Explorer.exe not starting after Virtumonde (and more) fix

Discussion in 'Malware Help (A Specialist Will Reply)' started by kstucchi, Sep 10, 2008.

  1. kstucchi

    kstucchi Private E-2

    I am helping my sister fix her computer, which did not have antivirus software on it. The usual problems, pop-ups, slowness, etc. Virtumonde and many more viruses, including DNS hijack were on here.

    Now I believe the viruses are finally gone. However, explorer.exe will not start at startup and it seemed to occur right after I ran Combofix. I can run explorer.exe from the taskmgr, but it will not start on its own.

    I've followed all of the instructions in the readme and I'm pretty sure the viruses are gone but maybe I'm just not seeing it.

    Any help in getting explorer.exe to come up at startup would be greatly appreciated! Apologies if I'm not posting this in the correct place.

    TIA

    Logfile of Trend Micro HijackThis v2.0.2
     
    Last edited by a moderator: Sep 11, 2008
  2. kstucchi

    kstucchi Private E-2

    Re: Explorer.exe not starting after Combofix

    Okay, I fixed this myself and just posting again to let others who have had the same problem know what I did to fix it.

    The problem, again, was that explorer.exe would not start at startup after I ran Combofix. I forgot to mention that I could not restore to a previous restore point because every time I tried it failed.

    After I posted yesterday and closed down IE, there was a popup window on the screen (!). I decided to go through the cleaning process in the README all over again one more time.

    Checked Add/Remove programs and noticed a weird install program called BChanger that I must have missed. I removed it. I also removed Java Runtime again.

    Rebooted, still needed to load explorer.exe manually.

    I reinstalled Java Runtime. Did not reboot.

    I ran a SuperAntiSpyware scan - which found no threats. Did not reboot.

    I ran a MalwareBytes scan - again, no threats. Did not reboot.

    I ran Spybot S&D - a-ha! - found 3 instances of Win32.Agent.es (2 Root class, 1 Type library). Spybot S&D detected it in a previous scan but could not remove it. When I removed BChanger via Add/Remove programs it probably was then able to remove it. This is the previous log:

    Win32.Agent.es: [SBI $F044382C] Root class (Registry key, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BChanger.Helper

    Win32.Agent.es: [SBI $F044382C] Root class (Registry key, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BChanger.Helper.1

    Win32.Agent.es: [SBI $092564BF] Type library (Registry key, nothing done)
    HKEY_CLASSES_ROOT\TypeLib\{9552F3B2-4183-4473-A347-96F82AF15F26}

    I rebooted. Explorer.exe started, desktop is back, wallpaper is changed to a nice blue color, which I don't know but am assuming was the color my sister had it before the viruses (was fixed to Dell wallpaper after Virtumonde fix).

    I don't know if the explorer startup fix was the Java Runtime, the trojan/worm that Spybot fixed or just a lucky break that either of them just so happened to change something in the system to restore explorer.

    Good luck to others with this problem!
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the zip folder from running the MGTools.exe ---> located at C:\MGLogs.zip
    so I can be sure that all malware is removed. :)
     
  4. kstucchi

    kstucchi Private E-2

    Thank you TimW. I wouldn't be surprised if there are more viruses. This computer is for the record books.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Only a couple of items to deal with:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  6. kstucchi

    kstucchi Private E-2

    These guys won't go away. I've tried before and, still, when I do a scan they are still there in Hijackthis. (And yes, all browsers are closed and antivirus is disabled when I try)
     
  7. kstucchi

    kstucchi Private E-2

    Avenger ran fine.

    Logs attached.

    Thank you!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The two lines are not a major problem...we will remove them.

    Are you having any other malware issues? :)

    Let's do a little clean up:

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you get a success message, then it is time to do our final steps:
     
    Last edited by a moderator: Sep 12, 2008
  9. kstucchi

    kstucchi Private E-2

    Thank you so much!

    The registry patch worked.

    I cleaned up all of the removal tools.

    Fingers crossed!

    You guys rock!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds