Virtumonde.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by ForceAccount, Dec 4, 2008.

  1. ForceAccount

    ForceAccount Private E-2

    Virtumonde.dll

    Ran the software for repair, Spybot slowed and locked at virtumonde. It steals my browser/redirects/unable to open. Help would be welcomed.
     
  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to Major Geeks, ForceAccount

    A little clarity is needed... were you able to run the other scanners requested?


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.



    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Links are given in the Step 2: Installing Tools and Running Scans section for downloading the definitions for the MBAM & SAS scanners. Then copy them to the problem PC. Yes, you could use a flash drive too but flash drives are writeable and infections can spread to them.

    Thanks!
    dr.m
     
  3. ForceAccount

    ForceAccount Private E-2

    What is happening
    Very slow start up and search
    Browser being redirected
    connection issues
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ForceAccount

    You MUST run our procedures to get us the requested logs!


    You need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the requested scans
    • SASlog.txt log from SuperAntiSpyware.
    • Malwarebytes Anti-Malware log
    • ComboFix.txt (normally C:\ComboFix.txt)
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
    • You will need to post 2 messages to attach all four logs since only 3 attachments are allowed in any single message. Post all of them in one thread.
    • Be patient after posting your logs and wait for one of the helpers to get to you. It can take a while to read thru all of the logs and to create individual fixes for you.
     
  5. ForceAccount

    ForceAccount Private E-2

    Here are two
     

    Attached Files:

  6. ForceAccount

    ForceAccount Private E-2

    and two more
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, ForceAccount

    Your Desktop is a mess! I strongly recommend that you cleanup all of the junk on it and leave only shortcuts. A cluttered Desktop is malware's playground.


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the "all clean and final instructions" you will be free to install what you want.

    Step 1:
    If you have not already done so, please disable the Guest account in User accounts.

    Step 2:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 3:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Step 4:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.


    Step 5:
    Navigate to and delete:
    c:\windows\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP <--- this folder

    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 6:
    Run Ccleaner



    Step 7:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    Thanks!
    dr.m
     
  8. ForceAccount

    ForceAccount Private E-2

    I had downloaded a new IE7 prior to getting your post, ran all steps in your post. Could not find 06 HKCU Software, 06 HKLM software policies, 06 HKLM policies or 016 ppf to delete from HJT. also could not locate

    c:\windows\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP

    Netscape is still being redirected to google/dell sometimes, and runs very slow.

    MG zip would not upload, had to load as seperate attachments
     

    Attached Files:

  9. ForceAccount

    ForceAccount Private E-2

    Lots of issues sending these, "unable to connect" although connected....
     

    Attached Files:

  10. ForceAccount

    ForceAccount Private E-2

    Browser will not allow me to change the default search page set at "Live Search" in search options
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ForceAccount

    Let's do this:

    Step 1:
    Dis-able Spybot's TeaTimer!

    How to disable Spybot's TeaTimer

    Step 2:
    Look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 3:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Step 4:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).



    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt
    Make sure you tell me if you had any problems running this procedure,* if you can now re-set IE defaults, and give a description of how things are working now!

    Thanks!
    dr.m
     
    Last edited by a moderator: Dec 16, 2008
  12. ForceAccount

    ForceAccount Private E-2

    Spybot 1.5.2.20 did show in programs 12.18 mb but unins 000.dat does not exist.
    I do not use Firefox or Opera

    I have AVG,SuperAntiSpyware,Windows Defender all running. Should I have all active?
     

    Attached Files:

  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Not unless you purchased SUPERAntiSpyware Pro - the Free version is an "On Demand scanner" only, and uses very little resources.

    *See this thread How to Protect yourself from Malware! for our recommendations. I still request that you make no changes until directed --- we'll tweak after the malware has been removed.

    I need alittle time to review your most recent logs... but you forgot to tell me how your machine is now running and if you had success in re-setting your IE defaults.
     
    Last edited: Dec 17, 2008
  14. ForceAccount

    ForceAccount Private E-2

    OK, things have improved, not being redirected or hijacked. Still having connection issues IE: Clicking on a link and it is connected.

    The host 'SMTP.ACD.NET' could not be found. Please verify that you have entered the server name correctly. Account: 'POP3.ACD.NET', Server: 'SMTP.ACD.NET', Protocol: SMTP, Port: 25, Secure(SSL): No, Socket Error: 11001, Error Number: 0x800CCC0D
    ----- O Internet Explorer cannot display the webpage

    Most likely causes:
    You are not connected to the Internet.
    The website is encountering problems.
    There might be a typing error in the address.

    What you can try:
    Diagnose Connection Problems

    More information

    This problem can be caused by a variety of issues, including:

    Internet connectivity has been lost.
    The website is temporarily unavailable.
    The Domain Name Server (DNS) is not reachable.
    The Domain Name Server (DNS) does not have a listing for the website's domain.
    If this is an HTTPS (secure) address, click Tools, click Internet Options, click Advanced, and check to be sure the SSL and TLS protocols are enabled under the security section.

    For offline users

    You can still view subscribed feeds and some recently viewed webpages.
    To view subscribed feeds

    Click the Favorites Center button , click Feeds, and then click the feed you want to view.

    To view recently visited webpages (might not work on all pages)

    Click Tools , and then click Work Offline.
    Click the Favorites Center button , click History, and then click the page you want to view.




    The host 'POP3.ACD.NET' could not be found. Please verify that you have entered the server name correctly. Account: 'POP3.ACD.NET', Server: 'POP3.ACD.NET', Protocol: POP3, Port: 110, Secure(SSL): No, Socket Error: 11001, Error Number: 0x800CCC0D

    I ran the diagnose connection and it is ok.

    This is erratic sometimes it goes right to the link and other times it takes several attempts. Also have "DNS error on the bottom left box sometimes.
     
  15. ForceAccount

    ForceAccount Private E-2

    Also with Outlook connection issues and failed sent msgs. several attempts and will finally go but very slow
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ForceAccount


    Once again - I find that you are not following my instructions. These are still installed according to your logs.
    • Windows Messenger
    • SpyBot TeaTimer
    For your problem with uninstalling Spybot 1.5.2.20, just reinstall from the file I see you still have. Then reboot and then try to uninstall it.



    For your pc's security - you should also remove these:
    • Java 2 Runtime Environment, SE v1.4.2_03
    • Java(TM) 6 Update 10

    And - update!
    Install the latest Sun Java Runtime Environment


    *TeaTimer has the function of blocking changes to your registry, which includes good changes.

    From the very start I have not removed any real malware issues - your first post had nothing to do with malware either. Spybot doing its scanning for virtumonde.dll and many many other items for Virtumonde, always slows down (quite alot) at this point and yes - for some people it can even hang. The hang is typically a problem with the Windows itself - sometimes registry corruption or hard disk problems.

    Whatever links you are clicking on must be related to something calling email programs since that is what SMTP is related to. Your problems are therefore software issues and should be posted in a new thread topic in the Software Forum.

    Clean-up after using the tools.


    Good Luck!
    dr.m
     
    Last edited by a moderator: Dec 19, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds