Virtumonde removal issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by nraford, May 23, 2008.

  1. nraford

    nraford Private E-2

    Hi guys,

    First, thanks so much for your service. I followed your tutorials to the letter (as best as I could) and removed about 95% of the problems on my machine. You guys are really life savers!

    After following all the instructions for my XP machine, I still seem to have some persistent problems with Virtumonde. I would appreciate your help looking over my logs, which are attached below. The rest of the logs will follow in my second post.

    Thanks in advance and please let me know what I can do to help.

    Best,
    Noah
     

    Attached Files:

  2. nraford

    nraford Private E-2

    Here are my second batch of log files. Thank you!

    Noah
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is no point in running MalwareBytes if you don't have the program fix all that it finds. Please re-run it and remove the malware, then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file and the new MalwareBytes log.
     
  4. nraford

    nraford Private E-2

    Tim,

    Thanks for the quick reply. I'm not sure why it said "no action taken" as I'm pretty sure I instructed it to fix these problems.

    Either way I'm rescanning now and will get back to you with the logs you requested as soon as it is finished. It doesn't seem to be finding anything now, but I'll keep it going just to be safe.

    Sorry for the confusion.

    Best,
    Noah
     
  5. nraford

    nraford Private E-2

    Hi Tim,

    Attached are the re-scanned logs. It turns out I did repair the previous logs, but accidentally clicked "View Report" before doing so.

    The second scan only found one instance of malware, so perhaps it has resolved itself?

    Thanks,
    Noah
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem....only a few things to do:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  7. nraford

    nraford Private E-2

    Brilliant, thanks Tim.

    Attached are my logs again. Looking forward to the final verdict.

    Best,
    Noah
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.....now download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  9. nraford

    nraford Private E-2

    Thanks Tim! You're a star.

    Everything seems to be working now. Thanks for all your help.

    Best,
    Noah
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds