Virtumonde help

Discussion in 'Malware Help (A Specialist Will Reply)' started by wannabcraftin, May 25, 2009.

  1. wannabcraftin

    wannabcraftin Private E-2

    Hi,

    I am new to the forums and found this place after doing a search on Virtumonde. I have Spybot, Ad-Aware, Remove It-Pro, SuperAnitspyware Free edition and PC Tools Antivirus. I have not had any luck removing this malware with any of the mentioned programs. I am getting desperate to fix this and hoping someone here may be able to help me. Thanks in advance for your help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. wannabcraftin

    wannabcraftin Private E-2

    I have finally managed to run all the programs from the Read and Run me first. I am attaching my logs from all the scans as I am not sure if I am still infected or not, Thanks for all your help!
     

    Attached Files:

  4. wannabcraftin

    wannabcraftin Private E-2

    Ok this is my last log to attach and hopefully all is well in computerland ;)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are basically clean. We just have a few minor things to do.

    First a question. Why are you running this PC with no protection software installed?

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - (no file)
    O3 - Toolbar: (no name) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - (no file)

    After clicking Fix, exit HJT.

    Delete the below folders since PC Tools is not installed.
    c:\program files\PC Tools AntiVirus
    c:\documents and settings\Owner\Application Data\PC Tools

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. wannabcraftin

    wannabcraftin Private E-2

    Thank you for checking my logs and guiding me in what needs to be done. To answer your first question about the antivirus I had PCTools installed when I started the process but when it came time to turn it off to run the programs I ran into a problem. I turned it off but my windows security was causing it to still be running in the background, I couldnt completely turn it off to run the program so I uninstalled. I then reinstalled when I was done with all the programs. I apologized if it caused an issue, I had no idea what else to do.
    I did everything that you directed in the last response except for remove the PCTools folder as I do have it reinstalled. I seem to be running a bit slow still sometimes and I ran my spybot search and destroy after doing all that you directed and it is still coming up with a virtumonde entry...could this be a false positive?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem, but in the future, I would recommend you state something like this in your post so that we know ahead of time what you did and why.;)

    You need to be more specific. For example.

    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?

    And for Spybot, you will need to attach a log from it so we can determine if it is really a problem. Also did it only find it once and fix it? Or is it still showing up after you have fixed it? If it is in System Volume Information or in a Quarantine folder (like C:\QooBox) it is not a problem.
     
  8. wannabcraftin

    wannabcraftin Private E-2

    Thanks for all the help your are giving me.
    I think I finally found my log for spybot and will attach to this msg. I ran my machine in safe mode and it seemed to be running fine. I am slow when browsing and there are times when even my typing lags behind and then appears all at once, sometimes it seems to freeze up for a few seconds and I can't even click anything. The only things I have noticed using a lot of CPU is McciTrayApp_SSR.exe (I believe to be my Hughesnet tools) and the system Idle process.

    The virtumonde is found every time I run spybot and says fixed every time, the file isn't in a quarantine folder it is in system32. I hope I covered everything in this post please let me know if there is anything else.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is nothing in your log indicating any infection from Virtumonde. Make sure that you are referring to an actual detection which shows up when the scan finishes. What you see down at the bottom of Spybot's window while a scan is running is just what it is currently scanning for. It is not what is being detected. The log at the end shows you detections.

    Speak to your ISP about these. I would suggest removing them as they probably are not even necessary and these applications are notorious for slowing PCs down.
     
  10. wannabcraftin

    wannabcraftin Private E-2

    I am going to try to run one more scan and explain what I found. I did another scan with Spybot and still coming up with 1 Virtumonde '[SBl $92386332] Library' entry. I searched and found the file here: C:\WINDOWS\system32 (it is a zipfldr.dll). It says that it was created August 4, 2004 and Modified on April 13, 2008. I don't believe this file to be the malware so I am now wondering if it is a false positive, if it is in fact a false positive how do I stop it from coming up again? I hope this further info helps. Thanks for all you have done to help me, I certainly appreciate it.
     

    Attached Files:

    Last edited by a moderator: Jul 30, 2009
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is a false detection. See this: http://forums.spybot.info/showthread.php?t=46096

    Make sure that you have the current Version of Spybot and also all current updates. Based on your previous log, you are way out of date with your 1.5.2 version of Spybot. The current version is 1.6.2.46 which you can get here: SpyBot-Search & Destroy Tools

    Uninstall your old version and reboot, before installing the new version.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds