Kill box can't delete the file.

Discussion in 'Malware Help (A Specialist Will Reply)' started by section_8, Jul 7, 2008.

  1. section_8

    section_8 Private E-2

    I have a computer here that is infected by Virtumonde and Smitfraud c. I so far have run Spy Bot S&D which got rid of Smitfraud but not V-monde. SB S&D recomended that I get rid of Virtumonde (& Virtumonde.dll) by using Kill box to delete the file. There seems to be 2 files in particular that need to be "off-ed", but when I use killbox to delete it says it could not delete the file and when I try to "delete on reboot" it goes through the 9 seconds until reboot and then tells me the data has been changed by an external source, and nothing happens. Can someone tell me what else I can try to get killbox to kill these 2 files...? (now 3 files)

    here is the HJT log:
    (Brief)
    O2 - BHO: (no name) - {5216BC01-B8DD-4E48-B96E-77710E54016B} - C:\WINDOWS\system32\qoMcyVPg.dll
    O20 - Winlogon Notify: qoMcyVPg - C:\WINDOWS\SYSTEM32\qoMcyVPg.dll

    The other file that kept arising is C:\WINDOWS\SYSTEM32\hgGvuVmJ.dll,c
    But you would only find hgGvuVmJ.dll.old in the system32 folder.
    I killed the rundll32 process with Process Explorer but it just started back up with another command name opnnnnNFw.dll,c


    Here is the whole log....
     
    Last edited by a moderator: Jul 7, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please uninstall HJT as it will be properly installed when you do the following:

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. section_8

    section_8 Private E-2

    My apologies for not looking at that first... It took some doing still but it did work. Everything seems fine now.

    You guy's rock!!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are sure all the malware is gone ...safe surfing.

    If you are uncertain, please attach the requested logs. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds