Computer infected with Virtumonde

Discussion in 'Malware Help (A Specialist Will Reply)' started by bunny1, Jan 10, 2009.

  1. bunny1

    bunny1 Private E-2

    I read your document and downloaded and installed all the antispyware and created the logs, I am not sure what to do next, I am not sure if it is completly removed. Your help would be appreciated.

    Thanks in advance.
     

    Attached Files:

  2. bunny1

    bunny1 Private E-2

    I was wondering if anyone answers these emails, I just don't want to format my harddrive and was hoping for a solution.
     
  3. bunny1

    bunny1 Private E-2

    Computer infected with Virtumonde - no response

    I posted a message yesterday regarding my computer being infected with Virtumonde, I really need some help. Does anyone reply to these messages, if not could you please let me know so I do not keep checking. I will have to try and find another solution. Please let me know if you can help or not.

    Thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. bunny1

    bunny1 Private E-2

    Sorry I am new to this, this is my first post
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not install and run SuperAnti-spyware. Do so now.

    Your MBAM log indicates that you did not have it fix what it found:
    Is this a company computer:
    Use windows explorer to find and delete:
    c:\windows\Tasks\hkkjngvh.job

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me what issues you still have.
     
  7. bunny1

    bunny1 Private E-2

    Thank you kindly for your response. I apologize for my second post, I was not aware I should not post again and read your link. This was my first ever post to a forum .

    I followed your instructions and ran SAS. I thought I had run SuperAntiSpyware, I think I may not have installed the free version and when I tried to clean my system, it didn't clean all. (not sure what happened there) Anyway I have installed it and ran it sucessfully this time. It found 9 entries and quarantined and deleted the items. I also deleted the entry in the scheduled tasks and created the fixme.reg file and executed it.

    Not sure what my next steps are. Do I need to rerun the other malware applications again?
     

    Attached Files:

    • SAS.log
      File size:
      965 bytes
      Views:
      1
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file so I can make sure you are clean.

    You did not answer my questions:
    Is this a company computer?

    What issues are you still having?
     
  9. bunny1

    bunny1 Private E-2

    I did buy this computer from work.
    I reran the mgtools and have attached the zip file.
    I am not sure if I am still having any issues, it seems to be okay, but my computer did abruptly shutdown, it indicated it had to shutdown abruptly due to new software, hardware or and virus. I have not installed anything new except the software required to clean the computer. I did hook up my zune to charge it though. Not sure if that could have caused it. Not sure if I should have, but I also ran spbot and superantivirus again, they did not pick up anything.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean......If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  11. bunny1

    bunny1 Private E-2

    Thank you so much for all your help, you're the best. Your effort was very much appreciated. I performed the final steps and all appears to be running smoothly. I read your preventive measures, not sure why I got it in the first place.:).

    Again thank you so much!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds