Help! Possible virtumonde infection and system registry broken!

Discussion in 'Malware Help (A Specialist Will Reply)' started by syllus, Jan 21, 2008.

  1. syllus

    syllus Private E-2

    Sorry for the lack of hijackthis log, but I think I have the virtumonde virus/malware on my laptop. Kasperski detected it and tried to delete it, but it couldn't - file vtstq.dll will not go

    I tried to remove the references from the registry and now the registry doesn't work. I changed the registry back (I think) but still won't work. I've got no internet, no network, no applications, I can't even copy and paste things in explorer!

    Is this the effect of the virus or something else?

    Please help!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide


    Download to either a thumb drive or a cd and then copy to the infected computer and then see if you can attach the requested logs.
     
  3. syllus

    syllus Private E-2

    Apologies to all for the duplicate post. I was confused when my thread disappeared from the main page so quickly.

    Logs attached as requested. Please note that VundoFix did not run as internet access could not be established. Also, Spybot would not install without internet access and AVG could not be updated.

    Some functionality has been restored and the vtstq malware has gone. (I think)

    However, my registry still does not seem to be working correctly. Applications do not function fully, I have no internet or wireless access and explorer and the taskbar only work some of the time and not completely (i.e. cannot move or paste, taskbar does not always appear).

    Please can you help?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you make some changes to your registry?

    What is the below file for?
    C:\Documents and Settings\Syllus\My Documents\rwe?

    We need to use a new tool.

    * Download and save to RenV.exe from following link to Desktop (
    must be on the Desktop)
    * Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).

    Code:
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp .exe
    
    * Now using your mouse, drag Log.txt onto RenV.exe
    * When finished, RenV.exe will produce a new log names Log.txt on your Desktop I will ask for this log later.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment.

    Now download The Avenger by Swandog46, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.
    Then attach the new logs:

    * Log.tx from running RenV
    * c:\avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. syllus

    syllus Private E-2

    Yes, I changed some of the restristry in order to get rid of the malware. This may well be the problem...

    I assumed I could always use a system restore. However, system restore no longer works!

    C:\Documents and Settings\Syllus\My Documents\rwe is a directory containing a few word documents. It is not vtally important.

    I have run RenV.

    I cannot uninstal Sun Java as the windows installer does not work. Windows advises that it may not be installed correctly and that I should contact my support personnel for assistance.

    Should I continue with the above or do I need to do something different?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue with what you can do with the instructions in my last post ...we may need to do some other things to get the registry back in proper order.
     
  7. syllus

    syllus Private E-2

    Everything completed except for Java update.

    No noticable improvement to system.

    Logs attached.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only malware I am seeing is:
    Code:
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp .exe
    
    You will notice it is not the real file due to the extra spaces.

    Not knowing what registry keys you removed ( I am assuming that you did not do a backup of the registry before doing it) ..then you may be stuck with saving your data and doing a reformat and re-install. :(
     
  9. syllus

    syllus Private E-2

    OK, well thanks very much for your help. I'll get rid of avp .exe.

    I don't have a re-install disk (as Dell don't supply them anymore). Is there any way of returning to default registry?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can contact DEll and request/demand a disc ...it is totally inappropriate of them not to supply a recovery disc at least.
    Otherwise ...post in the software section and hopefully either Adrynalyne or someone could possibly help.

    If it is just certain programs not working ..uninstall/delete and reinstall.

    You could also borrow the cd ( as long as it is the save version - home / pro) if you have your cd key (should be on the back of the computer.
     
    Last edited: Jan 27, 2008
  11. syllus

    syllus Private E-2

    Just had a thought.

    I only deleted/altered reg keys for vtstq.exe and vtstq.dll. If you know which keys are altered by this malware, I could probably figure out where I've gone wrong by comparing the registry on this machine with the broken one.

    Alternatively, I could infect this machine with the vtstq program and see what keys it alters...

    How about it?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you remove the entire key or just the subkey?

    I have no idea which key it attached itself to ....and re-infecting will just attach to keys that do exist ..not keys that are gone. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds