suffering from Troj/Virtum-Gen

Discussion in 'Malware Help (A Specialist Will Reply)' started by jdizzle, Aug 4, 2009.

  1. jdizzle

    jdizzle Private E-2

    Hi,

    About a day ago I attempted to boot up the system but found that after typing in the password and pressing Enter the screen remained stuck on the blue log-on screen, perpetually saying I was being logged on. I forced the system to shut down, restarted, and attempted to log on again--with success. Some obvious virus symptoms quickly arose and I ran Sophos with the results showing this particular Trojan virus. I tried to handle it by managing the quarantine but ran another scan and found the virus still there. I managed the quarantine again and subsequently ran as extensive a scan as I could with the results showing no problems or threats. However, the symptoms (pop-up advertisements, sluggish performance, inability to load some web pages [Facebook]) persisted and I knew I had to find help elsewhere.

    I have done everything on the READ AND RUN ME FIRST guide and have logs from all five programs.

    I was initially have trouble installing SUPERAntiSpyware but was successful after renaming the file and placing in a location of my choosing.

    Here is the log from that scan:

    View attachment SASlog1.doc

    Here is the log from the Malwarebytes Anti-Malware scan:

    View attachment MBAMlog.txt

    After one of the first two scans (I can't remember which) and following a reboot, two error messages appeared saying something about not being able to run or find some module and I remember seeing .dll (Sorry I can't be more specific) This might not be anything important or significant.

    Here is the log from ComboFix:

    View attachment ComboFixlog.txt

    Here is the log from RootRepeal:

    View attachment RRlog.txt

    Log from MGTools in next msg:
     
  2. jdizzle

    jdizzle Private E-2

    View attachment MGlogs.zip

    I know your time is in high demand, and I greatly appreciate any assistance you can offer. Thanks.

    Most importantly, I should add that my computer seems to be running better than it did a day ago. The random pop-up advertisements seem to have ceased, performance is faster and I can once again view web pages that I couldn't before. I hope this means things are back to normal and the virus has been taken care of.
     
    Last edited: Aug 4, 2009
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like the scans took care of most of the malware.

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\sufaloju

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. jdizzle

    jdizzle Private E-2

    Thanks Tim.

    I did what you suggested.

    However, yesterday Sophos randomly displayed a message several times saying it had detected Troj/Virtum-Gen or components of it in:

    C:\System Volume Information\_restore{A8393674-085C-4723-B63E-39928C5F4C89}\RP313\A0128238.dll

    It is currently in Sophos' quarantine and Sophos claims it can clean it up, but as I noted in my first message, Sophos originally detected malware and indicated it had dealt with the problem when it hadn't.

    Suggestions?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you forget to do this step?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds