Virtumonde, Smitfraud and others

Discussion in 'Malware Help (A Specialist Will Reply)' started by glenwill, Dec 15, 2008.

  1. glenwill

    glenwill Private E-2

    I started having popups on this computer about a week ago. I ran through all of the steps in the read and run first guide, and it appeared to be successful. Rerunning several of the programs found no spyware. Yesterday my son was on it, and started getting popups again. I don't know if it got reinfected, or was not really clean in the first place.

    I have rerun all of the steps, and am attaching the logs. This time when I ran, it found virtumonde, smitfraud-C and a rootkit I don't recall the name of. After running, I reran a few scans and both virtumonde and smitfraud-C show up still.

    Thanks for your help,
    Glen
     

    Attached Files:

  2. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Hi glenwill.

    On the 14th you ran SuperAntispyware a few times. Still have thos logs?


    ------------
    "C:\Documents and Settings\bwillits\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    supera~1.log Dec 14 2008 3180 "SUPERAntiSpyware Scan Log - 12-14-2008 - 19-56-35.log"
    supera~2.log Dec 14 2008 48505 "SUPERAntiSpyware Scan Log - 12-14-2008 - 20-32-01.log"
    supera~3.log Dec 14 2008 1839 "SUPERAntiSpyware Scan Log - 12-14-2008 - 20-53-42.log"
    -------

    You also have muliple users on this box, did you run the cleanings on each?

    While you are on that - Here's the smitfraud instructions:
    http://forums.majorgeeks.com/showthread.php?t=74265
     
  3. glenwill

    glenwill Private E-2

    Thanks so much for looking at my case. My apologies for the missing file. I thought for sure I had done a second post with the SuperAntiSpyware log file, but apparently I messed something up. It is attached.

    I've also attached the pre-clean log from the Smitfraud tool.

    Regarding the other users, this is a work laptop and they are prior users of this laptop. I can actually remove them as they are not needed. They are domain users not local users. Any reason for me to not just delete their folders in documents and Settings? None of the other users have been logged on in months.

    Glen
     

    Attached Files:

  4. glenwill

    glenwill Private E-2

    I just ran the Smitfraud fix, and attached is the log after running it. The before log is in my last post.

    Thanks,
    Glen
     

    Attached Files:

  5. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Not if you don't need them. Delete the user accounts via Control Panel > User Accounts and then remove any left over folders. The bwillits and Skundu accounts seem to be the focus of the problem.. The procedures should be run fully on both.
     
    Last edited by a moderator: Dec 18, 2008
  6. glenwill

    glenwill Private E-2

    I ran the procedures on bwillits. skundu is one of the domain logins, so I can't log into that account. I'll try to delete it tonight when I get home, along with the other unused accounts.

    Glen
     
  7. glenwill

    glenwill Private E-2

    I deleted skundu's documents and settings folder. I tried to delete several other users (gmahendru and rolsen), and I could delete all but the NTUSER.DAT and NTUSER.DAT.LOG files. Explorer complained that those files were in use.

    Glen
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs for the bwillits account are clean.


    Are you saying you want to delete all of other domain user folders which would appear to be the below user folders?
    Code:
    "C:\Documents and Settings\"
    GMAHEN~1      Jun  9 2008              "gmahendru"
    GWILLITS      Jun  9 2008              "gwillits"
    MDAS          May 13 2008              "mdas"
    ROLSEN        Apr 24 2008              "rolsen"
    SKUNDU        May  5 2008              "Skundu"
     
  9. glenwill

    glenwill Private E-2

    Yes, correct. I deleted all of the accounts you listed. I booted into safe mode and was able to delete the NTUSER.* files I indicated below that I could not delete. That was for the gmahendru and rolsen domain accounts.

    I think I am clean now. Thank you so much for your help.

    Glen
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  11. glenwill

    glenwill Private E-2

    Thanks again Chaslang, I followed all of the steps and the computer is running fine so far. I appreciate all your help.

    Glen
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds