Removing "virtumonde" permanently

Discussion in 'Malware Help (A Specialist Will Reply)' started by danny123, Jun 8, 2008.

  1. danny123

    danny123 Private E-2

    So basically, a couple days ago my computer started acting up. Ex: windows explorer kept restarting by itself and my computer was just being really slow in general. So, i scanned my computer with spybot and it said i had something called Virtumonde. Now, i've looked at other threads and everyone says that this gave them popups etc. Although I didn't get any popups my computer was obviously affected because it was being really slow. Anyway, I removed it, restarted my computer, and everything seemed fine. But when I scanned again, it said that it was still on my computer. I tried scanning/removing it multiple times and it's still there. Is there anyway to get rid of it permanently? It's not really doing anything (my computer seems to be running fine) but I don't wanna get keylogged or anything dumb like that.

    Thanks in advance,
    danny
     
  2. danny123

    danny123 Private E-2

    *bump*
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to read the sticky thread posted in the forum. For example: Don't Bump! It Only Hurts You!!!

    And then the other important sticky which you should have read and run before posting:

    READ & RUN ME FIRST. Malware Removal Guide


    Please follow the instructions in the READ & RUN ME link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.
     
  4. danny123

    danny123 Private E-2

    all right will do when i get the time
     
  5. danny123

    danny123 Private E-2

    all seems good after doing the cleaning guide :) thanks!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but I strongly advise your to attach the requested logs as true Virtumonde infections will leave many traces on your PC and the tools will not find and remove all of them. Manual steps are always necessary.
     
  7. danny123

    danny123 Private E-2

    errr crap i already deleted everything. would there be a way to recover the logs? (i deleted all the programs too)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have things in the Recycle Bin, then you would have whatever is there. Anything else is gone. Did you actually uninstall and delete the folders from ComboFix?
     
  9. danny123

    danny123 Private E-2

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Follow the instructions for downloading, installing and running MGtools and then attach the requested MGlogs.zip file. If I still see anything in this, I will be asking you to run other scans.
     
  11. danny123

    danny123 Private E-2

    here are the logs (attached)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. You just need to do the below as requested in step 1 of the READ & RUN ME.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3


    Now reboot your PC

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Also do the below to cleanup from running the READ & RUN ME.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds