Please help me get rid of this TrojanVirtum-gen!

Discussion in 'Malware Help (A Specialist Will Reply)' started by swennybear23, Oct 2, 2008.

  1. swennybear23

    swennybear23 Private E-2

    I came accross this thread (Troj/Virtum-gen) when google-ing how to get rid of this virus/spyware. It sounded like "abri" was able to help this gentleman "tomnewmark". I also have Sophos as my anti-virus and I get the same message "tomnewmark" recieved. I tried to follow the steps (Java, hijacker) that abri suggested, however, it seems like it was more personilzed for "tomnewmark" as the hijacker lines were different on my computer. I would greatly appreciate help with this as I am responsible for my Junior football teams e-mail updates. Thank you very much!


    ***After reading through the different threads I will do all of the read and run suggestions first and will attach logfiles as appropriate. However, this virus has completely disabled my desktop and I have been having to use task manager to run anything. Should I be doing this (taskmanager), or is there another way. Again, Thank you.
     
    Last edited: Oct 2, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If task manager is the only way, then yes.

    Are you able to get into safe mode and run them from there?
     
  3. swennybear23

    swennybear23 Private E-2

    Thanks TimW,

    Yes, I am able to get into Safe Mode and can run them from there. Do I need to turn off system restore temporarily when I do this? Thank you for your response. I will be able to work on my computer late tonight and will get that info to you ASAP!
     
    Last edited: Oct 3, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should not turn off system restore until we are finished.....and I await your logs. :)
     
  5. swennybear23

    swennybear23 Private E-2

    Hey TimW,

    I have been going through all of the steps for read and run and have ran into a couple of problems. First, I did not see a scanner logs section under SAS; and second, I have no idea how to temporarily disable my Sophos Anti-virus in order to properly run combofix. Everything else has been smooth and my computer is actually starting to run much better!

    I will await your reply before I proceed. Thank you.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should only have to right click the icon in the system tray and choose disable....though you may have to open the Sopho's control panel to do it.

    I you are unable to do that, skip Combo and continue with the rest. I need to see the logs. :)
     
  7. swennybear23

    swennybear23 Private E-2

    Hey TimW,

    Gosh I hope I did this right for you. I wasn't able to temp disable Sophos but ran the combo fix anyway, before I read your last post anyway, and it seemed to work. I guess the log will determine that?! I appreciate your help on this and please let me know if I need to do anything else.
     

    Attached Files:

  8. swennybear23

    swennybear23 Private E-2

    And these...
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    Drivers::
    logiflt
    
    File::
    C:\WINDOWS\system32\drivers\logiflt.iad
    
    DirLook::
    C:\Program Files\vghd
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
    Last edited: Oct 6, 2008
  10. swennybear23

    swennybear23 Private E-2

    Is this all I am supposed to copy? It doesn't scroll down any further when I click and drag?

    KILLALL::


    Drivers::
    logiflt

    File::
    C:\WINDOWS\system32\drivers\logiflt.iad

    Dir.Lookup::
    C:\Program Files\vghdto
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Exactly that....:)
     
  12. swennybear23

    swennybear23 Private E-2

    Hey TimW,

    Here are the logs. My computer froze up on me at the blue Windows is shutting down screen. I just held the button down to shutdown. Everything ran fine on startup, hopefully I didn't screw anything up:eek:
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what this is:
    C:\Program Files\vghd

    In the meantime:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Also tell me how things are running. :)
     
  14. swennybear23

    swennybear23 Private E-2

    That C:\Program Files\vghd was "virtual girl" desktop stripper my brother put on here a while back. Told him to take it off, I deleted the file to the recycle bin.

    I did get a successull prompt when running the fixME file. The computer is running better, still slow when opening programs (I-explorer), and slow upon start-up. It also at times freezes up temporarily when I am typing, as if a program was running in the background. The desktop appears to be stable, there are no consecutive popups. Internet explorer is fast between webpages for uploading/downloading time. I no longer recieve this message "Exception Processing Message0000013 Parameters 75b6bf7c 4 75b6bf7c 75b6bf7c" of which I asssume is good. I have not run Sophos or any other program to check if trojgen is still on, but also havent had any pop-ups from Sophos indicating it is still on the computer.

    I noticed this foler C:\QooBox, has a quarantine, snapshot, etc, inside of it. Not sure if it is legit or not. I will await your next directions, and again, thank you very much! Just FYI, before working with you, I downloaded Hijack program, in case we need to run it in the future.
     
    Last edited: Oct 6, 2008
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....it is the quarantine folder for ComboFix......

    New one on me....LOL

    Ok.....your slow problem should be addressed in the software section but I would suggest that you use a Startup Manager

    If you are not having any other malware problems, it is time to do our final steps:


    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below

      * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combo-fix folder from combofix.

    4. If we had you run Avenger, you can delete all files related to Avenger now.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    11. After doing the above, you should work thru the below link:

     
  16. swennybear23

    swennybear23 Private E-2

    Sounds great. Thanks a lot TimW, I truly appreciate it. Can I delete the WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe as well?
     
    Last edited: Oct 6, 2008
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds