Virtumundo

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jack Carraher, Feb 8, 2009.

  1. Jack Carraher

    Jack Carraher Private E-2

    Our computer has been infected with the virtumundo adware. We use Trend Micro which finds it and quarantines it. We can then delete it. It is located at CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B7... As soon as we get it deleted and then run the spyware again, it is right back. If we run the internet it is just continuous pop-ups. I am having to do this on a different computer as I can't do it on the infected computer. Thank you for your help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Jack Carraher

    Jack Carraher Private E-2

    Thank you for your help. I went through all the steps and had the following problems with the downloads - Spybot Search and Destroy - I have to use a different computer so I downloaded these programs to a CD and then copied them to the infected computer. Spybot S&D downloaded to the CD but I could not copy it to the computer. It kept getting an "Error sending request - the system cannot find the file specified" or "Error sending request - the server name could not be resolved". Therefore, I have been unable to run this program.

    I also had a problem trying to download MG Tools to the CD. It would start to download but after only 120 kb it would go no further, it just kept trying but got nowhere.

    I appreciate your help and time.

    Jack Carraher
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean by downloading to CD. First you need to download the programs to the hard disk on your other computer. Then you need to burn them to a CD.

    You made no mention of SUPERAntiSpyware, Malwarebytes or ComboFix.
     
  5. Jack Carraher

    Jack Carraher Private E-2

    I am sorry I didn't explain it better. I did downloadand burn the Search and Destroy program to a CD; then I could not get it off the CD onto the infected computer.

    As for MG tools, it just wouldn't download onto the good computer.

    Thank you.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why? What exactly happens when you try to copy the file to the infected computer?

    What about the other programs?

    Exactly what happens? Are you sure that you are logging into MajorGeeks properly? You need to make sure you check the box that says Remember Me.
     
  7. Jack Carraher

    Jack Carraher Private E-2

    I cannot be more effusive in my thanks for all your help in removing the Virtumundo virus/trojan from my computer. I downloaded and ran the five removal programs and the computer seems to be completely normal. The Super Antispyware program found over 90 problem files and removed them all. I did have to run it twice as the first time it went to the blue screen crash and gave a "Fatal System Error". I unchecked the two kernel boxes and the second time it worked. The Malware Bytes program found over ten items and removed them. The last three programs didn't find any more. Three of the logs are attached and I will attach the rest in another post.

    Again, thank you very much for all your help. Keep up the good work and if there is anything I can do to help, please let me know.

    Thank you.

    Jack
     

    Attached Files:

  8. Jack Carraher

    Jack Carraher Private E-2

    Here are two more logs. I could not find a log for Spybot S&D, maybe because it did not find any problems. If there is a log, maybe you can tell me where to find it.

    Thank you again.

    Jack
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask for one. ;)

    We do however need the requested log from MGtools before we can continue. Attach the C:\MGlogs.zip file

    And note that ComboFix did find and remove malware from Vundo. You said only MBAM and SAS did.
     
  10. Jack Carraher

    Jack Carraher Private E-2

    Here is the last log.

    Thank you again.

    Jack
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have little more cleaning to do.


    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O20 - AppInit_DLLs: qqmgbw.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. Jack Carraher

    Jack Carraher Private E-2

    I did the steps you outlined and everything seemed to work. The zip file is attached.

    Thank you again for all your help.

    Jack
     
  13. Jack Carraher

    Jack Carraher Private E-2

    I will try again to upload the zip file.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have not attached anything. You need to make sure that you have run C:\MGtools\GetLogs.bat to produce a new log. Otherwise you would be trying to attach the same log as last time and you cannot do that.
     
  15. Jack Carraher

    Jack Carraher Private E-2

    Here it is, sorry for not getting it done right the first time.

    Thank you again for all your help and patience.

    Jack
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds