Virtumonde.sdn issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by 350TWIN, Jun 19, 2009.

  1. 350TWIN

    350TWIN Private E-2

    Comp is slow to start up and mozilla runs slow. I did a bunch of scans and Spybot found this: Virtumonde.sdn. It would error when trying to delete. All other scans were basically clean. Ran Vundofix and it found nothing. Did all the Read and Run first and here is the info. Ran Spybot after the read/run and virtumonde still came up. Thanks for your help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the log from running Combofix and you need to re-run MGTools by double clicking on the C:\MGtools\GetLogs.bat file and this time making the agreement to run HJT.
     
  3. 350TWIN

    350TWIN Private E-2

    Thanks. I can't run the combofix, says it is incompatible with 64 bit. Anyways, here is the new MGTools. Thanks again.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please double clicking the GRK64.bat file (within the MGTools folder). If it runs a notepad window will popup with a runkeys.txt log. Also it should add the runkeys.txt log to the C:\MGlogs.zip file. Attach the C:\MGlogs.zip file to your next message.
     
  5. 350TWIN

    350TWIN Private E-2

    It didn't run. Tried to double click and also right click (run as admin), and with both a window popped up initially, but then just disappeared. No notepad was generated. I checked the zip file and nothing named runkeys.txt is in there. Here is the C:\MGlogs.zip anyways.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt attach anything. :(

    Go to start / run / type: cmd
    when the command prompt opens, type:
    cd c:\mgtools

    that will change you to that folder, then type:
    GRK64.bat and hit enter.
    You need to tell me what happens.
     
    Last edited: Jun 23, 2009
  7. 350TWIN

    350TWIN Private E-2

    It says:
    Running scan with GRK64.Bat-<c> 01/31/2008 By Chaslang.

    Note: Ignore any error messages about not finding registry keys!
    Just wait for the program to finish running!!

    The system cannot find the batch label specified-Rookit5

    c:\MGtools>_

    Then it doesn't do anything else.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Fixed in the new version. Thanks!


    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the new c:\MGlogs.zip file which should now include the runkeys.txt log
     
    Last edited: Jun 23, 2009
  9. 350TWIN

    350TWIN Private E-2

    Ok here it is.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean ( after putting you thru all that effort). The only thing I would suggest is that you clean out your temp folders and remove these items:
    C:\Users\BrianJonni\AppData\Local\Temp\eYNpfs04.exe.part
    C:\Users\BrianJonni\AppData\Local\Temp\is-HA857.tmp
    C:\Users\BrianJonni\AppData\Local\Temp\LhIDenSf.exe.part
    C:\Users\BrianJonni\AppData\Local\Temp\ppcrlui_1616_2.ui
    C:\Users\BrianJonni\AppData\Local\Temp\ppcrlui_2148_2.ui
    C:\Users\BrianJonni\AppData\Local\Temp\ppcrlui_3612_2.ui
    C:\Users\BrianJonni\AppData\Local\Temp\ppcrlui_3696_2.ui
    C:\Users\BrianJonni\AppData\Local\Temp\ppcrlui_3776_2.ui

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds