$sys$filesystem\aries.sys." Is there a chance that this is hanging out in my wife's login and I can't get to it, even with Admin rights? Am I looking in the wrong place?

    Thanks for the help from Tea Timer... I couldn't figure out how to kill the bugger, and kept stopping it manually in Task Manager.

    Other than the %WinDir, I did all the other steps. Oh, and HJT is in C:... but the log I attached was one I had saved into the wrong file. Sorry about that. I have fixed it.

    The computer is running faster than it has in a long time, especially in the browsers. But we keep getting these messages from Norton saying "An attempt to invade your computer by MASTON (and our IP address) has been blocked." This happens two - three times per hour. I've installed a software firewall recommended by MG, and it hasn't changed this. Is this the same problem, or something else?

    Thanks again... this seems to be making real progress. Here's the logs:
     

    Attached Files:

  12. JR Maston

    JR Maston Private E-2

    And the HJT log:
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. JR Maston

    JR Maston Private E-2

    Does Norton have an automatic firewall component? I haven't used any option to turn on a Norton firewall. But if it does have a firewall, I'll go ahead and uninstall the Outpost. Frankly, Norton is a pain in my ***... it sucks up resources like crazy with all of it's Live Update stuff. Is there a way to deactivate Norton's firewall?

    The message we keep getting is "A recent attempt to invade your computer by MASTON (IP address) was blocked. Click for more details." When the message first started showing up was right before we got hit with all that malware. Originally, the message didn't mention the name MASTON... that's a recent development (in the last week or so). I rarely see it on my login, but my wife gets it two or three times an hour.

    We aren't on a network. We have an HP laptop we're running through a wireless DSL connection. That's why the MASTON warning is so confusing. Our wireless connection is password protected, too.

    Thanks for everything you've done, man. It's making a HUGE functional difference.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is not a lot of support around here for Norton ...for all the reasons you give. But to have it pop up saying what you post, would suggest a firewall notice. And yes, it very well could just be your laptop is trying to access your computer thru the wireless network.
    Turn it off and see what happens.....if you were actually being "probed" then Outpost would report it.

    Did you run any of the scans from her login?

    I'd keep Outpost and dump Norton ...too many just as effective freeware anti-virus software that doesn't hog down your computer.

    Are you telling me that the laptop is the only computer you have?
     
  16. JR Maston

    JR Maston Private E-2

    Yeah, I have just the laptop. The Norton log looks weird... there's a section that says that our ISP has gone invisible, or something, and is not being covered by Norton.

    What freeware AV would you suggest using?

    I didn't run any of the scans from her login. Should I go and do a HJT report from there? Before coming to MG, I did a sweep and found a bunch of crap in her temporary internet files.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We have a Norton uninstall program on MG;s and you will find either AVG freeware or Avast on our top freeware picks section.

    As to your wife's login ...it would be a very good idea to run the following on her account just to be certain:
    ShowNew
    GetRun
    HJT

    Also run the ATF cleaner on her login.:)
     
  18. JR Maston

    JR Maston Private E-2

    OK, I ran the ATF cleaner on my wife's login again. Then I ran those three reports, and I've attached the log files. Thanks again for your help!
     

    Attached Files:

  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Her logs are clean also. If you are still having problems with Norton ....you may wish to uninstall, try a different anti-virus program and if that solves your problem .....
    If not, let me know.:)
     
  20. JR Maston

    JR Maston Private E-2

    Thanks for all your help. Everything is running wicked fast, and we haven't received any more "invasion" attempt warnings. You freaking rock Tim!
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome .....safe surfing!! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds