Troj Virtum Gen Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by ctesias, Jul 7, 2008.

  1. ctesias

    ctesias Private E-2

    Hi

    I have been trying for over two weeks to get rid of this malware and would really appreciate some help. I use Sophos as my main anti-virus software (which says it can fix it but doesn't) and have also tried AVG and other products without success.

    I have followed your instructions with regards to the MGTools and attach what I hope are the relevant files: runkeys.txt, newfiles.txt and and Hijackthis.txt. I did look for the MGlogs.zip file but for some reason it wasn't created (I tried twice). I looked for GetUnKey.txt, but of the new files created when I ran MGTools the only other files I found were procdll.txt and sysinfo.txt - please let me know if you need these too.

    I hope these contain sufficeient information for someone to tell me what to do.

    By the way, I did try adding this to an existing post but the forum said I didn't have sufficient privileges!

    Many thanks

    Ctesias
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You did not run ComboFix, Super-Antispyware or Malwarebytes....I need to see those logs and then you can run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    The log is right where the instructions say it will be:
    C:\MGLogs.zip
     
  3. ctesias

    ctesias Private E-2

    Tim

    You're absolutely right - I hadn't spotted the detailed malware removal process for XP, but I have now run this.

    In summary, it seems to have got rid of Virtum (and a number of other things besiides) but it would be very helpful if you could confirm that. I did run Sophos after producing the attached logs and found Virtum but I wasn't sure if that was because it was quarantined from earlier. Anyway when I ran Sophos cleanup it did delete Virtum (unlike previously) including a couple of files that were removed on reboot. Since then it all looks good. I have now installed AVG 8.0 Free instead of Sophos and am getting clean scans.

    The first time I ran Combofix I neglected to put the killall string into the Run field (see file 'Combofix log') so I ran it again with the string (see file 'Combofix log2'). Note that XP would not let me edit the exe to combo-fix.exe so I renamed it combo00fix.exe - I edited the string too. Does this have any ramifications when it comes to removal?

    The files are attached to this reply and to the next reply also. By the way, this is an awful lot of data to make public (although it look failrly anonomous) so I'd like to know how to remove them once you've given me the all clear.

    Thanks for your help

    C.
     

    Attached Files:

  4. ctesias

    ctesias Private E-2

    Re: Troj Virtum Gen Removal (Additioal Files)

    Please see other files attached.

    Thanks

    C.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The scans did get most of it. Let's do this:

    Please disable the guest account in user accounts.

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\BM9bbed35d.xml
    C:\WINDOWS\BM9bbed35d.txt
    C:\WINDOWS\SYSTEM32\pqzmds.dll
    C:\WINDOWS\SYSTEM32\dgapirxo.dll
    C:\WINDOWS\SYSTEM32\tmp132.tmp
    C:\WINDOWS\SYSTEM32\hhbswhyg.tmp
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.
     
  6. ctesias

    ctesias Private E-2

    I have completed all the actions detailed in your e-mail and attached the log files requested.

    Hope this does the trick!

    Thanks again.

    C
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you re-run the C:\MGtools\GetLogs.bat file by double clicking on it after doing the fix?

    ComboFix log is showing the removal of items in my fix, but the MGLogs.zip is not. Possibly because it is:
    It's Tue July 8, 2008 08:04:39 AM
     
  8. ctesias

    ctesias Private E-2

    Hasn't GetLogs.bat just rezipped some of the logs from the earlier run of MGTools - shall I run MGTools again from scratch?

    C
     
  9. ctesias

    ctesias Private E-2

    I rushed my last reply - yes I did run GetLogs.bat but having checked the zip file (which is datestamped 18.41 today), I can see that it appears to have zipped the files that were created when I ran MGTools on July 8th.

    Please let me know what I should do next.

    Thanks

    C.
     
  10. ctesias

    ctesias Private E-2

    Hi Tim

    End of the day here so I have run MGTools again and attached zip - hope this was a good call.

    Regards

    C
     

    Attached Files:

  11. ctesias

    ctesias Private E-2

    ...being precise, I ran MGtools.exe..
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That was the ticket! :) ......Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2. Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox ( or whatever you renamed it to) and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  13. ctesias

    ctesias Private E-2

    Tim

    That's excellent - thanks very much for your help :-D.

    I'll now work through the protection post!

    C
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're very welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds