Virtumonde removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by j0j0, Apr 27, 2008.

  1. j0j0

    j0j0 Private E-2

    Hi,

    I realise that other threads have been opened but none of the solutions seem to work of I've been doing them wrong. Anyway this is how my problem began.

    After installing an addon called MSN discovery onto my computer, I started getting a lot of popupps with different kind of ads and I am now unable to acces to different websites. Facebook and myspace do not load and when I type a search in google it doesn't load either.
    Spybot has identified virtumonde, virtumonde.dll and vundo. I was able to delete vundo thanks to vundofix but all my attemps to delete virtumonde have failed. I've used ad aware, spybot, ccleaner, hijackthis, SDfix.
    None of them has completely removed it since it disapears on the first reboot, but reappears on the second one.
    Could you give me some advice to permanently delete virtumonde without reinstalling windows.

    Thanks
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. j0j0

    j0j0 Private E-2

    Thanks for answering

    I followed the guide that brought me to the page
    http://forums.majorgeeks.com/showthread.php?t=74267
    wich only asks to
    "Please post the contents of C:\vundofix.txt and a new HiJackThis log in the thread you are working in."

    Wich I did, is there another log you need ?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is from the Special Removal Procedures link which is not really the main body of the READ & RUN ME. You need to skip that and follow the rest of the instructions in the READ & RUN ME as I requested. As you can see, VundoFix was of no use.
     
  5. j0j0

    j0j0 Private E-2

    Thanks for answering

    Here are the lats logs
     

    Attached Files:

  6. j0j0

    j0j0 Private E-2

    And the MGtools

    It seems to be working ok now, might reappear after a few reboots though..
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are not clean yet.

    You need to disable Spybot's Teatimer now as requested in the READ ME or it may prevent the below fixes from working. See this: How to disable Spybot's TeaTimer

    Uninstall the below software:
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Messenger Plus! Live <-- should have been uninstalled in step 0 of the READ ME. It is quite possibly even the reason for your Vundo infection.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: {ac48fb1b-8ef2-c42b-c2a4-ea645465d0dd} - {dd0d5645-46ae-4a2c-b24c-2fe8b1bf84ca} - C:\WINDOWS\system32\fnwsqppb.dll (file missing)
    O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\wTmp\kmdmns2.exe
    O20 - Winlogon Notify: khfdbAtQ - C:\WINDOWS\

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. j0j0

    j0j0 Private E-2

    Here are the logs
    About messenger plus, its been on my computer and friends for a few years without problems as I unchecked the advertisements on install.
    And I thought I had disabled teatimer since it wasn't at the same location and same name (spybot in french) should be off now anyway
    And couldn't find the line

    O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\wTmp\kmdmns2.exe

    Thanks for answering

    ps: what did that .reg do ?
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may well be but the application is still not trust worthy. It's your decision in the end but this program has cause many tens of thousands of PCs to get infected. And Virtumonde has also been caused by this program. Who knows what tricks they pull during program updates.

    It removed some registry entries that ComboFix added that are unnecessary.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
     
  10. j0j0

    j0j0 Private E-2

    Thanks a lot for your time and helping unknown strangers get rid of there spywares, you do a very good job don't think I would have gotten rid of it without you.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds