Can't Completely Remove Virtumonde (Continued with logs)

Discussion in 'Malware Help (A Specialist Will Reply)' started by smit6577, Apr 26, 2008.

  1. smit6577

    smit6577 Private E-2

    Hi, I am currently using Webroot Spy Sweeper and I have ran various full scans, quarantined, and "deleted" virtumonde but it keep showing up every time I scan. Can anyone help?

    Thanks in advance
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. smit6577

    smit6577 Private E-2

    Re: Can't Completely Remove Virtumonde (With Attachments)

    Ok I read/and went through all of the steps mentioned in
    READ & RUN ME FIRST. Malware Removal Guide.. Vundo didn't work and I have a question for the "Procedures based on your Windows Operating System section": do I really have to download and run those 5 programs? I only ask because I don't see why I should have to use those programs/logs when I'm paying for better rated spyware/virus related programs (symantec antivirus and webroot spysweeper). If you do require me to use those programs before you'll help me out I'd prefer to backup anything that's important and just re-image my computer, so if you could let me know what my options are it would be very helpful.

    Thanks again
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With Attachments)

    If you want our help to fix what those programs you have paid a lot of money for cannot do, then please follow our instructions. Otherwise you are welcome to call Symantec and Webroot and pay some more money to get technical support that will still not fix your problems.

    Our methods are used hundreds of times per week and they work. Symantec and Webroot will not remove this infection and normally they miss most of the files and registry keys associated with the malware which is why they cannot remove the problems.
     
  5. smit6577

    smit6577 Private E-2

    Re: Can't Completely Remove Virtumonde (With Attachments)

    Alright I'll go through the cleaning procedures with those programs when I get a chance sometime this week and post whatever I'm supposed to post, if anything.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With Attachments)

    The cleaning procedure for Windows XP will give you a list of logs to attach at the end if you are still having problems.
     
  7. smit6577

    smit6577 Private E-2

    Re: Can't Completely Remove Virtumonde (With Attachments)

    Alright so I'm not able to download MGTools.exe to my C:// right now. I click on your link and get the message "would you like to save this file?" and the only option I have is to click "save file" but there's no "save file to option". So when I click save file it automatically gets saved to my desktop. Is there anything I can do?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With Attachments)

    What browser are you using? Sounds like FireFox and that you never set the option to tell it to allow you to choose where to download which is what you should set. Downloading to the Desktop by default allows you to find them easily which may be good for people who don't know there way around Windows but it leads to cluttered Desktops. Cluttered Desktops slows PCs down and provides a great hiding place for malware.

    If FireFox is what you are using, Click Tools, Options, and on the Main tab select Always ask me where to save files. If for some reason you still have a problem trying to save MGtools.exe properly. You can download it to your Desktop and move it after downloading, or if necessary (but we prefer not) run it from your Desktop.
     
  9. smit6577

    smit6577 Private E-2

    Re: Can't Completely Remove Virtumonde (With Attachments)

    I am using firefox so that worked.. I went through all of the procedures and it seems all spyware etc. is gone. Nothing showed up on my spysweeper scan (if that's even reliable?) but I have a few questions. For each program I ran I restarted my computer after the scan (as you know for some of these this is required) so I was wondering if this might create a problem because my system restore was not disabled prior to restarting my computer after any of those scans. My other question is should I post those four logs?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With Attachments)

    Not a problem since my final instructions (when we get to them will take care of this.

    Yes because more than likely, you still have components of the infection that need to be removed.
     
  11. smit6577

    smit6577 Private E-2

    Re: Can't Completely Remove Virtumonde (With Attachments)

    Here's the first of the four:
     

    Attached Files:

  12. smit6577

    smit6577 Private E-2

    Here are my other 3 attachments
     

    Attached Files:

    Last edited by a moderator: Apr 29, 2008
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How do you like how our tools found and remove things that your "better rated spyware/virus related programs" did not find and remove? ;) Your Spy Sweeper scan is still incorrect since there is a little more to do. I recommend that you shutdown Spy Sweeper before doing the below to avoid having Spy Sweeper actually get in the way of proper malware removal.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {A2B8EA46-6C2C-4069-A613-1DC165E18DF8} - C:\WINDOWS\system32\tuvVLbYo.dll (file missing)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [6c4087b0] "rundll32.exe" "C:\WINDOWS\system32\pufwoxcr.dll",b
    O20 - Winlogon Notify: nnnmlJBq - nnnmlJBq.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 29, 2008
  14. smit6577

    smit6577 Private E-2

    All I can really say to that is I'm glad Symantec/Webroot is provided by my college and the cost is covered (discounted) in my tuition it's too bad they don't really work. I'll definitely recommend this site to anyone I know who has similar problems... Anyway, it will be a day or two before I have time to go through the procedures you posted, if that might cause more problems to not get that done right away let me know and I'll find time to take care of it sooner.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be in your best interest to complete them ASAP. These infections will respawn and spread (often changing names/creating new files) if not completely removed. And at each power down or power up you risk the chance of it reinfecting you.
     
  16. smit6577

    smit6577 Private E-2

    Can't Completely Remove Virtumonde (With more new logs)

    Things seem to be going smoothly so far, here my newest logs.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With more new logs)

    Why did you start a new thread? I'll merge this back to your first thread.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With more new logs)

    Your logs were from safe boot mode and they need to be from normal boot mode. Let's fix the below and get a new log.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://gomyhit.com/MTg2MzY=/2/288//
    O20 - Winlogon Notify: nnnmlJBq - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now make sure that you reboot into normal boot mode and then get the below new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. smit6577

    smit6577 Private E-2

    Re: Can't Completely Remove Virtumonde (With more new logs)

    I thought I had to start a new thread for every 3 attachments, but I looked back at the how to post attachments site and I'm not sure where I got that idea, so I won't do that again.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Can't Completely Remove Virtumonde (With more new logs)

    You can only put 3 attachments into a single message, not a thread. ;)
     
  21. smit6577

    smit6577 Private E-2

    Alright this should be the right one.. One thing that's happening that's unusual is every time I reboot windows security center shows up with the warning that my anti virus has been disabled, and eventually it enables again on its own.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    Try the below.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    After doing the above, reboot and see if there is any change. If not, it may be necessary to reinstall Symantec. The infection you had may have damage it.
     
  23. smit6577

    smit6577 Private E-2

    I got the success message and restarted my computer and the same thing happened.

    Something else that seems unusual is Spysweeper's system service shield pops up with "shield detected a change to service configeration for the following would you like to allow/block" for SYMREDRV, NAVENG, SAVRT, NAVEX15, and I basically get this message every time I power down/power up my computer and randomly while using it. I don't know if it's anything to worry about.

    The only other problem I have is SAS takes up a lot of CPU usage at start up even though I disabled automatic updates in preferences: scanning control and updates.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But what are you answering with?



    You can uninstall SUPERAntispyware now since we are finished with it but not there is also an option to tell it not to load with Windows. ;)
     
  25. smit6577

    smit6577 Private E-2

    I answer with allow because if I blocked it I would just keep getting the same pop-ups and it's the recommended action to allow it. Is it normal for those configerations to change frequently?
     
  26. smit6577

    smit6577 Private E-2

    ..I'm missing something here how do you get SAS to not load with windows?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not normal! So either Symantec is having a problem local to itself or there is a conflict between it and Spy Sweeper in getting things setup properly.

    Click the Preferences button and on the General and Startup tab uncheck the option that says Start SUPERAntiSpyware when Windows Starts.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds