Virtumonde keeps reappearing

Discussion in 'Malware Help (A Specialist Will Reply)' started by ch33zm0, Dec 3, 2007.

  1. ch33zm0

    ch33zm0 Private E-2

    Hi. I have been having some trouble with my pc. I have followed all the steps outlined in the Malware removal threads, as well as the special removal proceedures, but this Virtumonde, or Vundo Trojan keeps showing up in my AdAware scans. When I ran VundoFix the first time it caught the infected files and removed them. Now when I run it it shows no problems. My pc is running very poorly right now, and I wonder if you can help with this. All required logs are attached here and to the next post. I appreciate any help you can offer. I am preety novice at this stuff, so be gentle :)
     

    Attached Files:

  2. ch33zm0

    ch33zm0 Private E-2

    Here are the remaining logs. Thanks again!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    It has taken you quite awhile to post these logs. You ran the scans around Nov 21st and it is now Dec 3rd. Why did you wait so long to attach the logs and ask for help?


    You forgot to attach the log from CounterSpy. But don't worry about it now as long as you are sure that you had it Quarantine or Delete everything it found. If you did this, then uninstall CounterSpy now. Otherwise rescan and Quarantine everything and then uninstall CounterSpy. Then continue to the below.


    Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply See: HOW TO: Attach Items To Your Post
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    4. the ComboFix log
    Make sure you tell me how things are working now!
     
  4. ch33zm0

    ch33zm0 Private E-2

    Hey chaslang. I know it was a while between when I ran the scans and when I posted, but everything seemed to be running fine, and then it wasn't. Not very descriptive, but that's sort of the way it was. One day it was fine, I ran cans daily just to make sure, then the next day the Vundo Trojan showed up again. And then it kept showing up. Anyhoo, I have rerun everything in the Malware sticky, and cleared stuff up again, with the new logs from Spybot, AVG antispyware, and MGtools attached. I will also attach the log from combofix on the next message. Everything seems to be running ok right now, and there were no problems or errors when running the scans. Thanks for your time, and let me know if you find anything.
     

    Attached Files:

  5. ch33zm0

    ch33zm0 Private E-2

    Never mind. I already attached the combofix log :zzz
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please uninstall the CounterSpy trial as requested in my last message.

    Uninstall the below 10 old versions of Sun Java software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {E186418F-C3E9-43D4-A2BC-7DCC1A2AA1A0} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O20 - Winlogon Notify: vtuvspp - vtuvspp.dll (file missing)
    O20 - Winlogon Notify: winjyp32 - winjyp32.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. ch33zm0

    ch33zm0 Private E-2

    I have run what you asked, without any difficulties. Upon rebooting I was given the message:

    Windows - No Disk

    Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c

    Cancel Try Again Continue

    I hit continue, and things worked ok. Just wondering if this was normal. Other than that, start up was fine and things are running smoothly.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are two more old Sun Java versions to uninstall. I missed them the first time.
    Java 2 Runtime Environment, SE v1.4.2_05
    Java 2 Runtime Environment, SE v1.4.2_06

    Also the below file showed up. Please delete it.
    C:\WINDOWS\system32\drivers\xfug^iia.sys

    Let me know if you have any problem deleting this file and make sure it is still gone after another reboot.

    Also tell me if you still get that error message any more at boot up. It may have just been due to what Avenger was doing at reboot.

    Everything else looks good.
     
  9. ch33zm0

    ch33zm0 Private E-2

    Hey chaslang. Ok, those files were all deleted successfully. The message that popped up the first time after running avenger then rebooting did not reappear. I have attached the avenger file, not that it says much. I ran ccleaner again, but the cp seems to be running quite well. Thanks for all your help and patience.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds