Virtumonde help for windows Vista

Discussion in 'Malware Help (A Specialist Will Reply)' started by luami, Feb 4, 2008.

  1. luami

    luami Private E-2

    i know there is a similar thread on this forum for windows xp, but some of the files asked to fix i did not find on hyjackthis

    i can never get rid of aldd, rdfa, and aoprndtws from my registry keys after deleting and restarting

    I also have a weird problem when i start up my pc. I get this error like this
    "error loading C:\windows\system32\qomll.dll
    This specific module could not be found"
    I remember this was the virtumonde that NOD32 deleted but i keep getting this error after startup.
    I use NOD32, spybot search and destroy, ad-adware 2007 and i have uninstalled my java 6. I have my hyjackthis log below Thanks!

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Feb 4, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. luami

    luami Private E-2

    I followed all the steps in those instructions, but for some reason i kept getting messages on the combofix window that it was preparing to scan and then "out of memory" and nothing else appeared...so i wasn't able to attach the combofix log you asked :(

    This first time i ran AVG the program didn't give me a report and i followed all the steps including automating the reports after scan and unchecking the box below, but the second time i ran it..i got a report == and i attached it..but there was malware detected on the first scan: Adware.WebDir, Trojan.Hack.Vg, and some infected cookies i deleted. Now for some reason, my pc is telling me that my trial for this program has expired..weird..

    I couldn't run the Mgtool.exe after downloading it from this site, the file on my pc was attachment.php and no program on my computer runs it so i couldn't produce a log for that too ><

    What i did include was a hyjacklog and that was all i could do..

    The malware other than from the cookies are in quarantine, i found 3 Virtumonde on s s&d like always and they still never go away from the registries. That pop up after my pc starts still keeps popping up and I'm also getting other problems. After i click on stuff like my computer/control panel/documents such and such on start menu, my screen will just go blank except with the desktop background and everything would just start up again including the bottom right icons, loading the desktop icons and the window i wanted to load disappears..even my bottom menu bar disappears...and then it comes back..now i can't even access my folders. I opened task manager and realized 4 rundll32.exe running at the same time..and i didn't find so many before (like about 2 or 3) so i stop all those..but one kept coming back...and voila i can access my folders again...but they keep coming back everytime i restart my pc and i would have to stop those processes everytime i rebot
    this problem occurred after i got infected with virtumonde but it only happened on the first time i tried to go into my folders and the second time would work..now no matter how many time i try now..it won't work
    ..i don't understand all this..is it just better to reset my whole system?

    Thank you for your guidance
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must download MGtools.exe to your PC. Do not open or run the file from user browser. First download it to your PC and then run Windows Explorer to find C:\MGtools.exe and double click on it to run it. You must make sure you follow the instructions for Vista Users in the Using MGtools link or you will have problems.

    If you are having problems downloading the file, make sure you have clicked the Remember me box when you log into Major Geeks.

    Please do not attach HijackThis logs. You don't even have the correct version anyway and we don't need them as they are embedded into MGtools. We do however need the MGlogs.zip file to be able to help you. Also we need to get ComboFix to work. Try running it in safe boot mode. And also make sure you have DOWNLOADED the file to your Desktop. Do not attempt to run or open it from the download link as it will not work.

    Also avoid power downs, power ups, reboots ...etc. They will cause the infections to spread and mutate. Do not running anything that we do not ask you to run, as this could also cause mutation.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds