Virtumonde issues after removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nikon6, Jul 1, 2008.

  1. Nikon6

    Nikon6 Private E-2

    I ran Spyware Doctor (after Ad-Aware and Spybot S&D) and it found Virtumonde files. It got rid of them, the ads are gone, pc runs at an ok speed but now my IE is only half working (some pages work and some don't, most don't load at all) and my Norton's is saying my subscription expired. Now what do I do? :(
     
  2. Nikon6

    Nikon6 Private E-2

    never mind I think I am good now. I only have one problem, my clock didn't go back to the way it was when combo fix was done. Anyone know how to fix that?
     
  3. Nikon6

    Nikon6 Private E-2

    never mind again. all fixed. Sorry. I'm such a noob
     
  4. abri

    abri MajorGeek

    Hi Nikon6,
    Welcome to Major Geeks!

    Thanks for fixing your own computer. :-D

    How did you fix your Internet Explorer problem? People encounter this sometimes when trying to remove malware and it would be helpful to know what you did.

    If you'd like us to look at your logs, please attach them. In particular with Virtumonde, it leaves single files around that can start the infection again and by looking at your logs from the READ & RUN ME, we can locate them and give you instructions for deleting them.

    abri
     
  5. Nikon6

    Nikon6 Private E-2

    Thank you! You're welcome :-D I finished running the scans on the malware removal guide. I jumped the gun and thought since spyware doctor had removed the obvious virtumonde files that my pc was clean but it wasn't. I will attach my logs just in case.. it removed all kinds of crap. Scary!
     

    Attached Files:

  6. Nikon6

    Nikon6 Private E-2

    two more logs
     

    Attached Files:

  7. Nikon6

    Nikon6 Private E-2

    arg and now I am getting this error message when Yahoo Online Protection tries to run

    C:\Progra~1\Yahoo!\YOP\yop.exe

    This application has requested the Runtime to terminate it in an unusual way. Please contact the application's support team for more information.
     
  8. abri

    abri MajorGeek

    Hi Nikon6,

    The following link gives help information for Yahoo Online Protection. You can link from there to their help site for direct email help.

    http://help.yahoo.com/us/sbc/tutorials/olp/tut_olp_index.html

    Your newfiles log is missing almost all the information about your computer. Did you get any error messages when you ran the MGTools?

    Please do the following:


    1) Go to add/remove programs and uninstall the below:

    Java(TM) 6 Update 6

    2) Reboot after uninstalling the above.

    3) Install the current version of Sun Java from: Sun Java Runtime Environment

    4) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    5) Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (Note: if using Vista, don't double click, use right click and select Run As Administrator). Select Do a system scan only). In the box that opens, find the following entries and put a checkmark next to them (if you need some of them to be in the trusted zone, leave them). After check-marking them, close all your open browser windows and click on FIX:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Deb/My%20Documents/start.htm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

    Do the following belong to programs you are currently using and need or want to keep? If not, please fix them as well.

    O9 - Extra button: Help - {338FDCD2-DD11-4C3D-902C-05ADD8E43FB8} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
    O9 - Extra button: ComcastHSI - {7D20E863-4991-48EC-BD4A-22435A43DA4D} - http://www.comcast.net (file missing) (HKCU)
    O9 - Extra button: Support - {A94C44B6-23AC-40DE-89CB-0921A79EE68E} - http://www.comcastsupport.com (file missing) (HKCU)
    O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
    O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et0_x.cab


    Does the following program need to load at startup? If not, please fix it as well.

    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

    After you click fix, just close hijackthis.


    6) Next I would like to have you use ComboFix to remove some files.


    • Make sure that combofix.exe (cf.exe) that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):


    Code:
    KILLALL::
    
    FILE::
    C:\WINDOWS\SYSTEM32\acfwyhtq.tmp
    C:\WINDOWS\BM37060d2f.xml
    
    FOLDER::
    C:\Program Files\Enigma Software Group
    
    REGISTRY::
    
    [-HKEY_CURRENT_USER\Software\Kazaa]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\knight]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "HideLegacyLogonScripts"=-
    "HideLogoffScripts"=-
    "RunLogonScriptSync"=-
    "RunStartupScriptSync"=-
    "HideStartupScripts"=-
    
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "HideLegacyLogonScripts"=-
    "HideLogoffScripts"=-
    "RunLogonScriptSync"=-
    "RunStartupScriptSync"=-
    "HideStartupScripts"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe (cf.exe)
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below


    Note: Do not mouseclick combofix's window while it is running. That may cause it to stall.


    7) Now run CCleaner at the default setting with the Windows tab as the top one.

    8) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip along with the Avenger or Combofix log.


    Let me know how things are running now?

    abri
     
  9. Nikon6

    Nikon6 Private E-2

    thanks abri! I did as you asked and here are the new logs..
     

    Attached Files:

  10. Nikon6

    Nikon6 Private E-2

    Something is still running viruses on my pc :(
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are the exact problems that cause you to say this?

    I still see Kazaa Media Desktop 2.1 installed. This should have been uninstalled in step 1 of the READ & RUN ME.

    Did you uninstall your Symantec Antivirus program? It appears to be broken as the below lines indicate:
    O23 - Service: NAV Alert - Unknown owner - C:\PROGRA~1\Navnt\alertsvc.exe (file missing)
    O23 - Service: NAV Auto-Protect - Unknown owner - C:\PROGRA~1\Navnt\navapsvc.exe (file missing)
    O23 - Service: Norton Program Scheduler - Unknown owner - C:\PROGRA~1\Navnt\npssvc.exe (file missing)
     
    Last edited: Jul 4, 2008
  12. Nikon6

    Nikon6 Private E-2

    Kazaa isn't installed, it's a file stuck somewhere. When I try to uninstall via add/remove programs it says the file is missing.

    I uninstalled nortons and put mcafee on. mcafee found viruses, spyware doctor found some as well after everything was clean the other night.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you a patch to remove it.

    You need to show me exactly what and where they are finding things. Since we have not finished all of your cleanup and final instructions, they could merely be detecting quarantines and/or System Restore.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run this Norton Removal Tool (SymNRT) reboot and then run it one more time.

    Now copy the bold text below to notepad. Save it as fixKaz.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
     
  15. Nikon6

    Nikon6 Private E-2

    ok it worked! thanks! here are the logs!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to NAV Alert
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Services (if you do not find them or get any errors, just continue):
      • NAV Auto-Protect
      • Norton Program Scheduler
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste NAV Alert into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
      • NAV Auto-Protect
      • Norton Program Scheduler
    • Now exit HJT but do not reboot if it tells you it needs to. We will do that further down.
    Is the below a start page you setup?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Deb/My%20Documents/start.htm



    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.




    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. Nikon6

    Nikon6 Private E-2

    So far I have only done up to the combo fix part. When I ran that, McAfee blocked Trojan-PWS.Bancos twice and the program RemAdm-ProcLaunch!171.
    I also got the error that windows cannot open pv.cfexe like a million times.

    PS - oh and yes, that start page is one that I created with my favorite links that I use often on it.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated in the original instructions for using ComboFix
    And also this was stated:
    You must either shutdown McAfee or tell it not to block it from running. The detection is not malware. It is detecting ComboFix which is what you are trying to run to fix problems.
     
  19. Nikon6

    Nikon6 Private E-2

    I'm trying to attach the logs but it won't let me.. says I have already attached this file in this thread..
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This means they are the exact same logs. You are supposed to be getting new logs by running ComboFIx as requested and by running GetLogs.bat as requested.
     
  21. Nikon6

    Nikon6 Private E-2

    oops sorry I had run the combofix but forgot the getlogs part. :eek: Here you go..
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the new ComboFix log. Also it appears that you did not do the step with the fixME.reg patch or you did not get a success message that I asked you to tell me about.
     
  23. Nikon6

    Nikon6 Private E-2

    Here's the combofix log..

    I did the fixme patch and it said it worked! I can try it again..
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes please do and then attach a new MGlogs.zip file after running GetLogs.bat again.
     
  25. Nikon6

    Nikon6 Private E-2

    ok I ran the patch again, it worked again, I ran ccleaner again, I ran getlogs again and here is the file..
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this time the patch really worked properly.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  27. Nikon6

    Nikon6 Private E-2

    thank you so much chaslang.. my internet explorer is running kinda slow but other wise everything seems ok. I should say.. it is very slow to open, then not so bad once it's open. No ads or anything..
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is it only the 1st time you open and IE window or everytime. It may just be due to what addons you have. Click Tools, Manage Addons and disable all the addons. The exit IE. Then rerun IE. Any change?
     
  29. Nikon6

    Nikon6 Private E-2

    I disabled them all, still slow. It's every time I open a new window.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then you can reenable your addons. You may just be seeing normal speed of how IE7 loads.
     
  31. Nikon6

    Nikon6 Private E-2

    well, it never used to load that slow til I got malware on my pc. Maybe I will just uninstall IE and try firefox. Thanks chaslang!
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    FireFox is know for having a slow load the first time.

    You could try posting in the Software Forum to see if there are any tricks for IE7. Possibly a reinstall of IE7 or a re-registering of certain files may help.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds