Virtumonde and other possible problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by Copper29, Jan 4, 2006.

  1. Copper29

    Copper29 Private E-2

    Hello everyone, I just want to start out saying that this forum seems very helpful and informative. I have read the "Read this first" threads and this is what I have come up with. Please forgive anything I say that might be naive, as I am not an expert with computers. Any help is greatly appreciated.

    My computer is a Dell Dimension 8300 running
    Windows XP Home Edition Version 2002 SP1
    Pentium 4 CPU 2.80 GHz
    2.79 GHz
    512 MB of RAM
    40 GB hard drive
    This information I gathered from system information in My Computer Menu. I decided not to install SP2 until all my computer problems were resolved.

    I had originally tried to get help from another site concerning WinFixer but I believe that it has only been partially removed. I have not disabled system restore because I do not feel that the malware was removed. I have enabled viewing of hidden files. I uninstalled the multiple antivirus applications (I think). I rebooted in safe mode and physically unplugged the internet connection. I ran Ccleaner. I ran Microsoft Windows Malicious Software Removal and there was nothing found. I ran Ad-Aware and nothing was found. I ran Spybot Search & Destroy and there was one thing found: WildTangent. It said that it fixed it, but I've done that before. I also had trouble finding how to turn off the Teatimer other than turning it off in the tray by the clock on the lower right. I couldn't do this in safe mode. Microsoft Antispyware also found nothing. I scanned with Bitdefender and there was some things found (see attached). I then ran Panda ActiveScan which found nothing.

    I read the Virtumonde fix tool thread but I am not confident in my ablility to properly read the HijackThis file. Please give me your advice. Thank you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    You do not show any signs of a Virtumonde infection.

    You can have HJT fix the below entries.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    I would then suggest you set your home page to something better/more useful than Dell's mild malware affiliated MyWay. How about www.majorgeeks.com?;)

    Are you still having any malware problems?
     
  3. Copper29

    Copper29 Private E-2

    Thank you for your help! I actually never had that as my home page in IE, I had reset it to Altavista. Now I use Firefox and I am much happier. No popups and tabbed browsing is very cool. I am considering MajorGeeks as my new home page. :p

    I am concerned that I partially removed Virtumonde and it will rebuild itself eventually. I read somewhere that it can do that, but I really don't know what I'm talking about. ;)

    What was it that Bitdefender found and will I ever get rid of WildTangent? I don't seem to be having any more problems, but I take that sort of thing one day at a time. Do you think I could do my Windows updates without fear now? I have yet to do a more recent backup of my files and system. Which would you do first?

    I'm just full of questions.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But it is not showing anywhere in any scans so there is nothing to worry about. You could run the below as a backup to see if it finds anything additional:

    Running Ewido Security Suite

    and attach the log from Ewido

    BitDefender always complains about what it finds in AIM. If you do not use AIM, uninstall it and delete the folder. Otherwise ignore BitDefender's complaints about what it finds in AIM.

    I don't see any WildTangent? What are you referring too? And if you want to stop getting it. Don't use or install anything from AOL (including AIM).

    You should dump your Restore Points now per step 1 of the READ & RUN ME.
    Then Backup your files.
    Then continue with the below (which includes Windows Update):

    How to Protect yourself from malware!
     
  5. Copper29

    Copper29 Private E-2

    I ran Ewido and it didn't show anything so there's no log. Thank you for explaining Bitdefender and AIM. I'm putting off uninstalling AIM for now though. WildTangent was something that SpyBot found and I allowed it to fix it. It had come up with that before and supposedly fixed it before. I mostly was wondering if I should be worried about it.

    I followed the instructions you gave and I feel much better about my computer's security. I can't say thank you enough for taking the time to help me with my computer. I have to take some time to investigate how my newly installed programs work. So far everything is running smoothly.

    The only thing that I haven't done is the Java section of the "How to Protect yourself from malware." I'm afraid of messing it up. I'll read it again more carefully. Anything further that you may have for me is welcome.

    Thanks again for all your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No, nothing further as long as you are having no problems!

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds