Help with Virtumonde!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by justpk, Sep 3, 2008.

  1. justpk

    justpk Private E-2

    Hello, I have been battling getting rid of this. I followed the read me & run procedures and I am at this point of posting my logs. My computer was actually updating, which it wasn't able to do. I could not uninstall java at all. I hope it still get rid of it and everything that came with it. I hope someone can help me further. I have not done the system restore step yet. I almost did, but it was real sluggish. Here are the logs. Thanks so much for your help!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the log from Malwarebytes as requested. You can find it in the below path:
    Code:
    "C:\Documents and Settings\Administrator\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mbam-l~1.txt  Sep  2 2008 10689  "mbam-log-2008-09-02 (19-16-11).txt"
    
    You have Spy Sweeper installed. Is it only the antispyware program or does it include their antivirus or security suite? Is it a paid copy or trial? You install it on Aug 31st. Is this when your PC became slow?

    What are the below files for?
    Code:
    2008-09-02 16:57 2008-07-12 15:29 27,648 --a-- C:\WINDOWS\system32\drivers\RKHit.sys
    2008-09-02 16:57 2008-09-02 16:57 42 --a-- C:\WINDOWS\system32\AK083E209605E394C.lie
    Is the second a license file for something?

    Uninstall the below two old versions of Sun Java:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8

    Delete the below files:
    Code:
    "C:\WINDOWS\system32\"
    17.tmp        Aug  1 2008           0  "17.tmp"
    19.tmp        Aug  2 2008           0  "19.tmp"
    20.tmp        Aug  1 2008           0  "20.tmp"
    23.tmp        Aug  2 2008           0  "23.tmp"
    27.tmp        Aug  3 2008           0  "27.tmp"
    29.tmp        Aug  2 2008           0  "29.tmp"
    2e.tmp        Aug  3 2008           0  "2E.tmp"
    2f.tmp        Aug  3 2008           0  "2F.tmp"
    31.tmp        Aug  2 2008           0  "31.tmp"
     
    C:\7d892938342bf0.bup
    

    Delete the below folder:
    C:\Program Files\Enigma Software Group

    The below are not malware issues. They are just things you can do to improve performance and also registry patch is a cleanup from running ComboFix.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 4, 2008
  3. justpk

    justpk Private E-2

    I am un-able to get on the internet on that computer. I have run the Super anti spy ware to repair the winsok, but still not working. I will try to do the other things you said to do and then I will get back to you. Sorry for not posting that one log. Also before I forget, I installed Spy Sweeper to combat the Virtumonde, it helped a little by blocking the internet, 29,026 times!! I had McAfee, but had to delete it. Could not empty quarantine, it would freeze computer. I just wanted to keep you updated as to my progress. Oh and for the Java, still can't delete those, I have tried add/remove, ccleaner, tried just deleting but can't do that either. Any suggestions? Thanks sooo m폨uch for helping me.
     
  4. justpk

    justpk Private E-2

    Still unable to access the internet. I'm on a diff computer.
    Ok, starting from the beginning of your post, I am not sure what that file is, when I looked it up, it said created Sept 2, 2008, modified July 12, 2008, accessed today. Weird!! Modified earlier than it was created?How is that so? Says its a system file. Next one, says it's a LIE file? Not sure on that either, but don't want to open to find out. Says it was created, modified, and accessed on Sept 2, 2008. Could just get rid of both.

    Still can't uninstall the Java's.
    Deleted the .tmp files and the bup file.
    That is as far as I can go for now. Until I can get on the internet for the messenger removal.
    Did the HJT step.
    Now I am going to attempt to get on the internet. I will attach the log I forgot earlier and do the fixme.reg and do the scans. I will let you know my progress. Thanks again for your time and energy helping me.
     
    Last edited: Sep 4, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer all of my questions about SpySweeper.

    You may want to try uninstalling it to make sure it is not causing your problem with the internet.

    Why can't you uninstall the Java programs? Be specific on what problems you are having? If you get error messages, give the exact error message.
     
  6. justpk

    justpk Private E-2

    Hi again, I am able to get on the internet with this computer. I will hopefully get the rest of the info for you.

    Java- I try uninstalling through add/remove and ccleaner it looks like it goes through, with the progress bar and all, but it never goes away. I try to delete entry thru ccleaner it says I can't delete MSI installer. I can't figure it out. No Spysweeper isn't the only anti spy ware, I have spybot s&d and now Super Antispyware remover. Does not include virus, or security suite, it is a paid copy. The computer was slow before installing. I had McAfee whicch included in with my ISP, but has to uninstall because of quarantine folder as I said previously.
    PHP:
     Originally Posted by justpk  View Post
    Also before I forget
    I installed Spy Sweeper to combat the Virtumondeit helped a little by blocking the internet29,026 times!!
    I meant by blocking the spyware from accessing the internet 29,026 times.

    The fixme.reg was successfully entered into reg. I am now going to run Ccleaner and the Mgtools and attach that log.

    One more thing, when I re-boot, a dos screen shows up and it reads c:\windows\system32\cmd.exe I think it has to do with my ISP desktop doctor. I will un-install that and see if it quits showing up. Be back shortly.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note Spybot without Teatimer & the free SUPERAntiSpyware provide no realtime protection. So your only realtime antispyware protection is Spy Sweeper. However you have no antivirus protection installed and no real firewall which is what I was driving at.

    What did you do to get your internet connection back?

    You never attached the follow up MGLogs.zip file I requested in message # 2. If you stopped due to the problem with uninstalling Java. Just skip the Java uninstall and continue with the rest of the steps.

    Also make sure you tell me if you still have any malware problems when finished.
     
  8. justpk

    justpk Private E-2

    I ran the Network setup in Control panel and it did the trick fixing the internet.

    I originally attached the MGLogs.zip in post 1. Are you needing a new one? If so I got the below error message.

    ProcessDLL.exe Application Error
    The application failed to initiate properly (0xc0000135). Click on ok to terminate the application.

    As I said in stated in previous post, I had to uninstall McAfee to do the run & read me first steps. I couldn't empty the quarantine folder, it kept locking up the computer. Maybe it wasn't the correct way to do it. But it was all I thought to do at the time.

    No real firewall? What would you suggest I get? I have re-installed McAfee and it found 2 pups
    1-PrcViewer , Filename: C:\MGtools\process.exe
    2-RemAdm-ProcLaunch!171, filename: C:\Documents and settings\administrator\desktop\combofix.exe

    They are still in McAfee should I delete them and re-install to finish the procedures?

    I am not sure I am having any more malware prob, except for the pups found in McAfee.

    Please know I really really appreciate your time in helping me.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is what I requested in msg # 2.

    This error was explained on the Using MGtools download page and it does not stop the rest of the scans from working.

    Does your McAfee program include one.

    These are no more PUPs than McAfee is. ;) They are valid programs. MGtools and ComboFix could easily say the same for McAfee. :)
     
  10. justpk

    justpk Private E-2

    Here is the new MGlogs.

    Yes McAfee has a firewall, it is set for standard.

    Fixed the .net.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then since you reinstalled McAfee you now have both an AV and a firewall. ;)

    Your logs are fine.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds