Need HELP please.. Virtumundo and others

Discussion in 'Malware Help (A Specialist Will Reply)' started by papersun, Jul 23, 2006.

  1. papersun

    papersun Private E-2

    New here.. HELLO!!

    Working on a friends computer (that ran with no antivirus!!!) needless to say, it had some major problems. Ive noticed several trojans and malware issues. Some I believe I have taken care of others I havent.

    I have followed the instructions of the "Run Me First" thread. I have the BDscan log but not the log from Panda. Panda showed now problems and did not give me the option to save log. I will attach the bdscan as well as a hjt log. I am running 2 computers so I am able to be connected to internet as well as work on the problem computer. Thanks and look forward to fixing things up on this end.

    Rob
     

    Attached Files:

  2. papersun

    papersun Private E-2

    would also like to add that when i run adware scans now i still receive errors for virtumundo in my registry. that has been very consistant throughout the process.
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Empty the Trend Micro Housecall Quarantine folder.
    Empty the Recycle Bin

    << The installed version of Java on this compter is out-dated. Install version 1.5.0_07 available from http://www.java.com/en/download/manual.jsp. Uninstall all older versions of Java on your computer, before installing the latest version of Java. >>

    Windows Messeger is running in the background on this computer, and represents a security risk. Disable Windows Messenger by running Shoot The Messenger. If you are using this as your IM client then replace it with MSN Messenger.

    Now Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  4. papersun

    papersun Private E-2

    ok Shadow . I did as you said. Here is the new hjt log
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The HijackThis log is clean.

    How is the computer running?
     
  6. papersun

    papersun Private E-2

    i ran the trend micro again and the same 4 registry alerts showed up. ill delete them. and run it again a few secs. later and they reappear. computer runs better every time i have tried something with it. believe me.. it was a mess!! had a high school daughter using it ..
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Attach the Trend Micro log, so I can see what it is finding.
     
  8. papersun

    papersun Private E-2

    here u go.. hope this helps out
     

    Attached Files:

  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Tred Micro Anti-Spyware, really isn't that good of a tool. SPyvbot is by far better.

    Follow the directions for Running WinPfind by OldTimer.

    If there is something in teh registry that needs to be dealt with WinPFind will show it.

    Post WinPFind.txt when finished.
     
  10. papersun

    papersun Private E-2

    ok.. thanks for the info..here is the new log
     

    Attached Files:

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    WinPFind shows no registry entries that need to be removed.

    Boot to Safe Mode.

    Delete teh following files:
    C:\WINDOWS\ss3unstl.exe
    C:\WINDOWS\SYSTEM32\0svvohat.ini
    C:\WINDOWS\SYSTEM32\bg2u20p6.ini
    C:\WINDOWS\SYSTEM32\k9151576.ini
    C:\Documents and Settings\brad greathouse\Application Data\PFP120JCM.{PB
    C:\Documents and Settings\brad greathouse\Application Data\PFP120JPR.{PB


    Reboot.

    Lets flush all your restore points and create a new clean one for your system.

    Disable And Enable System Restore
    How to Protect yourself from malware!

    Safe surfing.
     
  12. papersun

    papersun Private E-2

    thank u very much!!!
     
  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds