Malware help please....

Discussion in 'Malware Help (A Specialist Will Reply)' started by LauraJ, Jun 4, 2006.

  1. LauraJ

    LauraJ Private E-2

    I started with a problem with errorsafe and could not get rid of it. In the process of following all the directions on this site for malware removal before I posted asking for help - I got to the Microsoft Windows Defender and ran it. It found Virtumond and I selected it for removal. However no matter how many times I reboot my computer, everytime it starts up, it tells me it's still there, and each time I select to remove it - and each time it tells me I have to reboot. In addition - what was happening with the errorsafe was an additional internet explorer window opening every time I did anything in explorer - it was a blue errorsafe.com screen. Now, I still get the additional window, however it is a "page cannot be found" screen - and it's always trying to access ip address 83.149.105.143. So in order to even list this thread, it took me forever because everytime I click on any link - or to sign in - or anything at all - it opens an additional screen and takes me to that first. Can anyone help me? I have even tried a system restore to 2 weeks prior to the problem starting (just yesterday), and no matter what I do - it's still there. Should I uninstall the Windows Defender? It seems to have created more problems than I started with. Thank you in advance to anyone who'll answer!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Uninstall Windows Defender for now. But then run the steps from the below which are mentioned in the READ ME where it mentions Virtumonde.

    Virtumonde aka Trojan Vundo Removal

    Attach the VundoFix log when finished.

    Then complete the rest of the READ & RUN ME and attach the two logs from step 6 and your HJT log from step 7.
     
  3. LauraJ

    LauraJ Private E-2

    Thank you for your help - I ran everything else, however the bitdefender would not let me export the file - I could go through all the steps, it just wouldn't export. Also, I'm not sure Panda ran at all - I really can't tell - it said it downloaded and I clicked run, but then nothing happened. I did run hijack this - here's what I have - any help you can give me would be so much appreciated!


    Edit by chaslang: Inline HJT log attached
     

    Attached Files:

    Last edited by a moderator: Jun 5, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    VundoFix was the first step I asked you to run. You did not run it. Please run it and ATTACH the log. Please do not post any logs inline like you did with HijackThis. ALL logs must be attachments to your messages.

    I really need to see the Panda log. After you run VundoFix and ATTACH the log, then Try Panda again.

    You also did not follow the directions in step 7 of the READ ME. As a result you have HijackThis here:

    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    This is exactly how we specify not to run it. Please fix this now.

    You also did not run other steps in the READ ME. You missed uninstalling items given in step 0 (like O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe) also I do not see Windows Defender installed. And per the READ ME, if Windows Defender would not run, you were supposed to run CounterSpy and attach the log from it.

    Then attach a new HJT log.
     
  5. LauraJ

    LauraJ Private E-2

    I did run Vundofix - it told me no files were found infected - I just ran it again - I get the same message, so I don't know how to attach any log since there isn't one. I did run windows defender, but kept getting the error message on reboot, so you told me to uninstall it. I have run Panda but am unable to export the log - have tried everything I know to try. I apologize for sending the log incorrectly and missing the other step.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange because you definitely are infected with Virtumonde. What version of VundoFix do you have?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you mean "export"? Did you save the log to your PC? If so, all you nned to do is attach it using the instructions given in the READ ME.

    Did you uninstall Viewpoint Manager?

    Did you install HijackThis properly yet as requested in step 7 of the READ & RUN ME. If not, please do so before you move on to my next message which will contain a procedure to manually fix Virtumonde.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's use my older manual approach to fixing Virtumonde. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of pmnli.dll once and then click the kill button. After you have killed all of the pmnli.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above in the winlogon.exe process but look for noisles.dll (you may not find any cases of noisles.dll).


    Next double click on explorer.exe and again click once on each instance of pmnli.dll and kill it.

    Now repeat the above in the explorer.exe process for noisles.dll (you may not find any cases of noisles.dll).

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {b51e10e5-0a62-44f7-a70f-df83ee39a2ab} - C:\WINNT\system32\noisles.dll
    O2 - BHO: (no name) - {BDF90A20-C0DA-4FAE-95A2-AAA4D4D32B08} - C:\WINNT\system32\pmnli.dll
    O20 - Winlogon Notify: msupdate - msupdate32.dll (file missing)
    O20 - Winlogon Notify: noisles - C:\WINNT\SYSTEM32\noisles.dll
    O20 - Winlogon Notify: pmnli - C:\WINNT\SYSTEM32\pmnli.dll


    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    [/quote]
    REGEDIT4
    [-HKEY_CLASSES_ROOT\MSEvents.MSEvents]
    [-HKEY_CLASSES_ROOT\MSEvents.MSEvents.1]

    [-HKEY_CLASSES_ROOT\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{827DC836-DD9F-4A68-A602-5812EB50A834}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msupdate]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
    noisles]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnli]


    [/quote]
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\WINNT\SYSTEM32\noisles.dll
    C:\WINDOWS\SYSTEM32\ilnmp.ini
    C:\WINDOWS\SYSTEM32\ilnmp.ini2
    C:\WINDOWS\SYSTEM32\ilnmp.bak
    C:\WINDOWS\SYSTEM32\ilnmp.bak1
    C:\WINDOWS\SYSTEM32\ilnmp.bak2
    C:\WINDOWS\SYSTEM32\ilnmp.tmp
    C:\WINDOWS\System32\pmnli.dll


    If you find any other files in this folder that begin with ilnmpand end with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went. Doing this in normal boot mode does not always work. So we may have to retry again in safe mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds