How to remove Virtumonde?

Discussion in 'Malware Help (A Specialist Will Reply)' started by sbezzi, Sep 29, 2008.

  1. sbezzi

    sbezzi Private E-2

    I have been hit with Vertumonde and I am having a hard time removing this virus. I read a lot about it but nothing seems to work. Can somebody help?

    Thank you in advance
     
  2. sbezzi

    sbezzi Private E-2

    Can anybody help me? I have ran ad-ware, pctools and a couple more programs but nothing seems to help. I have my infected computer and than I have another one that is clean.

    Thank you
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.




    Once all are attached our malware experts will review them and issue you with some further removal instructions if needed, plus as malware is a growing pest and due to the amount of infected folk it sadly may take a short while to review your logs but dont bump your thread as while it moves you to the first page of the forum, it actually moves you to the bottom of the work queue as fair system is to work from oldest thread to newest.

    We know how much of a pest malware is and you just want it gone, so please be patient and one of our malware experts will be with you asap.
     
  4. sbezzi

    sbezzi Private E-2

    Hi,

    Thank you for the reply. I went ahead and did the step by step precedure that you asked and have attached the logs for you to see. Let me know how I look.

    Note. After putting the computer in normal mode everytime I start up now it launches the Windows installer and it asking me for a CDM CD or something like that.
     

    Attached Files:

  5. sbezzi

    sbezzi Private E-2

    Here is the other log.

    Thank you
     

    Attached Files:

  6. sbezzi

    sbezzi Private E-2

    Any news on the logs?

    Thank you
     
  7. sbezzi

    sbezzi Private E-2

    Hi Halo,

    Were you able to look at my log.

    thank you
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have read ALL of the sticky threads. Example: reading this one Don't Bump! It Only Hurts You!!! could have saved you 2 days of additional waiting time. When you posted your last two messages, the result was 2 more days waiting in the work queue.

    First you need to disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer

    After rebooing from disabling Teatimer, continue with the below.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. sbezzi

    sbezzi Private E-2

    thank you. Here is the logs.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. sbezzi

    sbezzi Private E-2

    Thank you for all the help. You guys have been great. However I do have one small problem.

    Everytime I start my computer the Windows Installer comes on and it is asking me for a "new copy_CDA" disk

    What should I do about this?

    Thank you
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest that you post a description of this problem in the Software Forum and reference that you just finished this thread in the Malware Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds