Virtumonde + MS Juan Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by VietPho, Dec 16, 2008.

  1. VietPho

    VietPho Private E-2

    I have read the instructions you guys have given to another user on this forum about this same problem.

    I've attached the necessary log files.
     

    Attached Files:

  2. VietPho

    VietPho Private E-2

    Morelogs
     

    Attached Files:

  3. VietPho

    VietPho Private E-2

    I am currently doing a final scan using SAS and Malware Antivirus and spybot to see what is still on my computer.


    I am pretty sure that "MS Juan" registry is the one that is still on because I can't delete it even manually for some reason.


    It's amazing how this virus got installed onto my computer... I didn't even open any .exe files.
    All I did was browsed this forum (WARNING DO NOT GO TO THIS WEBSITE) : phimhongkong.com which is a vietnamese site for watching asian viet dubbed drama.
    This actually happened to my parent's computers last year; they went onto the website and it destroyed their computer and I had to reformat it for them.

    Is there a way to report that website to the FBI so they can investigate? I'm not sure what pages on there that caused this virus but it was in one of the "Phim bo" sub forum pages.

    Sorry, I digressed. I will post the results of my final scan in the next post.
     
  4. VietPho

    VietPho Private E-2

    Final Scans:


    Can't remove the registry. Any ideas guys?


    MBAM:
    SAS
     

    Attached Files:

  5. VietPho

    VietPho Private E-2

    This is frustrating.

    My SAS claims that it deletes the stuff in

    But it always re-appears.
     
  6. VietPho

    VietPho Private E-2

    I've attached the screenshot of what I get when I try to delete the registry file manually.

    "Cannot delete MS Juan: Error while deleting key."


    Is there a program out there that can exterminate this reg folder?
     

    Attached Files:

  7. VietPho

    VietPho Private E-2

    Hmm. I still can't remove the registry but it looks like I am able to browse the internet without any popups so I guess i'm safe for now.
     
  8. VietPho

    VietPho Private E-2

    Hmmm ??????
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your bumping has cost you at least a day.

    Don't Bump! It Only Hurts You!!!


    We are currently trying to catch up to threads that are on page 10 ....so we will get to you when you come up in the queue. Which you would have if you hadn't bumped it. :(
     
  10. VietPho

    VietPho Private E-2

    Files Infected:
    C:\WINDOWS\system32\efcASMFV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.


    Updated MBAM today and it found that.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you run MBAM, you have to tell it to fix what it find.

    Please re-run and attach the logs for:
    SAS
    MBAM
    Combo
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  12. VietPho

    VietPho Private E-2

    Thanks for helping!

    Here are the logs for:

    SAS
    MBAM
    Combo
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why do you keep running MBAM and not having it fix what it finds? Are you also not having SAS fix what it finds?
    And you did not attach a new MGLogs.zip
     
  14. VietPho

    VietPho Private E-2

    Here's the final log
     

    Attached Files:

  15. VietPho

    VietPho Private E-2

    I keep getting an popup afterwards saying it can't be deleted.


    I tell it to remove on setup but it doesn't.

    As for SAS, it claims that it is removing those 32 reg files but when I rescan (even if I don't reboot), it detects those same reg files again.
     

    Attached Files:

    Last edited: Dec 21, 2008
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I wish you had stated that a while ago.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me if you get a success message.

    And for added effect:

    download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  17. VietPho

    VietPho Private E-2

    I did not find this in the list:
    "O20 - AppInit_DLLs: mlnnxf.dll"

    I've attached the hijackthislog.


    (Not sure where Avenger log got saved)

    I've attached the new MGlog



    Conclusion: The MS Juan registry was removed! Thanks!

    But can you check to see if there's anything else I should worry about?
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know......If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  19. VietPho

    VietPho Private E-2

    Thanks for the help everyone!

    Now I have to figure out what virus my lil bro got on his laptop :(

    Apparently, the virus he got deletes his recycle bin and disables all the mc affee and other firewalls
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome......please start a new thread regarding your other computer. :)
     
  21. VietPho

    VietPho Private E-2

    Crap. I've been infected with another Vundo malware.

    I'll report all the info again soon. Should I start a new thread since this is a newer/stronger version of vundo?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please start a new thread. Make sure you download the latest version of the tools.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds