Virtumonde infestation! Went through sticky.

Discussion in 'Malware Help (A Specialist Will Reply)' started by iamwhil, Dec 28, 2008.

  1. iamwhil

    iamwhil Private E-2

    Ahoy Mates,
    As per instructions. 2 days ago I was online surfing in google chrome and started noticing long wait times. Then IE popups started showing up, so I knew something was wrong. I ran spybot search and destroy and it came up with virtumonde or vundo.h and got rid of all the copies except for one that it said was in memory, so try to restart. Well that was to no avail. It restarted and had the same problem. Then some other things started going nuts with some fake spy ware trojan showing up, but has since disappeared(I think).

    I have symantec installed and SuperAntiSpyware (as of the stickey). Auto-protect keeps showing either static or vundo as being detected.

    All the same I came across this forum and ran through the sticky about removing vundo. I don't know if it has been eraticated or if I have something lingering. Why am I not aware? I'm avoiding perusing the internet for the time being until I'm sure I'm safe from new and exciting attacks!

    As requested I went through the remove vitrumonde/vundo sticky and have attached the logs.

    So in advance, many thanks for the work you guys and gals do!
     

    Attached Files:

  2. iamwhil

    iamwhil Private E-2

    Sas Log as well.
    Thanks.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome to Majorgeeks.

    We are currently reviewing your logs and will get back to you with a plan of action as soon as possible. Thanks for your patience during this time.

    Kestrel13!
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    Note: Your desktop needs some organisation...a messy desktop provides a perfect hiding place for malware.


    1) Please go to Add or Remove Programs and un-install the following software:

    • Viewpoint Media Player <--- as per step 1 of the R&R.
    • SpywareBlaster v3.5.1 <--- this is very out of date, I will give you the link to the most current version further on down in my instructions.

    2) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank <--- Did you set your start page to about:blank yourself to speed up browser loading? Only fix this line if you didn't choose to do this.
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime <--- note: this is not malware, it is just running unnecessarily at start-up and can be fixed.


    After clicking Fix exit HJT.



    3) Now we need to use ComboFix to remove a bunch of malware files.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    File::
    C:\WINDOWS\bnetunin.exe 
    C:\WINDOWS\diabunin.exe
    
    DirLook::
    C:\fu
    
    
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"=-
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    4) Now Run Ccleaner!

    5) Now download SpywareBlaster 4.1 and install it.

    6) Now delete the old MGTools.exe and the MGTools folder and then go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. .

    7) Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. iamwhil

    iamwhil Private E-2

    Things seem to be running smooth but I don't know if that's just the result of enough ram to take care of the infestation. I ran the tools as you said above and have attached the logs.

    Thanks so much thus far!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds