Trojan Win32/Adaware.Vitumonde removal problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by mann303, Aug 29, 2008.

  1. mann303

    mann303 Private E-2

    Please can you help. I was infected by the above a week ago. I have tried to run your programs for cleanup but I can not update the definitions as it won't connect to the internet. My AVG 8.0 can not uopdate. I belief the virus has been removed but nothing is working properly. Spybot can't install as it tries to download files from the internet. Malware finds things but the application hangs when you try to remove the items. But there are items in the quarantine section. Please can you help as I am at my wits end. Thank you.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Don't worry about updating the definitions at this moment....just try to run the scans. Note the below instructions for using safe mode.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide


    Note:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. mann303

    mann303 Private E-2

    Thanks for the info re scanning in safe mode. That has worked and I have run all the programs and removed alot of items. the computer seems fine now and is connecting to the internet without any problems. Thank you for your help and the information on this site. Fingers crossed everything is fine now.Had computer 4 years and never had a problem to now.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you ran the scans, please attach the logs so I can be sure there are not items still needing manual removal. :)
     
  5. mann303

    mann303 Private E-2

    Will do. As soon as possible as not at home at moment. Thank you
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...I'm not going anywhere ....:cry
     
  7. mann303

    mann303 Private E-2

    Hi Thanks for being patient My computer has an AMD Athlon 64 3200+ processor. Please find attached the logs as requested.Thanks once again.
     

    Attached Files:

  8. mann303

    mann303 Private E-2

    4th file as requested
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like the scans took care of most of it ...let's just do this:

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 7"
    J2SE Runtime Environment 5.0 Update 9"
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me if you are having any other issues.
     
  10. mann303

    mann303 Private E-2

    Thanks for that. Did everything you asked. The registry updated fine. Thanks once again. If I have any problems I will let you know,but everything seems fine now.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.

    If you are not having any other malware problems, it is time to do our final steps:
     
  12. mann303

    mann303 Private E-2

    All done. Thank you once again. My computer seems fine now. Best Regards
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds