Virtumonde help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by noto, Jan 24, 2008.

  1. noto

    noto Private E-2

    I have been reading and trying to get rid of this thing for 3-4 days now and finally decided to get an account and ask for help.
    I have Webroot spy sweeper and it finds but can't remove it.
    I have tried the vundofix and it says it can't delete ddcc.dll I think it was or ddccy.dll

    When I close down IE windows it closes my explorer windows as well and sometimes chashes windows. I can sometimes get it back by running explorer from the start menu but most the times it doesn't have a start menu or CTRL-ALT-DELETE or anything.

    I have read the readme thing but I'm sure a HJT log is going to be asked for so I'm gong to attach it.

    Thanks in advance for any help as this has been driving me crazy.
     

    Attached Files:

  2. noto

    noto Private E-2

    Computer is running so slow now and ads are poping up, can't get anything done.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Is your copy of Spy Sweeper a paid version or a free trial?


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    Make sure you don't miss the uninstalling of Viewpoint Manager in step 1.

    Question: Why don't you have an antivirus installed?
     
  4. noto

    noto Private E-2

    Its the paid version.

    I thought spy sweeper was a virus scanner? :eek:

    I read the readme and tried everything that looked like it might help already but will again maybe I missed some things tried so many things and read so much about this thing its all a bit confusing at this point.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It depends on what version of it that you purchased. The original Spy Sweeper was just an antispyware program. Did you purchase Spy Sweeper with antivirus? By the way, yours is infected by the Vundo infection that you have.

    We do not consider the READ & RUN ME to be run unless ALL steps are followed and the logs are attached as requested. You need to do this or we cannot help you fix your problem.
     
  6. noto

    noto Private E-2

    I have run all the steps and now my machine is clean... Runs very slow now with all the virus and scanner software monitoring everything...
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No not yet you haven't. Again refer to what I posted in message # 5. And I doubt you are totally clean.
     
  8. noto

    noto Private E-2

    I did the readme part and here is the log
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete each step below in the order written.

    As I suspected you are not clean; however you need to attach the requested log from ComboFix. It is located at C:\combofix.txt

    Also I'm not sure where you downloaded ComboFix.exe to, but it must be on your Desktop otherwise later when we use it, it will not work properly.

    Also do you have the log from AVG Antispyware to attach?

    Your copy of SuperAntiSpyware is infected. Uninstall it now and then delete the below folder if it still exists:
    C:\Program Files\SUPERAntiSpyware

    Also delete the below folder because it is also infected and you don't need ZoneAlarm since you have Sygate installed but your installation of Sygate could be broken.
    C:\TOOLAPP3\ZoneAlarm

    Are you copies of Spy Sweeper and Spy Subtract paid versions or free trials?


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0
    Java 2 Runtime Environment, SE v1.4.2


    Okay now we need to use a new tool.
    • Download and save to RenV.exe to your Desktop (must be on the Desktop)
    • Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\Program Files\ATI Multimedia\main\ATIDtct .EXE
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [Weather] "C:\PROGRA~1\AWS\WEATHE~1\Weather .exe" 1
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Don't forget to attach the log from ComboFix that you got while running the READ ME.

    Make sure you tell me how things are working now!
     
  10. noto

    noto Private E-2

    Ok attaching combofix log now before I do these steps, so I don't forget.
    Also moved combofix.exe to desktop for the next steps.
    Also looked under reports for AVG and see no logs.
    Spysweeper is registered don't know about spy subtract is a trial with 0 days left heh.
    I don't see a way to uninstall C:\Program Files\SUPERAntiSpyware so just deleted it.
     

    Attached Files:

  11. noto

    noto Private E-2

    Ok did everything you said.

    Not sure if its running any better or not.
    I have attached MGlogs.zip, avenger.txt and I have already attached combofix.txt to the previous post.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then uninstall SpySubtract now.

    Also uninstall AV Antispyware since you have Spy Sweeper.


    Part of your ATI software is infected and we need to remove it.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [ATI DeviceDetect] "C:\Program Files\ATI Multimedia\main\ATIDtct.EXE"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"

    After clicking Fix, exit HJT.


    Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    Code:
    Files to delete:
    C:\Program Files\ATI Multimedia\main\ATIDtct .EXE
    
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  13. noto

    noto Private E-2

    Ok done that and here are the new logs :)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  15. noto

    noto Private E-2

    Before I clean up everything I noticed a few problems.
    Sygate was not loading and when I tried to run it manuall it no longer worked couldn't find the path to the exe anymore.
    I reinstalled that.
    Another problem is now I can't login to a couple sites that I could before... It just nolonger works.
    One is https://webadmin.ccbill.com/ it just keeps failing to login but works fine on another computer with the same login info and there is a nother site I can't remember the url right now but its basically the same kind of login page. Not like a .htaccess login.
    Any ideas?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sygate was broken by the Vundo infection you had. It is possible that other software was broken by it too.


    No I have no idea on this one. Perhaps Secure Sockets Layer (SSL) is broken. You may want to post this in the Software Forum. Perhaps there is a configuration/setting that was changed. Also try a different browser (like FireFox) and see if it works.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds