Virtumonde and other issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by gumby man, Oct 19, 2007.

  1. gumby man

    gumby man Private E-2

    I have a computer with winxp pro with sp2 on it with all of the updates. Has been running for about 6 months with no issues. Booted the other day and found Dealio icon popup in my task bar and knew that all was not well. Tried to go to Start, Run, and then Msconfig to see what was going on, but no can do. The Shutdown and Run dialog boxes were missing. I knew I was in for trouble. I ran Superantispyware, Spybot S&D, and Mcafee and they all found many issues. Most problems were gone, but I ran them every day for a few days and they still found just a few things, but never totally clean. I found this forum and I have run all the basics. I have updated my java to Java6 update 3. I had Java6 update 2. I ran counterspy and I have a log. I was at the step to run the online portion, but I can no longer get online either in safe mode or regular mode. I ran winsockxpfix.exe, which has fixed connection problems in the past on my machine and several others, but I still can not get online. When I plug in my cable to my switch, I see the green light come on, but no connection. I try to disable and reinable my NIC, but no luck. Repairing the connection does not work either. Since I can not get online, I have halted at the step of online scanning.

    Brian
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this and run on the infected computer:
    Combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Then see if you can continue with the Read and Run First.
     
  3. gumby man

    gumby man Private E-2

    Ran combofix but still can not get on line.
     

    Attached Files:

  4. gumby man

    gumby man Private E-2

    I also ran vundofix but it could not complete. It asked to reboot to take care of a file, but then it still could not get rid of it. The name of the file is:

    wvurqnl.dll

    Rian
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need your ShowNew, GetRunKeys and HJT logs.:)
     
  6. gumby man

    gumby man Private E-2

    Here are my logs.

    Brian
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach new logs for:
    ShowNew
    GetRUnKEys
    HJT
    Avenger
     
  8. gumby man

    gumby man Private E-2

    OK, I followed your instructions and I am posting the logs. I have been using a different computer to use the internet than the one that has the problem. It is still disconnected from the net. After your next response, I will hook it back up and try to get back on. I will post the last file on the next post.

    Brian
     

    Attached Files:

  9. gumby man

    gumby man Private E-2

    Here is avenger.

    Brian
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We missed one ....

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Quote:
    REGEDIT4

    [HKEY_LOCAL_MACHINE\software\Microsoft\windows\currentversion\Explorer\ShellExecuteHooks]
    "{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}"=-

    [/quote]

    Now tell me how things are running.
     
  11. gumby man

    gumby man Private E-2

    Still no internet, would you like any new logs after I entered the new reg data?

    Brian
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is possible that your NIC card is faulty ....but lets try resetting your IE defaults:

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If you still cannot get online ...I would suggest that you :
    1) try a new nic card
    2) (are you using a router ...if so:) connect directly to the modem
    3) post your ipconfig data .....From this and any other computer you are running (for comparison).
     
  13. gumby man

    gumby man Private E-2

    Okay, I reset the defaults and no luck. I changed my cable, no luck. Plugged directly into router instead of switch, no luck. Used external USB NIC, no luck. When I plug my internal or external NIC into switch or router, the light comes on to indicate a connection was made. Powered down router and switch, no luck. All other computers on network work fine. I removed my network card from device manager and rebooted, but all that did was make it to where I can not see any network connections at all. If I try to run the network connection wizard or get to the network properties, it will usually just hang. I pulled up the task manager and looked at the processes and there is one process that takes up 50% of my core 2 duo processor. I can not seem to enable my network at all. I tried to disable then reinable my NIC's, but no luck. I can not post any ipconfig data because I can not access it :)

    Brian
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you tried different cards (usb, etc) did you get a balloon saying new hardware found?

    Have you tried using the usb nic and then starting the new hardware installation manually?

    This is sounding like a driver issue ...have you looked in the event logs?
     
  15. gumby man

    gumby man Private E-2

    Yes, I did see a balloon, but I think that I had previously installed that usb nic, so I uninstalled it and manually added it like you mentioned. The link light comes on and the tx/rx light comes on as well, but still no network. Which event logs are you speaking of?

    Brian
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you do some registry tweaking at some time prior to all this?

    In task manager ...are there any ! or X or ?'s showing for any device?

    Go to control panel / admin tools / event viewer ....look in system and applications.

    You may need to do a repair install to regain the system files that may be missing.

    But this is not malware ....you may best be served by posting in the software section.
     
  17. gumby man

    gumby man Private E-2


    Well, I could not get the network to work at all, so the whole thing was hosed. Finally had to reformat and start from scratch. Tried to do a repair install, but it hung at the installing network part. Thanks for the help anyways. That was a real booger !!

    Brian
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry to hear you had to hose it and do a new install ...the network part often takes time.

    Good luck! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds