Virtumonde removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by robbo, Jan 25, 2009.

  1. robbo

    robbo Private E-2

    Hi i have looked at this site to remove Virtumonde followed the steps and now all i need to know is if i have added the right attachments as SpydoctorSD had more then one log so i have the one that relates to Fixes.log and if i still have Virtumonde on my PC after that i will scan with my Adware 2008 .THANKS TEAM ::cool
     

    Attached Files:

  2. robbo

    robbo Private E-2

    Here is my other log, hope i have done this posting right feel free to whop my *** majorgeeks but lets not go there lol :cool
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gifWelcome! to MajorGeeks.com!http://www.majorgeeks.com/images/grenade.gif

    There has been an update to SAS since you last installed it. Please download the updated copy below and save to your desktop. Before installing this new version, please uninstall the current version, reboot and then install the new version. After installing, update and then configure the scanner as requested in the READ ME. Once completed, run a full scan and attach the new log once complete.

    Also, please run C:\MGTools\GetLogs.bat and attach the new set of logs created (C:MGLogs.zip).

    SUPERAntiSpyware 4.25.1012
     
  4. robbo

    robbo Private E-2

    Hi Bjgarrick and thankyou for taking the time to look at my problem i have done this correct this time lol please see attached logs.:major.thankyou again :)
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.


    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Default Security Settings

    To Default Security Settings:
    For Internet Explorer 6 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up navigate to the Security Tab and click Default Level for the following:
    • Internet
    • Local Intranet
    • Trusted Sites
    • Restricted Sites.
    Click OK to exit.

    For Internet Explorer 7 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up, navigate to the Security Tab and simply click the "Reset all zones to default level" button. Click OK to exit.

    NOTE: If it's "grey" then it's already at the default level.​
    Step 4:
    Please download ATF-Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF-Cleaner menu to close the program.​

    Step 5:
    Next I would like you to install the current version of Sun Java: Sun Java Runtime Environment

    Step 6:
    Finally, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  6. robbo

    robbo Private E-2

    hi bjgarrick :) just one thing i have already updated java to update 11 should i uninstall this as well then perform this step again once i deleat the other java updates and then i will perform the scan you have asked me to do in this post.thanks :)
     
  7. robbo

    robbo Private E-2

    Hii again i just noticed from your post at the end are you asking me to RUN COMBOFIX again or just from the previous scan retrieve the .txt log and also just so i understand it better i take it you want me to go to the majorgeeks folder open it and click on the icon showing the detective (analyse) ?:)
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If it's already installed, then just be sure all previous versions are uninstalled.
     
  9. robbo

    robbo Private E-2

    Ok i will attempt this later :)
     
  10. robbo

    robbo Private E-2

    Hi Bjgarrick i have not run into any kind of problems so far when your happy all is ok i will perform a full scan with my Adware 2008.The only thing i have noticed is when i run Combofix my AVG in the system tray displays as if it is scanning but when i check it is not scanning, after i reboot it clears.Here is my logs thanks again
     

    Attached Files:

  11. robbo

    robbo Private E-2

    Sorry i just had to run the MGlogs again as i done this before i did the Combofix scan.I will wait patiently for your reply thanks :major
     

    Attached Files:

  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware & Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources (except a little disk space) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to Add/Remove Programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows Vista, Windows XP or Windows ME, you need to follow the below:
      • Refer to the cleaning steps in the READ ME for your Windows version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. robbo

    robbo Private E-2

    I shall do this soon as for the advice on keeping the amentiond malware programs i will also check with my Adware if this still detects Virtumonde.Then if all is well i will deleat this program.Thankyou for your time and patience Bjgarrick :major
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You're Welcome!:)
     
  15. robbo

    robbo Private E-2

    Hi Bjgarrick i have followed the FINAL STEPS when i performed the Combofix/u windows incountered a problem window appeared (PREP.COM) and Avg8 detected a Win32.trojandropper C:/32788r22FWJFW in local settings/temp/c.tmp/b2e.dll which i moved to the vault and removed. I disabled Avg8 and Hidden Files and then did full scans with your metioned programs and did not detect anything when i used Adware 2008 it detected this in my first scan and last scans even thou Adware 2008 said it was deleated the first time.Also i could not deleat SpybotSD folder it said SDHelper access denied.But no Virtumonde found.Should i perform the same steps from the VERY begining to resolve this Win32 trojan.:confused i have just done a system restore disable and enable also.
     
    Last edited: Feb 7, 2009
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the updated of ComboFix and save to your desktop. Once downloaded, run it and attach a log.
     
  17. robbo

    robbo Private E-2

    Hi bjgarrick i ran the combofix after it rebooted another IE icon appeared on the desktop (but did not have the arrow in the corner of the icon) plus a text file called (catchme) also appeared to so i moved this to the bin for now.Are theses infected ??? when the log compleated a windows message appeared words to the effect that said (NIRCMD.exe cannot be found make sure it is typed correctly and try again).Before all this i had run full scans with Adware and AVG8 and no infections found (good i guess) but from my previous post (2/7/9-14.09) when i found this new infection i had moved to vault and deleated but also did the system disable and enable mode to flush the restore points then did another scan and came up clean (maybe this did the trick).So things look good other then SpybotSD folder i would like to remove if possible thanks :major
     

    Attached Files:

  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will pop up for you to view when you login after reboot. Please attach this log to your next post.
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    These are leftovers from the utilities, they are flagged by some programs due to their nature.
     
  20. robbo

    robbo Private E-2

    Hi again done the scan and from the log looks like nothing was found that related to the error i had when i deleated the combofix so hopefully that will be good news as i'm not getting any errors on screen.:major are we there yet :-D
     

    Attached Files:

  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Everything looks good, just be sure you follow all of the steps in post 12.:)
     
  22. robbo

    robbo Private E-2

    Thanks very much for your help bjgarrick i would never of thought to come to a site for help but on the other hand it could cost people possible £100s to get a pc fixed i will sure donate money to the cause for the great help recieved by yourself and the majorgeeks team.:major
     
  23. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    You're Welcome!

    Surf Safely!:major
     
  24. robbo

    robbo Private E-2

    Hi Bjgarrick don't know why but i have managed to remove the SpybotSD folder by diconnecting the internet and then deleating it and OK, just a question in my future FULL scans should i disable HIDDEN FILES and if any HIGH LEVEL INFECTIONS found deleat and then perform DISABLE then ENABLE SYSTEM RESTORE as i have never done this action in every day scans Pc users would not normally do ? :)
     
  25. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Our guides explain how to scan a system. There are certain things you should do and once the system is clean, it's best to toggle system restore to flush out any bad restore points.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds