I have redirect / Virtumonde / System Scanner :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by mtell, Feb 19, 2011.

  1. mtell

    mtell Private E-2

    Hi,

    Description:
    My computer has a redirect and a system scanner in the tray that changes my desktop image and blocks certain things online. And gives warning of an infection with a fake scanner.

    Also when I go to a page like Amazon, it takes me to something like zigwagjet and some other unrelated pages.

    I have ran the ReadMe instructions, but it comes back again, so I need more professional help to get rid of it.

    Note:
    ComboFix can not complete - It freezes my system. It would not finish in ever 3 hours. So I have no log for ComboFix.

    RootRepeal finds 2 hidden/locked files, and I goggled what it says is locked and it says its related to Virtumonde. But I am not sure.


    Can you please help? Many thank you very much.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. mtell

    mtell Private E-2

    Also please see attached for the other logs.

    Thank you.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What RR found is not a problem.

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Tell me exactly what is inside of these folders but do not click on anything.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Still experiencing redirects?
     
  5. mtell

    mtell Private E-2

    Thank you, I set computer to normal.

    C:\Documents and Settings\Administrator\Local Settings\Application Data\{4CEB7BB7-D26B-4717-8B18-D459BE355B4D}
    >>>This is not on my computer anymore - I can not see it

    C:\Documents and Settings\All Users\Application Data\nBbImKd08200
    >>>Has one file in it called nBbImKd08200 - File has no extension - File size is 1KB


    Thank you, I did this and ran it fine.

    Thank you, I erased them.

    Thank you, please see attached.

    At the moment I am not, but I thought I repaired it myself with your FAQ, then it popped up again a day later...

    So can you please check to see if virus is gone? But so far computer looks great no redirect, or fake virus scan has come on.

    Thank you very much for your time and professional help to help me, I really appreciate it.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You can delete the below then.

    C:\Documents and Settings\All Users\Application Data\nBbImKd08200

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. mtell

    mtell Private E-2

    Thank you very much for helping me.

    Id like to make a donation, do you have that feature? I dont need to receive anything from the store.

    Thanks again.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)

    We do not accept donations per se however we do have the software store and the clothing store which offer many goodies!! :major Or just think of what we did as a gift. ;)
     
  9. mtell

    mtell Private E-2

    Okay, thank you very much for volunteering your time and knowledgeable professional service to help people which is very kind today!

    I will check out the clothing store...:)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I reccommend the hoodies. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds