MGTools logs attached; Virtumonde

Discussion in 'Malware Help (A Specialist Will Reply)' started by djhamham, Dec 19, 2008.

  1. djhamham

    djhamham Private E-2

    I ran the MGTools.exe and have attached my logs. I appreciate your help in getting rid of this Virtumonde virus. My Symantec Anti-Virus and SpySweeper have not done the job.
     

    Attached Files:

  2. djhamham

    djhamham Private E-2

    Got an error message:

    "The application failed to initialize properly (0xc0000135). Click on OK to terminate the application."

    So I re-ran MGTools.exe and attached the MGlog files after I saw I was still getting pop up ads that take over my browser.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  4. djhamham

    djhamham Private E-2

    Read me Run Me First done, logs attached

    Ok, I followed the steps. My logs are attached. Computer seems to be running better.

    One note: SAS did not seem to remove ocvmse.dll correctly. After reboot, I kept getting an error message that I had to click OK on about 20 times to get through to the screens I was trying to get to - it kept complaining about ocvmse.dll. Stupid me thought it must be a needed system file that should not have been touched so I restored it (doh!). I now know better.

    Fortunately, Malwarebytes or Spybot seemed to remove it cleanly so the error message did not recur.

    I hope my logs look good. Thanks for your help.
     

    Attached Files:

  5. djhamham

    djhamham Private E-2

    Read and Run Me First done; Message II with 4th log

    Here is the last log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Important Notice: A new version of SUPERAntiSpyware is out that should help with this problem from Vundo.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
    Note: You have both Spyware Doctor and Spy Sweeper installed. I recommend that you uninstall one of these immediately. This can be just as problematic as installing multiple antivirus programs.

    Now uninstall Java(TM) 6 Update 7


    What is drive E? Look for the below folder and file on it and another drives and delete them if found. Also if E is removable drive and has been used on other PCs, those PCs may be infected.

    e:\resycled\boot.com

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - AutorunsDisabled - (no file)
    O24 - Desktop Component 0: (no name) - (no file)

    After clicking Fix, exit HJT.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • don't forget the two new SUPERAntiSpyware logs
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 22, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds