Problem with VundoFix.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jack Hamlyn, May 31, 2006.

  1. Jack Hamlyn

    Jack Hamlyn Private E-2

    Hello,
    I am trying to get rid of what Ad-Aware reports as "Virtumonde". It says that it has removed it, but it is right back every time I run Ad-Aware. I downloaded the VundoFix program from your website, but when I check the run as task box, it never re-opens. When I just click the scan for vundo button, it finds several files in windows\system32 (pmnli.dll, ilnmp.ini, ilnmp.bak1, & ilnmp.bak2), but I just close the progam then. Am running XP Pro SP2. What could cause the program not to re-open?
    Can I just click the remove vundo button without running as a task?
    Thanks for your help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    First a note: Ad-Aware cannot fix Virtumonde!

    You may have other malware causing problems for VundoFix. Let's find out.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. Jack Hamlyn

    Jack Hamlyn Private E-2

    Hello again,
    Yes it was obvious that Ad-Aware was not fixing the problem, that's why I was using VundoFix. I had already been through running all the tests/scans from the sticky thread and I was trying to fix the problem without bothering you - it looks like you have plenty to do already! So I ran everything again and saved logs where possible. Here are the results:

    Run from safe mode.
    CCleaner - see attached
    MWMSRT full scan - nothing found
    Ad-Aware full scan - see attached
    Spybot - see attached
    MW Defender full scan - nothing found
    CWShredder - nothing found
    Kill2Me - doesn't report if anything found

    Run from safe mode with network support.
    Bitdefender - see attached in next reply

    Run from normal mode.
    Panda ActiveScan - see attached in next reply
    Hijack This - see attached in next reply

    Thanks again for your help.
     

    Attached Files:

  4. Jack Hamlyn

    Jack Hamlyn Private E-2

    Other 3 log files.
    Thanks
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's use my older manual approach to fixing Virtumonde. Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.
    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of pmnli.dll once and then click the kill button. After you have killed all of the pmnli.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of pmnli.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.pagesubmit.com/search/side.shtml
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    O2 - BHO: InfoDocReader Object - {A5B00A5B-073E-4246-AFF0-CCAE0D5BF6D1} - C:\WINDOWS\system32\pmnli.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O20 - Winlogon Notify: pmnli - C:\WINDOWS\system32\pmnli.dll


    Copy the bold text below to notepad. Save it as fixVundo.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.

    C:\Documents and Settings\Jack H\Local Settings\Temp\nsh5.tmp
    C:\Documents and Settings\Jack H\Local Settings\Temp\nsh4.tmp
    C:\WINDOWS\backup\TB040923.DAT

    C:\WINDOWS\SYSTEM32\ilnmp.ini
    C:\WINDOWS\SYSTEM32\ilnmp.ini2
    C:\WINDOWS\SYSTEM32\ilnmp.bak
    C:\WINDOWS\SYSTEM32\ilnmp.bak1
    C:\WINDOWS\SYSTEM32\ilnmp.bak2
    C:\WINDOWS\SYSTEM32\ilnmp.tmp
    C:\WINDOWS\System32\pmnli.dll

    If you find any other files in this folder that begins with ilnmp and ends with any other extension ( the .ini is an an extension) delete them to.

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now attach a new HJT log and tell me how the steps went.
     
  6. Jack Hamlyn

    Jack Hamlyn Private E-2

    Hello again,
    I followed your instructions and everything went smoothly. I am attaching the new HJT log as requested. I have just gotten online to post this and have no pop-ups yet, but we'll see as time goes on. This kind of crap seems like extortion to me, where some company puts this junk on your computer and then pops up ads for you to buy their software to remove it! 99% of the pop-ups were from anti-virus/anti-spyware software companies! Coincidence?
    Much thanks for your help.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not a coincedence. There are close to 300 rogue tools out there and more being added to a list all the time. This rogue list is mentioned at the end of step 5 on the below link.

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds