pop-ups galore - cannot remove virtumonde

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by betenoire, Mar 24, 2007.

  1. betenoire

    betenoire Private E-2

    My girlfriend's computer seems to be infected with virtumonde, and probably a bunch of other stuff as well. She's getting pop-ups constantly, even when her browser window isn't open and her computer has slowed to a near halt.

    I walked her through the steps in "read and run me first" and am attaching the logs from the various scans.

    She was unable to run a scan using Counterspan because her computer froze up every time she tried. She did do one with AVG anti-spy, however.

    The Bit Defender scan detected the virtumonde - but was unable to remove it for some reason.

    She also ran the vundofix program - and while it says that it found and fixed the problem she's still getting the pop-ups.

    Help, please?
     

    Attached Files:

  2. betenoire

    betenoire Private E-2

    the last three logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Get started on the below while I look thru all of your logs and work up a fix.

    • Is your copy of AVG AntiSpyware a paid version? If not, uninstall it now!!
    • Is your copy of Spy Sweeper a paid version? If not, uninstall it now!!
    • Is your copy of Spyware Doctor a paid version? If not, uninstall it now!!
    • I also see Yahoo AntiSpyware and Windows Defender installed! Do you use and like Yahoo AntiSpyware?
    Similar to antivirus programs, having too many realtime malware blocking tools installed will cause many problems. It can make each program less effective, make it difficult to impossible to remove malware, and it will slow your PC down tremendously.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
     
  4. betenoire

    betenoire Private E-2

    - Uninstalled free copy of AVG anti-spyware.
    - Could not locate Spy Sweeper in her add/remove programs list. She has had it in the past so maybe some traces are left behind?
    - Spyware Doctor is a paid version - so she kept it.
    - She didn't even realise that she had Yahoo AntiSpyware on her computer. I told her I'm pretty sure it's bundled in with the Yahoo toolbar so I had her uninstall that (she's got Google toolbar anyway, so it was a bit redundant to have both. And I like Google MUCH better.)

    Okay, she downloaded and installed the newest Sun Java yesterday - I just got her to uninstall the 5.11 now.

    This is a bit hard/complicated because I'm doing all of this over the phone with her and I'm not physically looking at her computer or anything.

    Thanks so much for helping her out. I'm always sending people to you guys - I really appreciate what you do for people.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! We will remove them.

    According to the newfiles.txt log you posted, the new version was not installed yet

    If you think it was complicated on the phone before, wait until you start doing the below! ;)

    Start by downloading two tools we will need

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of byxxw.dll once and then click the kill button. After you have killed all of the byxxw.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    hgggedcr.dll

    Next double click on explorer.exe and again click once on each instance of byxxw.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    hgggedc.dll

    Next double click on iexplore.exe and again click once on each instance of byxxw.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    hgggedc.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - AÓ - (no file)
    O2 - BHO: (no name) - pAÓ - (no file)
    O2 - BHO: (no name) - rsion - (no file)
    O2 - BHO: (no name) - {0816E6B6-B239-4471-A722-3ADD70CD5E6E} - C:\WINDOWS\system32\byxxw.dll
    O2 - BHO: (no name) - {4D7C8A39-430F-4091-B9BF-3173DFA06DA0} - C:\WINDOWS\system32\hgggedc.dll
    O2 - BHO: (no name) - {6440EA15-B6F2-4E9C-953A-01EB6F8865A1} - C:\WINDOWS\system32\rqooo.dll (file missing)
    O2 - BHO: (no name) - {C20B22A6-E4CD-4BEF-ABC6-294229A9A58A} - C:\WINDOWS\system32\pmkkk.dll (file missing)
    O2 - BHO: (no name) - ¨Ó - (no file)
    O2 - BHO: (no name) - À@Ó - (no file)
    O2 - BHO: (no name) - Ø?Ó - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O20 - Winlogon Notify: byxxw - C:\WINDOWS\system32\byxxw.dll
    O20 - Winlogon Notify: hgggedc - C:\WINDOWS\SYSTEM32\hgggedc.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\bcbmdjld.dll
    C:\WINDOWS\system32\byxxw.dll
    C:\WINDOWS\system32\hgggedc.dll
    C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
    C:\WINDOWS\system32\bcbmdjld.dll
    C:\WINDOWS\system32\hgggedc.dll
    C:\WINDOWS\system32\wxxyb.bak1
    C:\WINDOWS\system32\dljdmbcb.tmp
    C:\WINDOWS\system32\wxxyb.tmp"
    C:\WINDOWS\system32\dljdmbcb.ini
    C:\WINDOWS\system32\dljdmbcb.ini2
    C:\WINDOWS\system32\wxxyb.ini
    C:\WINDOWS\system32\wxxyb.ini2
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. betenoire

    betenoire Private E-2

    We were unable to do this part, as there wasn't an iexplore.exe in there. I even had her read the list out to me and it just wasn't there. But the rest of the stuff in Process Explorer went fine.

    This happened with KillBox.

    Anyway, the pop-ups are still happening. Did we/she miss something in my bumbling over the phone instructions?

    New logs attached.
     

    Attached Files:

  7. betenoire

    betenoire Private E-2

    Okay, I figured out why she couldn't find iexplore.exe in Process Explorer - she didn't have that browser open. Give us a second - I'll get her to repeat that step.

    Sorry. And thanks for your help/patience.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well some new infections showed up too so it will take at least another round of fixes. Sometimes this happens if a fix is not perform properly the first time or if something is missed in the procedure. We will get it eventually. Becareful not to perform any other reboots except when requeted. These infections spread and mutate at reboot.

    After you attach the next set of logs we will continue. DO NOT REBOOT after attaching the logs. Even if you have to wait until tomorrow to continue, leave the PC running until then.
     
  9. betenoire

    betenoire Private E-2

    Okay, re-ran Process Explorer with IE open. There were no instances of either of the dll's we were looking for in the iexplore.exe threads. No idea what's going on now as she's still getting popups. Ugh.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I guess you missed message # 8.

    I'll work up another procedure based on the logs you attached in message # 6
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First uninstall Windows Defender & Yahoo AntiSpyware since you have a paid copy of SpyWare Doctor running. Do this now before continuing!!

    Be careful when looking for filenames in Process Explorer. Some of the below are different than last time and I added some more to check for.

    Make sure you have rebooted in Normal Mode (do not open any other processes)
    Also make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of hgggedc.dll once and then click the kill button. After you have killed all of the hgggedc.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkifr.dll
    bcbmdjld.dll
    byxxw.dll

    Next double click on explorer.exe and again click once on each instance of hgggedc.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkifr.dll
    bcbmdjld.dll
    byxxw.dll

    Next double click on iexplore.exe and again click once on each instance of hgggedc.dll and kill it. (If you do not find the dll, just continue on.)

    Now repeat the above step for the below DLLs (If you do not find the dll, just continue on):
    pmkifr.dll
    bcbmdjld.dll
    byxxw.dll

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {4D7C8A39-430F-4091-B9BF-3173DFA06DA0} - C:\WINDOWS\system32\hgggedc.dll
    O2 - BHO: (no name) - {D37CF8FB-9AEA-414C-81C9-5175586F6478} - C:\WINDOWS\system32\pmkif.dll
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O20 - Winlogon Notify: hgggedc - C:\WINDOWS\SYSTEM32\hgggedc.dll
    O20 - Winlogon Notify: pmkif - C:\WINDOWS\system32\pmkif.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me later whether you get a success message on adding this into the registry. This is important!!

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\pmkif.dll
    C:\WINDOWS\system32\hgggedc.dll
    C:\WINDOWS\system32\bcbmdjld.dll
    C:\WINDOWS\system32\byxxw.dll
    C:\WINDOWS\system32\fikmp.bak1
    C:\WINDOWS\system32\wxxyb.bak1
    C:\WINDOWS\system32\dljdmbcb.tmp
    C:\WINDOWS\system32\wxxyb.tmp
    C:\WINDOWS\system32\dljdmbcb.ini
    C:\WINDOWS\system32\dljdmbcb.ini2
    C:\WINDOWS\system32\fikmp.ini
    C:\WINDOWS\system32\wxxyb.ini
    C:\WINDOWS\system32\wxxyb.ini2

    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    Now run ATF Cleaner again!!! Be sure that you DO NOT skip this!!!!!!!!

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. betenoire

    betenoire Private E-2

    Okay - re-ran the whole procedure again.

    Some of the dll's had returned to the explorer.exe threads in Process Explorer - so they were removed again.

    Ditto some of the lines had returned to HJT - fixed again.

    Re-did the steps from Pocket Killbox - this time we didn't get the "PendingFileRenameOperations" prompt. But it rebooted the computer automatically - I hope that doesn't cause any problems?

    Ran ATF cleaner - no problem. Both times there weren't any cookies/whatever to remove from IE because I've gotten her to stop using that browser. Firefox cookies/etc were removed.

    Three new logs! (and still getting pop-ups)
     

    Attached Files:

  13. betenoire

    betenoire Private E-2

    Yeah, I always seem to be in the process of composing a reply when you're posting yours.

    So that last set of logs was in responce to message 8. We'll now go ahead and follow the steps in message 11.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes run message # 11 even though some items may no longer be there. Just keep going all the way thru.
     
  15. betenoire

    betenoire Private E-2

    Windows Defender has been uninstalled. We can't find Yahoo AntiSpyware on the computer, so that's not been removed. We checked both add/remove programs and the start menu for something referencing it and we're still not finding it. Sorry!

    Process Explorer:

    In winlogon.exe there were no instances of hgggedc.dll. Also none of pmkifr.dll - although there were some pmkif.dll. We didn't kill those. Also no bcbmdjld.dll or byxxw.dll.

    In explorer.exe there were no instances of hgggedc.dll. Also none of pmkifr.dll - although there were some pmkif.dll. We didn't kill those. Also no bcbmdjld.dll or byxxw.dll.

    In iexplore.exe there were no instances of hgggedc.dll. Also none of pmkifr.dll - although there were some pmkif.dll. We didn't kill those. Also no bcbmdjld.dll or byxxw.dll.

    Hijack This:

    O2 - BHO: (no name) - {4D7C8A39-430F-4091-B9BF-3173DFA06DA0} - C:\WINDOWS\system32\hgggedc.dll - not present
    O2 - BHO: (no name) - {D37CF8FB-9AEA-414C-81C9-5175586F6478} - C:\WINDOWS\system32\pmkif.dll - not present, although a line with different number/letter combo WAS there ending with C:\WINDOWS\system32\pmkif.dll - should we fix that?
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide - not present
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" - fixed
    O20 - Winlogon Notify: hgggedc - C:\WINDOWS\SYSTEM32\hgggedc.dll - not present
    O20 - Winlogon Notify: pmkif - C:\WINDOWS\system32\pmkif.dll - fixed

    Fixme.reg:

    Got a sucess message.

    Pocket Killbox:

    Done. Got PendingFileRenameOperations prompt. Did not reboot.

    ATF Cleaner:

    Done. For both "main" and "Firefox".
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry my mistake! A cut & paste typo! I left the extra 'r'. It was pmkif.dll

    And the HJT line are:
    O2 - BHO: (no name) - {C1A2E334-32E3-464C-8B86-C73E10864E38} - C:\WINDOWS\system32\pmkif.dll
    O20 - Winlogon Notify: pmkif - C:\WINDOWS\system32\pmkif.dll

    Try the procedure again using that file name and those HJT lines!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way the Yahoo AntiSpyware may be hooked into something else from Yahoo! I see all of the below in your newfiles.txt log:

    Yahoo! Anti-Spy
    Yahoo! Browser Services
    Yahoo! Install Manager
    Yahoo! Internet Mail
    Yahoo! Messenger

    Do you see any of these in Add/Remove Programs?
     
  18. betenoire

    betenoire Private E-2

    Okay, steps repeated. New logs attached.

    All of the Yahoo! stuff aside from Messenger should be gone now. We hope.
     

    Attached Files:

  19. betenoire

    betenoire Private E-2

    p/s -

    Still getting popups and popup attempts. Spyware doctor keeps giving notices that it's blocked a bad site.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's because a few of the bad files I've been asking you to delete, are not getting deleted. Let's try again.


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\pmkif.dll
    C:\WINDOWS\system32\fikmp.bak1
    C:\WINDOWS\system32\wxxyb.tmp
    C:\WINDOWS\system32\fikmp.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.
    After reboot run Windows Explore and double check to make sure that the below files have been deleted. If not, delete them manually.
    C:\WINDOWS\system32\pmkif.dll
    C:\WINDOWS\system32\fikmp.bak1
    C:\WINDOWS\system32\wxxyb.tmp
    C:\WINDOWS\system32\fikmp.ini

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    I would bet that the PC is running a lot faster than when you first started this thread!
     
  21. betenoire

    betenoire Private E-2

    Done, done, and done. We didn't have to manually remove anything - as pocketkillbox worked this time around.

    New logs are attached. Still getting the notices from spyware doctor that it's blocking malicious websites.

    Thanks!
     

    Attached Files:

  22. betenoire

    betenoire Private E-2

    The computer in general is running back up to it's normal speed now, and the blocked website alerts are only happening when we visit a certain website. We've been going there for 5 years now and have never had any sort of problems or pop-ups from them until the last few days. Should I contact the webmasters there? Is a pop-up block alert cause for alarm, because I'm not sure that it is.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You'll have to be more specific and even attach a log!

    Again specifics are required. If popups are being caused due to the site you are accessing sending popups then that is not necessarily malware. It is just popups.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds