How do I remove win32\virtumone.0

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mike703, Aug 13, 2007.

  1. Mike703

    Mike703 Private E-2

    Hi
    Could you please help me remove Trojan. Win32\Virtumonde.0

    Have followed all instrutions from your Malware removel guide.
    It seems to have stopped Norton Internet Security from showning
    pop ups - (Blocked - Trojan.Nebuler & Infostealer.Ldpinch) and the ad pages
    that were poping up.

    My problem now is about 5mins after bootup Windows defender shows
    Trojan.Win32\Virtumonde - reboot to protect your system.
    Also Virtumonde shows in Spy Bot scan - can not remove it.

    Have attached all files as requested - your help would much appreciated.
    Thanks for great site and the time you guys put in helping kill these things.
    Regards
    Mike
     

    Attached Files:

  2. Mike703

    Mike703 Private E-2

    Here are the other 3 files.
    Thanks
    Mike
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please re-run Counterspy and have it delete/quarantine everything it finds ...it does no good to just let it detect problems...you need to have it fix those items!


    Download this file - Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRUn
    HJT
    Avenger
    ComboFix
     
  4. Mike703

    Mike703 Private E-2

    Hi Tim
    Thanks for such prompt reply.
    OK! Ran Counterspy:
    Detected: Virtumonde - Adware - 7 objects
    Registry: Trojan. win32.agent.vg - 18 objects

    Followed all other instructions - PC feeling better already.
    Will attach Files - thanks again for your time.
    Mike

    Having a problem adding New Logs.
    Getting a message - administrator has banned I P address
     
  5. Mike703

    Mike703 Private E-2

    The Files
     

    Attached Files:

  6. Mike703

    Mike703 Private E-2

    And the other 2 files.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Start -> Run -> cmd (press 'Enter')

    At the prompt...

    sc stop VundoFixSvc
    sc delete VundoFixSvc
    exit

    Now you can reboot and Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRUn
    HJT
    Avenger
     
  8. Mike703

    Mike703 Private E-2

    Hi - Need to check something with you.
    Start - run - cmd - enter. I get C:\documents and settings\mike>_ flashing curser. Do I need to change dir. before entering (sc stop vundofixsvc sc delete vundofixsvc)do I need to press enter after each line. Sorry not to good with the dos thing.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you do not need to change directories before entering the commands and each line is a separate command which means a carriage return is entered after each command.
     
  10. Mike703

    Mike703 Private E-2

    Thanks
    PC is much faster and no longer getting Windows defender pop up.
    Here are my new logs.
     

    Attached Files:

  11. Mike703

    Mike703 Private E-2

    And one more
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run avenger.exe one more time by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:
    Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Please attach a new log for:
    Avenger
    ShowNew

    Tell me how things are running before we do our final cleanup!:)
     
  13. Mike703

    Mike703 Private E-2

    Hi Tim
    Thanks again for your time.
    PC is feeling like new.:D
    Sorry for delay in reply - living down in Cape town South Africa.
    Think we have a 8 Hr time. Ever come down this way the beer is on me - and it's good.

    Here are the logs
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK...the avenger fix didn't run correctly ...are you sure you did it exactly as instructed?

    You can uninstall Counterspy .....if you do the avenger fix again and the log shows the same error ...use windows explorer to find and delete those two files ....let me know if you are able to do that.
     
  15. Mike703

    Mike703 Private E-2

    Ok!
    1: Unistalled CounterSpy.
    2: Ran avenger - removed fewglvfl.temp but not ldr3c8.temp
    3: deleted ldr3c8.temp in windows/system 32
    4: attch. new avenger log
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Avenger didn't remove either of them ....check to see if they still exist in the system32 folder ....
    Otherwise...(after removing those two items)..Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  17. Mike703

    Mike703 Private E-2

    Hi Tim
    Files in system 32 folder clean.
    everything is running 100% -I Thank you.
    Mike

    will now do final steps.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know ...safe surfing!!:)
     
  19. Mike703

    Mike703 Private E-2

    Thanks for your help!!!
    Go well.
    Mike
     
  20. Mike703

    Mike703 Private E-2

    Sorry!
    One last question.
    Will Norton Internet Security 2007 stop this from happening again?
    or is that like wishfull thinking?rolleyes
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First off...Norton is a resource hog ...(I never pay for any anti-virus or anti-spyware)
    Second...no anti-virus is 100%
    One's surfing habits is more than likely the cause of most viruses (that and P2P software).
    It would be best to follow the suggestions in the How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds