Virtuemonde Nightmare!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jaydub514, Dec 7, 2008.

  1. Jaydub514

    Jaydub514 Private E-2

    Well it looks like my PC has finally been infected with the common Virtuemonde malware. I've ran numerous removers, etc to no avail -- they keep coming back. Adpages will load on their own, whenever they feel like it -- it's driving me nuts! AVG Antivirus picks a few "Fakeadremove" type entries up, as well as different variations of the virtuemonde malware/trojan. When going through the add/remove program list I had 2x old JAVA entries which may have been the way into my PC.

    I've followed each and every step of the READ AND RUN to the "T" so here I am now to post the logs for some expert advice.
     

    Attached Files:

  2. Jaydub514

    Jaydub514 Private E-2

    And here is the MG zip file.

    THANK YOU helpers for doing what you do everyday -- just browsing through the forums I can tell you guys have one of the most painstaking tasks here dealing with all of our issues. All your help is greatly appreciated by all of us!!!
     

    Attached Files:

  3. Jaydub514

    Jaydub514 Private E-2

    Quick update -- now it seems like a program called "SpyGuard 2008" is automatically installing on my PC (after doing all the aforementioned steps) and show a fake windows security center window. I managed to remove it from the add/remove program menu on the control panel, but it keeps coming back. Having these phantom programs be installed without my permission tells me something is definitely wrong!

    Thanks guys
     
    Last edited: Dec 7, 2008
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only problem on your system that I see is AVG 7.5. It is no longer supported and you can not update definitions. You need to uninstall it and install a newer AV, run the scan with it and let me know if it finds anything.
     
  5. Jaydub514

    Jaydub514 Private E-2

    I uninstalled AVG, installed Avast Home.

    Ran the boot test -- took a while but it did come up with a few notifications.

    C:\Documents and settings\Jason\local settings\temp\_Avast4_Unp168054661.tmp\[UPX] ----- infected by WIN32:Trojan-gen [other]

    C:\program files\ Alwil Software \Avast4\DATA\moved\A0030228.dll.vir ---- infected by WIN32:Rootkit-gen [RTK]

    C:\system volume information\-restore{12BB4D41-0C1E-4D08-B17B-12AF3691316B}\RP347\A0030563.exe\ [UPX] ---- infected by WIN32:Trojan-gen [other]

    I chose the recommended "move objects to vault" option for the above notifications. I'm still getting the fake windows security center/Spyware Guard 2008 popup.

    Thanks!
     
  6. Jaydub514

    Jaydub514 Private E-2

    One more alert popped up while the PC was sitting idle for a few minutes

    C:\Windows\system32\winscenter.exe [UPX] --- infected by win32:Trojan-gen(other)

    I tried to move it to the vault but avast froze up on me. I have since shutdown the affected PC and will just use another one to check this thread.

    Thanks!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You appear to be re-infected....please re-run SAS, MBAM and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.

    Attach those three logs. :(
     
  8. Jaydub514

    Jaydub514 Private E-2

    Tried to run SAS first -- the PC would reboot on its own once the quarantine process would get started. This happened twice in a row, so I ran MBAM first -- then SAS. That worked great, then ran the MGtools. Here are the logs!

    Thanks again
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yep...somewhere between the 7th and the 11th you got infected. None of the items found by MBAM were in your first logs.
    Code:
    C:\Documents and Settings\Jason\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    mbam-l~1.txt  Dec  7 2008        1267  "mbam-log-2008-12-07 (00-27-54).txt"
    mbam-l~2.txt  Dec 11 2008       [B][U] 6611[/U][/B]  "mbam-log-2008-12-11 (13-43-39).txt"
    
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  10. Jaydub514

    Jaydub514 Private E-2

    Hmmm I ran C:\MGtools\analyse.exe but couldn't find those two lines --


    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""

    [-[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]

    I've attached the log to see if maybe they were named something similar that you may see?
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Must have been having a "senior day" yesterday....:confused

    These were the lines to fix in HJT:
    O2 - BHO: (no name) - {DBCDF5F3-A809-4C69-9F9C-8B17CFFF692B} - C:\WINDOWS\system32\qoMcdEwV.dll (file missing)
    O20 - AppInit_DLLs: lnrsnp.dll

    Please get me the new MGLogs as well as the log from running Avenger.
     
  12. Jaydub514

    Jaydub514 Private E-2

    Ok here are the logs

    Also, Avast popped up with the process.exe is infected prompt don't know if that's something already nukes though.

    Thanks!
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any problems.....please tell me exactly what Avast is reporting.
     
  14. Jaydub514

    Jaydub514 Private E-2

    I ran the longest test from Avast this afternoon and I proceeded to do the recommended move all to vault with the items it found. Looks like my system restore got contaminated too. I've attached the screenshot of the results.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No program will remove infections in the system restore folders..you have to toggle system restore to do that.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  16. Jaydub514

    Jaydub514 Private E-2

    Well everything was just dandy until...I got a notification about svchost.exe being suspicious file with a possible rootkit from avast this morning. I also noticed that yesterday all of a sudden my windows firewall reported itself as being turned off. Puzzled, I turned it back on and thought nothing of it. I've attached a screenshot of what avast is reporting. I chose to ignore it for now.



    Thanks!
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have no idea what transpired between the 17th and now, so you will have to go thru the removal procedures again.

    First I want you to use windows explorer and find:
    C:\WINDOWS\ServicePackFiles\i386\svchost.exe

    (You may need to find it on you xp cd in the i386 folder)

    Right click it and then go to the system32 folder and paste it in the right pane, and do the same for the system32\drivers\ folder.

    Then go back to the Read and Run FIrst and download and run the tools --> NOTE, the procedures have changed and the software has been updated.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds