BSOD After Removing Virtumonde

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maevik, Sep 14, 2008.

  1. Maevik

    Maevik Private E-2

    I was recently infected with the Virtumonde malware. I ran several spyware removers as well as virus scanners and eliminated the majority of the problem. Now the only symptoms I can find are:

    Browser in SafeMode with Networking gets hijacked. Any links i click will be redirected.

    Computer BSODs and restarts ~5m after loading in normal mode.

    The BSODs started after I enabled Windows Defender, which also seemed to be the thing that helped the most in removing the symptoms of the infection.

    Here is the message I get after the computer reboots after a BSOD.

    Problem signature:
    Problem Event Name: BlueScreen
    OS Version: 6.0.6000.2.0.0.768.3
    Locale ID: 1033

    Additional information about the problem:
    BCCode: 1000007e
    BCP1: C0000005
    BCP2: 8305E9DD
    BCP3: 8944BBDC
    BCP4: 8944B8D8
    OS Version: 6_0_6000
    Service Pack: 0_0
    Product: 768_1

    Files that help describe the problem:
    C:\Windows\Minidump\Mini091408-01.dmp
    C:\Users\User\AppData\Local\Temp\WER-62431-0.sysdata.xml
    C:\Users\User\AppData\Local\Temp\WER2E8E.tmp.version.txt

    Read our privacy statement:
    http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409


    Also, here is a HijackThis log:



    Any help with this would be greatly appreciated. I don't know what else to do.
     
    Last edited by a moderator: Sep 14, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to MG's..:)

    First thing to do is to re-run HJT ( although improperly installed) and select the following line:
    O2 - BHO: (no name) - {D2267E35-3DBB-4B09-BF5C-1CA11D5447F7} - C:\Windows\system32\byXOfeeB.dll
    After clicking fix, just exit HJT

    NOW:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide


    Note:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Maevik

    Maevik Private E-2

    I've tried several times to fix that, both in normal and safe mode. It wont go away... trying the other stuff now.
     
  4. Maevik

    Maevik Private E-2

    Ok, I followed everything that it said to do in the order it said. I got as far as ComboFix which told me it needed to restart my computer.

    When it restarted I got an error boot message that said

    Windows Boot Manager

    Windows failed to start. A recent hardware or software change might be the cause. To fix the problem:

    1. Insert your Windowss installation disc and restart your computer.
    2. Choose your language settings, and then click "Next."
    3. Click "Repair your computer."

    If you do not have this disc, contact your system administrator or computer manufacturer for assistance.

    File: \Windows\system32\drivers\Combo-Fix.sys

    status: 0xc0000221

    Info: Windows failed to load because a critical system driver is missing, or corrupt.


    I also cannot use my keyboard to select "Safe Mode" when I press F8 during start-up. I know my keyboard is working because I can get into the BIOS and the keyboard works fine. I don't know what to do. I don't have a system disc or an administrator. Can anyone provide direction? I'm starting to freak out.
     
  5. Maevik

    Maevik Private E-2

    Update: I made a Vista boot disk, however since I cannot use my keyboard, I have no way of booting from CD (I have to press any key to boot from CD) so it always takes me back to the screen that tells me to insert my windows installation disk.

    If I cannot even boot is my computer dead?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you using a USB keyboard? Have you tried a regular keyboard? Did you check your bios to see if it has USB Legacy support?

    Probably some protection software interfered with the ComboFix and may have removed the combo-fix.sys file which could be the reason for the error.

    Where did you get a Vista boot disc?
     
    Last edited: Sep 15, 2008
  7. Maevik

    Maevik Private E-2

    I went and got a PS/2 keyboard and was able to use the menus. I got into the computer and everything was working fine.

    Thanks again for your help. I'm following the directions on keeping my system clean.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would still be concerned about leftover traces and would like to see the logs from at least:
    MWB's
    SAS
    MGLogs.zip
     
  9. Maevik

    Maevik Private E-2

    I'm sorry I haven't been around to update on this. I've been dealing with some family issues (my mother was diagnosed with cancer) and fixing this computer had to be put on a backburner.

    Here is the SAS log:

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 09/15/2008 at 08:49 AM

    Application Version : 4.21.1004

    Core Rules Database Version : 3566
    Trace Rules Database Version: 1554

    Scan type : Complete Scan
    Total Scan Time : 00:02:59

    Memory items scanned : 461
    Memory threats detected : 0
    Registry items scanned : 6379
    Registry threats detected : 2
    File items scanned : 1
    File threats detected : 0

    Adware.Vundo Variant/Rel
    HKLM\SOFTWARE\Microsoft\aoprndtws
    HKU\S-1-5-21-2294021428-1571833952-2475533299-1000\Software\Microsoft\rdfa​

    I no longer seem to have the ComboFix or Malwarebytes logs. Let me know if I should run the scans again to obtain a log for you.

    The only noticable effects still on my computer are 1) Desktop Wallpaper doesnt work 2) Large "preview" icons in windows show up as invisible (all I see is the file name.)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This has been such a long time since you first posted ( my condolenses for your mom and wish her all the best and a speedy recovery!) that you need to go back to the Read and Run First instructions as all the tools have since been updated ( including the SAS program). Install them anew and attach the logs when you can. :(
     
  11. Maevik

    Maevik Private E-2

    Ok, I ran everything once again in the Read & Run to the letter. I had no problems at all until ComboFix. The program appeared to be running fine, the computer went to the "Windows is shutting down" screen, then I got a blue screen (this hasn't happened since I was first having problems.)

    Now when the computer boots up it prompts me to choose
    Start windows in safe mode
    Start windows in safe mode with networking
    Last known working configuration
    Start windows normally

    No matter which of these I choose, I get the error "Info: Windows failed to load because the system registry file is missing, or corrupt."

    I have the logs though, and will post them as soon as I figure out how to get back into my computer. It says to insert my windows disc and restart, but I do not have a disc (system came with vista installed) so I'm wondering what I should do next.
     
  12. Maevik

    Maevik Private E-2

    Ok, I got back into my computer using the vista bootup disc from NeoSmart.

    Before running ComboFix the other programs seemed to have fixed my issues. My wallpaper and icons were showing up and everything was working great. Now it's back to where it was ( I did not use a system recovery, just the bootup repair.) The ComboFix log looks to be incomplete, but I have absolutely no desire to run that program again.

    Logs are attached.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well...yeah I guess not to combo. It does happen with that utility as it sometimes removes infected system files. It is why we want users to at least try to install the recovery console before running it.

    And yes, you got some infections, so all I need now is the new MGLogs.zip. :)
     
  14. Maevik

    Maevik Private E-2

    Here it is
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the new MGTools.exe scan. Your is a old version :
    Code:
    ShowNew.Bat - (c) 07/01/2006 By Chaslang                       *
    *              This version supports Win2K, XP and Vista                     *
    *                                                                            *
    *             09/06/2008 Version 2.28
    
    MGtools.exe
     
  16. Maevik

    Maevik Private E-2

    Oops, here
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, it looks like the scans took care of all of it.

    However, you appear to have two AV programs installed:
    ESET NOD32 Antivirus
    Trend Micro AntiVirus

    but your HJT log shows the ESET services as this:
    O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe (file missing)
    O23 - Service: Eset Service (ekrn) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (file missing)

    Which AV is active.
     
  18. Maevik

    Maevik Private E-2

    Trend Micro AV

    I liked Eset better, but after ComboFix, it doesn't seem to work, and registry errors are keeping me from re-installing or repairing the program. So I set trend micro as main now.

    Also, I'm still not getting a desktop or icons since the ComboFix run. Is that just due to registry errors, and not necessarily malware.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's get rid of those services that are dead:

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Tell me if you get a success message.

    Now lets uninstall Combo:
    If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)

    Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    "%userprofile%\Desktop\combofix" /u

    Notes: The space between the combofix" and the /u, it must be there.
    [*]This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    And you have neither the OS disk or a restore disk?
     
  20. Maevik

    Maevik Private E-2

    Ok, I ran that batch file and got the DOS window that flashed up. I didn't see any success message, but if it was in the DOS window, it went away too fast to see.

    ComboFix uninstalled successfully (or so it said -_- lol )

    No, I have neither a system disc nor a restore disk. I was able to create a system restore disk from the previously stated site.

    Everything seems to be running great, except that I still have no desktop wallpaper, and those icons are still missing. They were working when I restarted after running SAS, SBS&S and MWB. Then I ran ComboFix and... well, now they're gone again. Would you suggest going back through the READ & RUN up till MWB? Other suggestions?

    Also, a big heartfelt thank you for all the time you spent helping me with this! These write-ups are incredibly effective and clear! I intend to reference them for troubleshooting malware henceforth. Thanks!
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this happen with other user accounts?

    If you go to task manager is explorer.exe running? If so, try ending the process and then reload it. Do you now have the icons back?
     
  22. Maevik

    Maevik Private E-2

    Ahh, yeah, that fixed it. Thanks
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds