Virtumonde has locked up my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by gosubs, Dec 25, 2008.

  1. gosubs

    gosubs Private E-2

    Hoping you can help. Problem started yesterday with random popups regarding spyware and malware. After detecting the Virtumonde Trojan and several other malware on my kid's PC using Spybot and trying unsuccessfully to remove, I read through your forums and started following the READ & RUN ME FIRST instructions. I haven't even made it past step 1 and my computer is completely hosed. I was able to uninstall Viewpoint Mediaplayer as well as get rid of some old games from the PC. I then was able to download the new Java file as you instruct and then delete the older versions of Java from the PC. I tried to load Java in Safe Mode and was unsuccessful. When I tried to reboot in normal mode, the desktop comes up (slowly) and I get a MacAFee popup window that says my computer is not protected and that's it. I can't open any folders, can't even get into the Start menu. I can CTRL ALT DEL to get the Task Manager, but can't do anything in Normal mode. Tried several times and even had to hard boot a couple of times because I couldn't even shut down from Task Manager.

    I'm limited to Safe Mode only and when I open McAfee it says my spyware and malware monitoring is disabled but doesn't allow me to enable them. Any ideas on how I can get out of this mess.
     
  2. gosubs

    gosubs Private E-2

    The specs - its a Dell Dimension 3000, running XP Version 5.1 through SP3, 76477-OEM-0011903-00102, 2.66 GHZ Celeron processor, 512 MB
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    * Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    * Then search for TDSSserv.sys
    * Let me know if you find this or not.
    * If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    * Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  4. gosubs

    gosubs Private E-2

    Thanks, Tim. Sorry for the slow reply, I've been away from home at a hockey tourney. I'm ready to tackle this beast again. First off - I did not find TDSSserv.sys following your instructions. Second, I am limited completely to Safe Mode at this point as I can't even get the computer to come up in Normal mode anymore. I am unable to load JAVA in safe mode uninstalled my McAfee program because of all the error messages I was getting. The latter may not have been the smartest mode, but when I opened McAfee it told me that the key items, firewall protection and scanning were disabled anyways and I was unable to "re-enable" them, so I'm not sure if it was doing me any good anyways.

    I am in the process of following all the READ ME FIRST guidelines that are possible and once complete, I will post my logs and results indicating what steps I was unable to do.
     
  5. gosubs

    gosubs Private E-2

    Okay, I have completed as much of the READ ME FIRST tasks as possible and attached logs for MBAM, combo-fix and MGtools. There is no SUPERAntiSpyware log because I was unable to install the program in SAFE Mode and I can't start my computer in Normal mode at all.

    I was unable to complete the following tasks from the READ ME FIRST instructions:

    Uninstall MALWARE programs - I was able to get rid of the few programs from the list that were installed with some effort, but there are some programs I'm not sure what they're for that I might want to uninstall (Creative MediaSource) and also was hoping to uninstall Ad-aware before running Spybot to avoid conflict, but I can't uninstall Spybot in Safe Mode.

    JAVA - I was able to download the newest version and the delete all my old versions, but I am not able to install the new JAVA program in Safe Mode.

    SUPERAntiSpyware - couldn't install in Safe Mode. I followed the link for the workaround on the instruction page, but the file they suggest running (gpedit.msc) could not be found on my computer.

    Finally, as I mentioned, I uninstalled my MCAFEE software because all the critical anti-virus and firewall capabilities were disabled and I was unable to re-enable them in Safe Mode. Not sure if this was a good idea or not, but the software wasn't doing anything for me anyways and was constantly popping up error messages while I've been trying to troubleshoot this problem.

    I haven't tried to restart the PC in normal mode yet - I figure I'll wait for you to review the logs I was able to attach. Of note, although no logs are copied, the following items were found and "fixed" with Spybot:

    26 problems:
    Fraud.AntivirusTrigger 1 copy TrojanC
    Fraud.VirusTrigger 3 copies MalwareC
    Hitbox 5 copies Browser
    MediaPlex 3 copies Browser
    RightMedia 1 copy Browser
    Virtumonde 4 copies TrojanC
    Virtumonde.generic 1 copy Trojan
    Virtumonde.prx 2 copies TrojanC
    WebTrendsLive 2 copies Browser
    Win32.Agent.sd 3 copies TrojanC
    Worldsecurityonline.FraudAlert 1 copy Malware
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    c:\windows\SYSTEM32\qcmerrps.ini
    c:\windows\SYSTEM32\wvwdgivu.ini

    Now try to reboot into normal mode. If you are able, try installing SAS and running a scan --> either way, run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. gosubs

    gosubs Private E-2

    Well, we appear to making progress. I was able to come up in normal mode, download both the latest Java and SAS and run the SAS program. As you'll see from the logs, it did find a number of issues in SAS. I was still getting a few popup ads when I was on FireFox downloading SAS, although the ads haven't popped up since. I still need to reload a firewall and anti-virus software program. McaFee was a free install with my ISP and I need to contact them tomorrow to get a code to reload it. For now, and pending any input from your review of my logs, I don't plan on spending any more time online on this PC (will check this thread through one of my other PCs. Much thanks for getting me this far, though I suspect there may still be more work to do.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....:)

    You need to download and install:
    Java Runtime

    And you should also not have the "Kids" user account set as having administrative privileges.

    If you are not having any other malware issues, then:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds