Virtumonde Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by sammyg10, May 4, 2008.

  1. sammyg10

    sammyg10 Private E-2

    hey guys - I went through all the recommended scans and removed a bunch of files related to Vundo/Virtumonde. I was wondering if somebody could take a look as to if it has been fully removed. Specifically, I have been getting insane amounts of popups (in differed IE windows) with dialogue boxes etc. IE also refuses to open a few sites. I ran vundofix.exe and it detected a couple of files but they kept reappearing in the c:\windows\system32 folder.

    Thanks
     

    Attached Files:

  2. sammyg10

    sammyg10 Private E-2

    Here is the MGlogs.zip file
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software per the READ ME step 1:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {9f6808dc-a77c-6179-ce34-1fb8de858e2c} - {c2e858ed-8bf1-43ec-9716-c77acd8086f9} - C:\WINDOWS\system32\youovcye.dll (file missing)
    O4 - HKLM\..\Run: [c8994542] rundll32.exe "C:\WINDOWS\system32\uwqfhtig.dll",b
    O20 - Winlogon Notify: tuvSlIxx - tuvSlIxx.dll (file missing)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. sammyg10

    sammyg10 Private E-2

    Thanks for your reply. Everything seems to be working perfect. In fact, since the last time I ran the scans, (before the first post), I haven't had any popups.

    I was NOT able to find O4 - HKLM\...\Run: [c899.... file, but deleted the other two.

    The Registry merge was successful.

    Here are the remaining logs that you asked for.


    Big time props to you guys for helping me out. If you guys take donations, would love to contribute.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC is not clean! Because you violated the guidelines given in step 1 of the READ ME and started using MSconfig again (probably right after posting your first logs) the cleaning procedure did not work. You must stop using MSconfig as requested and do not use it anymore (see step 1 of the READ ME). Then you need to attach an new MGlogs.zip file.
     
  6. sammyg10

    sammyg10 Private E-2

    Uh oh. Apologies on the change.

    I went through it again. Here are the latest logs.

    P.S. Having so many programs launch on start-up does take forever. Is there anything else that you can suggest instead of using MSConfig? Thanks
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See step 1 of the READ ME again! ;) However do not take any steps yet until we finish all of our malware cleaning. I'm looking at your logs while you read step 1 again (specifically where it mentions not using MSconfig). :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It appears that you did not Remove Windows Messenger as rquested in my previous instructions. Run that tool again and make sure you use remove not disable.

    You have a load of processes and 5 services running from Roxio. Do you use this software? If so, what features do you use? It is wasting a lot of resource loading those services all the time. If you don't use it, uninstall it.

    Do you really use both Yahoo Messenger and AIM6? If not, uninstall them.

    Uninstall SUPERAntiSpyware now since we are finished with it.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. sammyg10

    sammyg10 Private E-2

    To the best of my knowledge, I did remember removing Windows Messenger. I think that may be the reason why HijackThis does not have the O4 line dealing with msmsgs.exe.

    I uninstalled Roxio and SUPERAnti-spyware. I do use Yahoo and AIM, so keeping them for now. However after uninstalling Roxio, the computer booted up much faster than it has in a while.

    I deleted all the lines you asked me to in HijackThis except

    O4 - HKLM\...\Run: [MSMSGS] only because I couldnt find it.

    I've attached the latest MGlogs.zip.

    Not a single pop-up since the time I posted the first logs. I think I might be there.

    What do you think?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was why I pointed them out. Just be sure that whatever you uninstalled you don't need. I believe all of this is related to DVD/CD burning and more.

    I need to see the followup MGlogs.zip file to see where things stand.
     
  11. sammyg10

    sammyg10 Private E-2

    Here's the latest log
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds