vcmgcd32.dll & vcmgcd32.dl_

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Escapingjail, Oct 12, 2009.

  1. Escapingjail

    Escapingjail Private E-2

    It refuses to be completely removed by Combofix & Malwarebytes. I also Ran a program called regrun, which also picked up a few other things that seemingly are gone now.

    Even if I can remove vcmgcd32.dll & vcmgc32.dl_ it comes back on the next startup. This Virus seems to be breaking a few random programs a few hours after they are repaired, such as Microsoft Applocale, Daemon Tools, SageTV, and Street Fighter 4 PC game.

    I have attached my MGlog.zip any extra help would be greatly appreciated.

    I've been pulling my hair out over fixing this, thank you in advance.
     

    Attached Files:

  2. Escapingjail

    Escapingjail Private E-2

    Please don't count this as a bump I can't figure out how to edit my original post.

    After working on this for a few more hours and reading this page http://www.microsoft.com/security/p...ame=Virus:Win32/Sality.R&ThreatID=-2147395704

    I gathered that this virus was editing my system INI with this string. (This is the full system.ini the bold is the part I feel was edited by the virus)

    After deleting this I went into safe mode and deleted both vcmgcd32.dll & vcmgcd32.dl_ and ran combofix (which for some reason afterwards would not give me a combofix.txt) and Malwarebytes (Which gave zero hits. Then I restarted back into safe mode. Both files were still not there and looks like I succeeded into figuring it out.

    Then at this point I restarted backing into windows normally, both files were still there and my system.ini was still edited.

    For now i've deleted the part in the INI I feel is part of the virus again but this time also made it read only. To see if this helps.

    Please take note this was just an update on my status and not a bump.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please put ComboFix on your desktop. You then need to run it and attach that log as well as the logs from:
    SAS
    MBAM
    RootRepeal

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds