Vundo and Virtumonde problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by preciuoscat, Feb 29, 2008.

  1. preciuoscat

    preciuoscat Private E-2

    Hi. I have tried many times to get rid of Vundo and Virtumonde files from my machine with no success. I have used Vundofix, Vundobegone, Spybot and Adaware. I have installed Hijack This and have attached a copy of the log. Could you please look at this and advise what I can do to fix these problems.
     

    Attached Files:

  2. Cat_w_9_lives

    Cat_w_9_lives Major KittyCat

    Hello and Welcome to Majorgeeks, please do the READ & RUN ME
    FIRST here:
    http://forums.majorgeeks.com/showthread.php?t=35407

    The above link will give you directions on how to clean your PC of malware, if you still need help after following procedures you can post the requested logs in the Malware Forum as attachments and they will help you.

    Sorry if it was easy to get rid of there would not be a Malware Forum, they do not read logs unless you follow procedures. The procedures work if you follow them :), they're experts.
     
  3. preciuoscat

    preciuoscat Private E-2

    Thanx heaps for the help. I don't know if everything is OK yet but it seems to have done the job. If I have any further problems, then I will post a new thread.;) I have attached logs just in case.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Sorry for the delay. You post was overlooked due to being in the wrong forum at first.

    You have some more work to do.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {01EB8A6B-CFDC-452E-BC3B-8AB1EB913265} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {04DEB418-433F-43A9-B9B9-3535439129D5} - (no file)
    O2 - BHO: (no name) - {05BCD702-B9D1-498B-B6C9-B67EB55576D5} - (no file)
    O2 - BHO: (no name) - {16ad1997-9c77-49a3-a741-2a3207105748} - (no file)
    O2 - BHO: (no name) - {31F0250F-8D94-42AA-A131-E6E85E96798E} - (no file)
    O2 - BHO: (no name) - {3D09DB87-B08D-4539-8E05-64FC8CA0247B} - (no file)
    O2 - BHO: (no name) - {6E9A6DFF-085A-4506-8DD3-5786D9B27A46} - (no file)
    O2 - BHO: (no name) - {7EB4899F-FDC2-4060-ADAC-74534E08F17E} - (no file)
    O2 - BHO: (no name) - {8206852a-bd4b-4f24-b012-363efa6b0bfd} - (no file)
    O2 - BHO: (no name) - {85ab9b53-39c4-4a40-9fb7-d895f51d0a02} - (no file)
    O2 - BHO: (no name) - {9654C2F9-7A1B-4F2D-988E-BDC7E897B22C} - (no file)
    O2 - BHO: (no name) - {9BDF9FDE-F762-4C5A-814E-10DA58D674F5} - (no file)
    O2 - BHO: (no name) - {B1389238-28B9-4BBD-9C47-22B935C3F8BE} - (no file)
    O2 - BHO: (no name) - {b5d9234d-9587-4362-93ea-f1bed2fa7cb5} - (no file)
    O2 - BHO: (no name) - {C01FDFD1-F9DD-47B4-B390-CD6EE06E76D9} - (no file)
    O2 - BHO: (no name) - {CB7C2D93-FC1A-43D4-8396-D79EF197A26A} - (no file)
    O2 - BHO: (no name) - {D173BEFE-CFC5-413A-B851-9A96334D166B} - (no file)
    O2 - BHO: {1cb30328-c69e-3369-f454-5b52ddbd859d} - {d958dbdd-25b5-454f-9633-e96c82303bc1} - C:\WINDOWS\system32\gxioindw.dll (file missing)
    O2 - BHO: (no name) - {E55B8BEE-1CC0-491C-BF9F-75636D431B24} - (no file)
    O2 - BHO: (no name) - {EFEE3514-D098-4445-8992-AD91322EB76D} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. preciuoscat

    preciuoscat Private E-2

    Thanx so much for getting back to me. I thought things were OK until I did these things that you said, now they are even better. My machines seems to be much quicker and I'm not getting the pop-ups in internet explorer.

    The logs are attached.

    Thanx again.;)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ComboFix did not work properly for some reason. Let's try to fix things another way. Note: You did not install the version of Sun Java I asked you to install. You need to use the links given in the procedure. You installed a very old version that is susceptible to Vundo infections.


    Uninstall the below old versions of software:
    Ask Toolbar
    J2SE Runtime Environment 5.0 Update 6


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. preciuoscat

    preciuoscat Private E-2

    As far as I could tell, things were good before but I have done these things and the logs are attached.
    Thanx heaps:wave
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    It only looked that way on the surface. ;) Now your logs are really clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     
  9. preciuoscat

    preciuoscat Private E-2

    Thanx so much for all your help, hopefully, I won't need it again.:wave
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds