Another Virtumode Problem needing resolved.

Discussion in 'Malware Help (A Specialist Will Reply)' started by ocdetective, Sep 8, 2007.

  1. ocdetective

    ocdetective Private E-2

    Hi like quite a few others I have been getting problems with virtumonde. I ran the latest spybot in safe mode and it came up with 3 instances shown in the registry.
    The rest of my scanning and cleaning was done in accordance with the Read and Run me First sticky and I am attaching the necessary logs to this and the next post.
    Hopefully they are sufficient to debug the problem - thanks in advance.
     

    Attached Files:

  2. ocdetective

    ocdetective Private E-2

    Here are the other 3 necessary logs. The HijackThis executable was renamed LoJohnThat prior to running it.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Most of your Vundo infection appears to be gone already. Let's cleanup what remains.

    First uninstall the CounterSpy trial since we are finished with it.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now delete the below files:
    C:\WINDOWS\system32\etxsikvw.dll
    C:\WINDOWS\system32\kbathggs.ini
    C:\WINDOWS\system32\vxdsjjal.ini
    C:\WINDOWS\system32\wvkisxte.ini
    C:\WINDOWS\system32\wxsrypcf.ini

    Now rerun Spybot and if it still detects anything, attach a log from Spybot.

    Also attach a new log from ShowNew no matter what!
     
  4. ocdetective

    ocdetective Private E-2

    OK uninstalled counterspy, merged the text into the registry. I deleted the .ini files but could not delete the .dll file until I rebooted in safe mode. I also immediately ran spybot (so in safe mode) after deleting the .dll and emptying the trash folder.
    Attached are the 2 files requested (the same 3 instances of virtumode still appearing seemingly :( )
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. Spybot log if anything is still detected
    3. ShowNew


    Make sure you tell me how things are working now!
     
  6. ocdetective

    ocdetective Private E-2

    Many thanks for the help so far!
    OK slowly getting there - ran The Avenger as requested and seemingly it managed to clean the .dll and one instance of the virtumonde but the other two could not be found by The Avenger for some reason so Spybot was still picking them up initially. Checked the registry to confirm they still existed within there and manually deleted them there and ran spybot which showed no immediate threats, so rebooted and re-ran spybot with similar results (the resultant log shown attached).

    One other thing after deleting the etxsikvw.dll file earlier I am now getting an error message on boot up saying "Error loading C:\Windows\system32\etxsikvw.dll - the specified module could not be found". I checked my device drivers and there are no errors there so not sure why this is popping up?

    3 logs attached as requested.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below files:
    C:\Documents and Settings\bgscweni.txt
    C:\Documents and Settings\spipdxqb.txt

    Also delete the below folder:
    C:\Documents and Settings\Mike\Application Data\Sunbelt Software





    Download Registry Search (see the link titled RegSearch Download Link)

    * Extract the files from Regsearch.zip into a folder.
    * Doubleclick regsearch.exe to start the program.
    * Enter etxsikvw in the top area of the form and then click "OK".
    * Notepad will be opened with text in it (the file named RegSearch.txt will be saved in the program's folder as well). Attach this file to your next reply.
     
  8. ocdetective

    ocdetective Private E-2

    Ok files and folder deleted and copy of regsearch log attached as requested. :)
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    How are things working now?
     
  10. ocdetective

    ocdetective Private E-2

    OK the fixME file merged successfully into the registry. Things are running well right now - spybot consistently coming up clean and now consciously using Firefox instead of IE7. Thanks again!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  12. ocdetective

    ocdetective Private E-2

    Ok done all the clean up suggested and set a new system restore point. I have Symantec Personal Firewall and AVG anti-virus always running as well as spywareblaster. I will now run spybot, ccleaner and ad-aware personal on a weekly basis and will stick with Firefox. I have the latest Java and it is set to prompt whenever an update is available. Is this sufficient?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! As stated in that link you need to have a realtime antispyware blocking tool installed and non of what you just mentioned fall into that category. You need to install one the ones listed.

    Also make sure you get your updates for Spybot and Ad-Aware each week too. Also everytime you update Spybot you should re-Immunize because there could be new additions.
     
  14. ocdetective

    ocdetective Private E-2

    OK have installed Comodo BOClean so should be all sorted now. Cheers for all the help!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds