Virtumonde pest

Discussion in 'Malware Help (A Specialist Will Reply)' started by mateojimmy, Dec 16, 2008.

  1. mateojimmy

    mateojimmy Private E-2

    I have been having problems w/ virtumonde, virtumonde.generic, and smitfraud.c. I run Symantec and Sybot S&D normally w/ their associated protections running. I had problems w/ the trogen before, but I thought I fixed it w/ Spybot. It started acting up again recently. My wife and I are both careful on the internet and not sure where it came from. We believe the first time was using blogspot and the second time facebook...Neither of which I would assume would pass along vundo w/o running the applications they have. I tried Avast (installed it, ran it, uninstalled it) and it fixed some stuff. I also tried VirtumondeFix from atribune.org and it found nothing. Symantec didn't find anything either. Then I came to this site and followed the READ & RUN ME FIRST thread. I was unable to uninstall Java (I have Java 2 Runtime Environment, SE v 1.4.2_03). I got the message "The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is no correctly installed. Contact..." It wasn't in safe mode at the time. Instead of Normal Startup mode in msconfig I used Diagnostic mode dropping to bare bones including not running teatimer (Normal ran way too many services). System Restore was already turned off. I downloaded SUPERAntiSpyware & Malwarebytes, installed them, and updated them. I downloaded the rest of the files and turned off my wireless connection on my laptop. I then ran through the 5 programs suggested and collected their logs. I tried to get back on the net but was unable due to disabling everything. I went to take it to a Normal start, but it was already in a Custom mode. I took it to Normal and back to Custom (getting rid of a bunch of services). I was able to access my wireless connections and it claims everything was back to normal. I was however not able to establish a connection to the net (IE, Mozilla, Outlook, etc.). So I downloaded the logs and am currently using another computer. Attached are my logs. Thanks for your help in advance.
     

    Attached Files:

  2. mateojimmy

    mateojimmy Private E-2

    more logs
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    For us to properly diagnose and fix your problems, you need to get us logs from Normal Boot mode without MSconfig being used. Please follow the below instructions. Do them in Normal Startup and Normal Boot mode.


    Run this procedure: Resetting Registry and File Permissions Make sure you reboot as instructed.

    Afer reboot, run SUPERAntiSpyware and first check for updates. Then run a new scan and attach the new log. Do the exact same with Malwarebytes.

    Now try using this Your Uninstaller! 2008 to uninstall the old Sun Java version.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (file missing)
    O20 - AppInit_DLLs: ckykge.dll zdejxh.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    Now I suggest that you reboot and run another scan with SUPERAniSpyware and Malwarebytes to see if those Vundo related registry keys have truly been removed or are they still detected. Let me know.
     
  4. mateojimmy

    mateojimmy Private E-2

    First of all, thank you a ton! I believe that all malware is removed. As you asked I changed startup mode to normal. I previously downloaded all files and transferred them w/ a flash drive. I reset my registry and rebooted. I tried to get online to update SUPERAntiSpyware and Malwarebytes, but no luck. Although my wireless connection showed connected as normal, Internet Explorer kept giving me errors. I clicked on the link to have Windows diagnose the problem. It came back w/ the Winsock provider catalog had a problem and that I should reset it. I did and it forced me into a reboot. When complete, it still gave the same errors and so I didn’t get the updates. I ran the scans, which found nothing. I used ccleaner to uninstall Java and then followed the rest of your list. When I was all done I deleted the quarantined files, ran ccleaner, the three scanners and again they found nothing. I have attached my logs (again transferred w/ a flash drive). Thank you again for the help getting rid of Virtumonde!!! Do you know what I need to do to use the internet again?
     

    Attached Files:

  5. mateojimmy

    mateojimmy Private E-2

    attached log
     

    Attached Files:

  6. mateojimmy

    mateojimmy Private E-2

    FYI, this is what I get after diagnostic for bad IE (or Mozilla) connection.


    Last diagnostic run time: 12/19/08 21:34:02 WinSock Diagnostic
    WinSock status

    info All base service provider entries are present in the Winsock catalog.
    info The Winsock Service provider chains are valid.
    error Provider entry MSAFD Tcpip [TCP/IP] could not perform simple loopback communication. Error 10061.
    error Provider entry MSAFD Tcpip [UDP/IP] could not perform simple loopback communication. Error -1.
    error Provider entry RSVP UDP Service Provider could not perform simple loopback communication. Error -1.
    error Provider entry RSVP TCP Service Provider could not perform simple loopback communication. Error 10061.
    error A connectivity problem exists with an installed LSP.
    action Automated repair: Reset WinSock catalog
    action Successfully executed: netsh winsock reset catalog
    info System restart required



    Network Adapter Diagnostic
    Network location detection

    info Using home Internet connection
    Network adapter identification

    info Network connection: Name=Local Area Connection, Device=Realtek RTL8139/810x Family Fast Ethernet NIC, MediaType=LAN, SubMediaType=LAN
    info Network connection: Name=Wireless Network Connection, Device=Broadcom 802.11b/g WLAN, MediaType=LAN, SubMediaType=WIRELESS
    info Network connection: Name=1394 Connection, Device=1394 Net Adapter, MediaType=LAN, SubMediaType=1394
    info Network connection: Name=Internet Connection, Device=Internet Connection, MediaType=SHARED ACCESS HOST LAN, SubMediaType=NONE
    info Both Ethernet and Wireless connections available, prompting user for selection
    action User input required: Select network connection
    info Wireless connection selected
    Network adapter status

    info Network connection status: Connected



    HTTP, HTTPS, FTP Diagnostic
    HTTP, HTTPS, FTP connectivity

    warn FTP (Passive): Error 12029 connecting to ftp.microsoft.com: A connection with the server could not be established
    warn HTTP: Error 12029 connecting to www.microsoft.com: A connection with the server could not be established
    warn HTTPS: Error 12029 connecting to www.microsoft.com: A connection with the server could not be established
    warn FTP (Active): Error 12029 connecting to ftp.microsoft.com: A connection with the server could not be established
    warn HTTP: Error 12029 connecting to www.hotmail.com: A connection with the server could not be established
    warn HTTPS: Error 12029 connecting to www.passport.net: A connection with the server could not be established
    error Could not make an HTTP connection.
    error Could not make an HTTPS connection.
    error Could not make an FTP connection.
     
  7. mateojimmy

    mateojimmy Private E-2

    I thought I had uninstalled ZoneAlarm Firewall....I found out that i hadn't. I uninstalled it and now I can get online. So I believe that I have cleared the virtumonde pest and the connectivity issues. If you double check my logs and verify that I am clean, I believe that I am ready to finish up and remove some of the files installed. Thank you again for your help.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  9. mateojimmy

    mateojimmy Private E-2

    I did as you asked and they both came up clean. I've attached them for you. Also, since a few days ago, I have run a number of the scans (Spybot S&D, Malwarebytes, and SuperAntiSpyware) after numerous reboots and haven't found anything. Do you think that I have dormant or hidden vundo files? Or are you just being extra careful? Thank you again.
     

    Attached Files:

  10. mateojimmy

    mateojimmy Private E-2

    I just ran Spybot S&D and it found a Microsoft Windows Security Center AntiVirus Override registry entry. It fixed it, but unsure what exactly this is, so I don't know if this was an issue or not. Attached log file.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not a problem. It is just a registry setting that you may have set yourself in Windows Security Center. When you tell it that you have an antivirus program that you will monitor yourself, this value AntiVirusOverride value gets set to a 1. The normal value is 0 which mean Winows Security Center will monitor your antivirus and it will popup a red shield if your AV is out of date or disabled.

    Your logs are all clean but you do need to do the below to remove some remnants of Avast. This registry patch may not work since you did not disable Spybot's Teatimer as requested in the READ & RUN ME. Try the patch, but if you get a warning from Teatimer, make sure you allow the change.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Also run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. mateojimmy

    mateojimmy Private E-2

    Sucess on the registry edit. Also I disabled Windows Messenger as described, but I am pretty sure this is what we use to chat online (w/ MSN messenger)...As this is what it is called in the program files list. Anyways, thanks again!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Windows Messenger should not be what you use. As stated it was a security risk. Microsoft has removed it from Windows XP in later versions and stopped all development on it. It was superceded by MSN Messenger and then Windows Live Messenger. Or perhaps you are thinking of .NET Messenger Service or Office Communicator which is used in corporate environments.

    Windows Live Messenger is available here: Windows Live Messenger


    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds