Virtumonde detected by SpyBot

Discussion in 'Malware Help (A Specialist Will Reply)' started by legolass, Nov 27, 2010.

  1. legolass

    legolass Private First Class

    Hey y'all!

    I am not actually having any problems (yet, and am knocking on my head!). I ran my normal once-a-week scans, and SpyBot (bless them!) found Virtumonde.dll. It has been trying desperately to get rid of it, but no go. Did read and run me and attaching logs.

    The only thing that didn't work was Root Repeal. I started it and went away for a while. Came back and my desktop was back to the user screen (I have three users). When I went in, Windows told me the system had recovered from a serious error.

    Error Signature:
    BCCode:77 BCP1: C000000E BCP2:C000000E BCP3:00000000
    BCP4: 01DA7000 OSVer: 5_1_2600 SP: 3_0 Product: 768_1

    Error Report Contents:
    C:\DOCUME-1\CHRIST-1\LOCALS\Temp\WERcdd.dir00\Mini112710-01.dmp
    C:\DOCUME-1\CHRIST-1\LOCALS\Temp\WERcdd.dir.00\sysdata.xml

    I sent the error report, and it said Windows was temporarily unable to read my hard disk drive. If an error report was created by Root Repeal, where would it be?

    I then carried on with everything else, and am attaching logs. Thanks for any help, as always!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the log from Spybot. Typically this is just some benign registry entry that it should be able to remove but does not. In all cases we have seen, it is really a non-issue, but let's see the log to be sure.

    Are you running more than the firewall from Comodo? Double check to be sure it is only the firewall running.
     
  3. legolass

    legolass Private First Class

    Hi Chaslang!

    I checked the firewalls, and the Windows one WAS on. I don't know how that happened, because when I downloaded the Comodo one from MG months ago I conscientiously followed all instructions, including turning the Windows firewall to OFF. I have turned it off now.

    Also, please forgive me, but I don't know how to access the logs from SpyBot. I can get in through SpyBot to see them, but when I tried to download them to attach to this post, the "logs" category under Spybot didn't come up, and I don't know how else to get them.

    Thanks!
    legolass
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but my question is about what protection from Comodo is active. Comodo Internet Security also can be an antivirus, antispyware, firewall....etc. What do you actually have active?

    When it finishes running, right click in the scan window and create the log to attach.;)
     
  5. legolass

    legolass Private First Class

    Hi Chaslang!

    As far as I KNOW, the only Comodo product I downloaded was the firewall. I checked my security settings, and the Comodo firewall is ON, the Windows firewall is OFF, and my Avast antivirus (seemingly the only one I have!) is fully updated and running.

    I ran the SpyBot and am attaching the logs. .Results is before I told it to fix the problems, and .Results1 is after I told it to fix the problems, since I wasn't sure what you need to see. Hope this is OK. As last night, when I ran SpyBot just now it stopped when it got to the Virumonde section, and this little box popped up with a list, and said if I click Yes it will run a scan next time I reboot, and to go ahead and finish this scan and deal with the results. I did that yesterday,too; it ran a VERY LONG time, and then found Virumonde again, seemed to delete it, but then it came back again. I packed it in after that (last night) and then did the read and run me today, and now we're back to square one with SpyBot.

    Hope this all makes sense, and thanks!
    legolass
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to check what Comodo says not what Windows says. Double click the Comodo icon in your tray and see what protection it indicates you have.


    C:\WINDOWS\system32\mfc40.dll is a file for Microsoft Visual C++. Locate the file in Windows Explorer. Right click on it and select Properties. Now see if there is a Version[ tab in the window. If so, select the Version tab and on the next window select each of the listed Item names (one at a time) to get more info about the file. The most important Item is the company name. If there is no Version tab, tell me that too.

    All of the below files on your PC are just from an older version of the files from Visual C++
    Code:
    ----a-w           924,432 2004-08-04 12:00:00  C:\WINDOWS\system32\mfc40.dll
    ----a-w           927,504 2008-04-14 00:11:56  C:\WINDOWS\system32\mfc40u.dll
    ----a-w         1,028,096 2008-04-14 00:11:56  C:\WINDOWS\system32\mfc42.dll
    ----a-w            53,248 1998-06-17 23:06:34  C:\WINDOWS\system32\MFC42ENU.DLL
    ----a-w           981,760 2007-04-03 03:14:47  C:\WINDOWS\system32\mfc42u.dll
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I went around to a few of my PCs and found one where I still had mfc40.dll on the PC. I then ran Spybot and it FALSELY detects mfc40.dll as Virumonde. This is a bug with Spybot. It is not malware.
     
  8. legolass

    legolass Private First Class

    Hi Chaslang!

    OK, Comodo summary shows Firewall, blocked 158 intrustions... Under that it says Defense+, blocked 1 intrustion, 0 apps currently running in sandbox. I remember when I downloaded it I said Firewall Only, or something like that, and then (I AM only a Private, and there IS a reason for that!) I just trusted it to know what to do, because I certainly don't. (You probably guessed that...)

    I found and checked the above files; they all had Version tabs, they all said Microsoft under Company, and then there were other things listed under company, like file version, internal name, language... did you need those? The only one that was a little different was mfc42u.dll, which also had a Digital Signature tab. It said Microsoft under that.

    I see you found it too. So should I delete this mfc40.dll file? Or just wait 'til Spybot fixes the bug? I run it every week, and I never got this before.

    Thanks!
    legolass
     
    Last edited: Nov 27, 2010
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is a valid file. I now remember why I removed Spybot from the READ & RUN ME. It is basically junk. It finds lots of false detections which are absurd ( 31 on my last scan just run ). All were valid files or bookmarks to websites with info on malware. They were not malware. These problems have existed with Spybot for years and have never been fixed. Also their logs are basically useless as they do not even point out the exact location of where they "think" a problem is with bookmarks. You have to try and wade thru all the bookmarks you have just to try and fiigure out what it thinks it is finding. Then you find, it is not a problem. It is just a link to something you saved. Funny thing is that it finds these bookmarks a problem with FireFox but they are not problems in IE when the same one exist. This is a bug!

    The only reason to keep Spybot around is for the Immunization and SDhelper features. I don't recommend scanning with it as it is way too slow and is not really that useful against real current malware problems ( the same is true for Ad-Aware which is not useful at all anymore and I tell people to uninstall it ). SUPERAntiSpyware and Malwarebytes are 1000 times more useful then either Spybot or Ad-Aware.
     
  10. legolass

    legolass Private First Class

    Hi Chaslang!

    Thanks for the advice. I did get rid of Ad-Aware long ago, and along with SpyBot I do scan every week with SAS and Malwarebytes. I will keep SpyBot then for the immunize feature, but stop scanning with it (although I must say I have never run into anything like this with them before).

    Thank you so much for helping me yet again. :wave

    Should I just follow the cleanup steps in the read and run now?

    legolass
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Follow the below.
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  12. legolass

    legolass Private First Class

    Hi Chaslang!

    OK, I'm all set. Thanks again for all your help.

    Sincerely,
    legolass :wave
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds