Virtumonde (and ..?) - help needed

Discussion in 'Malware Help (A Specialist Will Reply)' started by dbt_vanhove, Jun 30, 2008.

  1. dbt_vanhove

    dbt_vanhove Private E-2

    What do i post/upload? :confused

    Strange, really strange that 'high-end' licensed products don't handle this pretty old nasty.

    I ran Spysweeper, it detects (high level risk) & crashes at some point. Or deletes, whilst it's back on next run/reboot.

    I'm pretty advanced removal-user so simple instruction r fine.

    thx

    David
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. dbt_vanhove

    dbt_vanhove Private E-2

    okay thanks!
    Not SUPERAntispyware,
    but MalwareByte's Anti Malware ( www.malwarebytes.org ) did kill the bastard thoroughly. Free and GOOD!
    It detected more deeply (6 detections) instead of just one by SUPERAntiSpyware. Just one was really not good enough for Virtumonde.

    So the latter is not so SUPER after all ... rolleyes
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I strongly recommend that you attach all of the requested logs. Most Vundo infections will leave a lot of extra baggage around that always requires manual removal.
     
  5. dbt_vanhove

    dbt_vanhove Private E-2

    so here additional logs ... thx for the help, the browsing and most of all, your persistance! :)

    i've zipped some; since only up to 3 can be Uloaded, and it's not really clear if this is all you need (due to pretty 'fragmented' cleaning instructions)

    If any other logs R needed, please inform exactly which ones.

    Thanks again!!!

    ps
    vundo (& sting else) has been picked again INDEED !!!

    You are RIGHT it leaves a lot of mess behind. Programmed really tricky!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need the requested log from MGtools. This is the C:\MGlogs.zip file.
     
  7. dbt_vanhove

    dbt_vanhove Private E-2

    ok sure .. there you go!

    gotta sleep now, it's 05.40 am here ;)

    Good Night!
     

    Attached Files:

  8. dbt_vanhove

    dbt_vanhove Private E-2

    tip;
    >>> would be MUCH easier if cleaning instructions are listed with only 'one' time choosing the operation system, thus having just one page to follow to the bottom instead of opening all these windows ??!

    ... and closing it with a full list of logs to be uploaded (general).
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are in pretty good shape. We only have a little to do. You must have caught the infection very early.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - (no file)

    After clicking Fix, exit HJT.

    Now delete the below file:
    C:\WINDOWS\BM236a2adc.txt

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!



    Observations:
    • You have both Spy Sweeper and Spyware Doctor installed. I would recommend only using one of these because they will slow your PC down and you can have conflicts between them just like with antivirus programs.
    • You have an old version of Spybot installed and should update.
    • You have an old version of SpywareBlaster installer and should update.
     
  10. dbt_vanhove

    dbt_vanhove Private E-2

    Great. Incredible, one to help me out, two that you know all this.

    Pretty hard to get that you want to lend a hand to me here in little Belgium. Nice!

    It indeed wasn't that cleaned after all.

    The computer is very fast now (for it's specs), on booting and runnig. A little extra is resolved, the HD indicator blinked about every second or so, & HD ticked for (very) unkown reasons, this disappeared too.

    So:
    0. Registry has been added succesfully!
    1. the requested log has been attached
    2. Spyware Doctor is removed, SpySweeper kept (paid license), as suggested
    3. Updates Spywareblaster and Spybot done (an reran) ...

    Something else 2do 2 finish this session off?

    Bill really deserves a slap in the face for putting such a vulnerable system out.

    One question left, i want to clean it weekly here, is there a bot that runs/updates the right antimalware & others and gets the new definitions on startup, one after another, in the right order, fully AUTOMATED :zzz:zzz

    Would safe a lot of tedious manual preventive cleaning.

    thanks thanks thanks! :wave:wave

    David
     

    Attached Files:

  11. dbt_vanhove

    dbt_vanhove Private E-2

    there's added a screenshot from onecare live run ...

    seems it's still infected ... :cry

    just to let you now
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Final instructions appear further down in this message.

    Some programs will allow automatic updating. Spy Sweeper as you know does. Spyware Blaster will only autoupdate if purchased but it is not a scanner anyway. Spybot does not autoupdate. You antivirus program should get auto updates. As far as scanning, some programs allow you to use a built-in scheduler to create tasks for when they are run. Spy Sweeper does this and NOD32 probably had the feature too. For others, you could probably create a Windows Task yourself to run weekly. There are some programs out there that attempt to get updates for many programs automatically but I don't recommend using them as they add to the additional waste of system resources since they always have to load and run at startup. Personally I prefer to do my own updating so that I know when the system is changed (due to the update) and if something strange starts to happen, I then know what updates may have caused an issue. With autoupdates running without your knowledge, you would just be thinking that you have not changed anything that could be causing your system to behave improperly.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! System Restore is not a problem as my last message will take care of that and the second item in that snapshot is just an MP3 that you downloaded. I cannot read where anything after that is being detected but if they are in System Volume Information they are not problems. Also if they are in one of the Quarantine folders they are also not problems. Finish my final instructions and see where things stand.
     
  14. dbt_vanhove

    dbt_vanhove Private E-2

    okay thank you ....

    0. followed 1 to 9;
    1. updated to SP 3 amongst other xp updates (afterwards)
    2. completed the long list at 'Malware Removal Guide' (some Active X settings at ie settings could not be found)

    Things should be fine 'for now'

    Thank you for this extensive help!!

    greetings,

    David.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  16. dbt_vanhove

    dbt_vanhove Private E-2

    okay this thread can get a lock if needed/available, good night.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not close threads since only the creator and one of the staff here can reply to threads in the Malware Forum. Thus no one can hijack a thread. We know when a thread is complete by being the last to post and then we just let it slip down out of sight. ;) Thus if you do not have the need for any more help it would be best to not post anymore now. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds