Virtumonde and No Explorer -- Removal / Fix

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vette, Jan 16, 2009.

  1. Vette

    Vette Private E-2

    The problem started at the beginning of this week. I first noticed when my Avast alerted me of a Virus. A new firefox window had popped up and Avast stopped it from where ever it was going to go. I had 2 of these pop up right in a row. So I first set my computer to do an Avast scan at boot. I let it do its fix and reboot. I then started Spybot up and let it do its scan. It found a few things and then asked to scan at reboot. Among these was Virtumonde which it could not fix. I rebooted and let it scan, it said fixed. I then ran Ad-Aware 08 and it also found a few things and Virtumonde.

    next day I had a few windows attempt to pop up again, and my teatimer came up with some things trying to edit the registry. I ran Spybot and Avast a few more times, each time deleteting a few items. I was playing online on the ps3 when an online friend of mine sent me to your website. his favorite tools were Advanced System Care 3.* and CCleaner. I ran both of those. Next thing I know when I reboot all I have is a desktop and mouse. No icons, no start bar, no task manager, nothing. I tried safe mode - same thing. I tried the command prompt option and I was able to run avast and shcedule a boot scan. After re-booting I had a desktop a mouse and now Yahoo instant messanger. i was also now able to use the task manager. From here I re-ran spybot, ad-aware, Advanced System care, and avast. Next reboot no messenger only desktop and mouse. However, i could still bring up the task manager with let me bring up firefox. I also tried explorer. when explorer loaded it brought up desktop icons and start bar .. 30sec and it all disappeared. That just kept happening over and over.

    Today I was surfing more and saw a note about renaming a copy or explorer. I named it rerolpxe and it at least gave me just a file browser. I then gave up my attempts and decided to follow your steps. I removed a few unnecessary programs including logitec desktop manager. ( that came with my web cam, but I had no idea what it was used for) Immediately after running the SuperantiSpyware the next reboot all the icons were present and the start bar was working ok. I had also removed spybot prior to starting since I noticed tea timer was not recommended. i let it re-install and again it found virtumonde, but claimed it fixed it. i then ran malwrebytes, combofix, and mgtools as directed.

    Here are the log files and results

    Additional Notes: I current have an annoying beep like the finishing of a program when there are no programs running ? Any further suggestions.

    Also a question about teatimer. I had liked it. Is there something better to protect the registry or is it not necessary ? just curious.


    Any help would be greatly appreciated !! :) I hope i followed the directtions well I notice so many post where people could follow everything.
     

    Attached Files:

  2. Vette

    Vette Private E-2

    Additional remaining Log files:
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Best be addressed in the software section as this may just be how you have system alerts set.

    As to teatimer...it is fine to run, though we ask that you disable it when you do the scans as it can interfere with both those and any fixes we as you to do.

    Your logs are clean. Are you having any malware issues?
     
  4. Vette

    Vette Private E-2

    At the moment there doesn't seem to ba any issues. No pop ups and no problems loading up windows. I had just wanted to make sure the logs looked like no other problems. I appreciate you taking the time to look through them. Thanks to you and MajorGeeks for helping me get back to running smooth ! I have already been recommending my friend do the same :)
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds