I knew it was there...Virtumonde.sdn

Discussion in 'Malware Help (A Specialist Will Reply)' started by bigtrucks, Apr 28, 2009.

  1. bigtrucks

    bigtrucks MajorGeek

    I knew I had something it just never showed up until now. I've had it unplugged as I was working on my friends Dell. Hooked mine EMachine Winxp back up and let it up date then ran Spybot S&D first that's when i spotted the Virtumonde.sdh. I plan on doing the R&R me 1rst but I need to know if I can tic the Fix Selected Problems button before going on ?
    BTW I also ran MBAM it showed nothing.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Of course......fix what it finds! :) Do that with all scans.
     
  3. bigtrucks

    bigtrucks MajorGeek

    Thanks! I'm on my way. see ya later with the logs.;)
     
  4. bigtrucks

    bigtrucks MajorGeek

    Well all righty then.. I'm here with my logs. Wasn't easy but I finally defeated:strong the ComboFix. The third time Was the charmer;) Any who.. My AVG refused to let me into the virus vault, but I was able to disable it before runing CF. SAS showed nothing that I could see in the logs but I'm not the malware expert(although I wouldn't mind learning to help others) I already had MBAM installed BUT of course it kept messing up. Uninstalled and then installed a fresh, nothing showed in the logs. COMBOFIX.... yeah it knows who the boss is now:-D Pop up "Boot partition cannot be enumerated correctly" while trying to check for recovery console which wasn't there. Ran the scan threw.(I got to see what my desk top looked like with out Icons).No task bar (not even from the key board) had to Alt>Ctrl>Del then hit run new task every time I needed to do something. Tried to run CF that way , (didn't know if restarting would mess things up).Before running CF I tried dragging the Recovery Console to CF while still in windows file .No luck. Restarted then went on with MGTools finished that and took another stab at CF, that's when it kicked in. The time never changed. Is this just a random thing that CF dose or was I just lucky.?Anyway here's the logs
    Do you want me to attach the SpyBot log as well. That's who caught the nastie. Thanks for your help.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what was found, but your logs are clean. The only question I have is if you know what this is:
    C:\WINDOWS\thousand.ini

    If you don't, you could rename it to C:\WINDOWS\thousand.ini.old and see if you have some problems running your programs.

    Your main problem that I see is this:
    Total Physical Memory 256.00 MB
    Available Physical Memory 25.99 MB

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. bigtrucks

    bigtrucks MajorGeek

    Yes it's a program for legal letters. I have the disk for it just haven't gotten around to saving the doc's so I can uninstall it.That will be on my clean out list starting Mon night . I was wondering if I can remove some of my files that I thought I had uninstalled but I see they are lingering in the C:\files..ie C:\TCL\100games is a game I downloaded from disk and have uninstalled it a long time ago,games I downloaded from the net and don't bother with any more.?

    While looking in there I found these files that I'm not familiar with.
    1.c:\KPCMS created 04--1-09 size 0
    1. c:\itouch_crash_info.txt created 12-11-08 acc.04-29-09 size 0 size on disk 4. KB
    3. c:\itouch.log created 12-11-08 size 171 bytes
    4. c;\playground.log When I clicked on it I received this Note pad
    View attachment playground.log
    I googled it and came up with this http://nl.tallemu.com/oasis2/file/playfirst__inc_/unspecified_product/trijinx_exe/72220
    Is this something I should get rid of . I won't take any action on anything until I here back from you.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can safely remove all that junk. :)

    But do look into getting more Ram for your system.
     
  8. bigtrucks

    bigtrucks MajorGeek

    Thank You very much Tim for the help. I will take care of that Ram as soon as I can.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds