Virtumonde, Smitfraud-C, Personal Guard 2009 Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by blnoni, Nov 4, 2009.

  1. blnoni

    blnoni Private E-2

    On Oct 30, 2009 I clicked the wrong button and ended up with Personal Guard 2009, which I can't get rid of. After running numerous cleaning programs this keeps returning along with Smitfraud-C and Virtumonde.
    I faithfully ran through your entire Windows XP Cleaning Procedure only to have Personal Guard 2009 pop right back up.
    I am attaching the logs that you recommended and am really looking forward to any help I can get.
    Thank You!
    View attachment SUPERAntiSpyware Scan Log - 11-04-2009 - 02-32-36.log

    View attachment mbam-log-11-4-2009 (13-50-26).txt

    View attachment RRlog.txt

    View attachment MGlogs.zip
     
  2. blnoni

    blnoni Private E-2

    Attached is the fifth log recommended to post. After running ComboFix Smitfraud-C still showed up while running Spybot.

    View attachment ComboFix.txt
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Not quite. You did not download and install SUPERAntiSpyware and Malwarebytes from out links! You are YEARS out of date.

    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Also delete the below since this is not where we asked you to save MGtools to:
    C:\Documents and Settings\Colleen\Desktop\MGtools.exe

    Uninstall the below old versions of software:
    Spybot - Search & Destroy 1.4

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\about.htm
    F2 - REG:system.ini: Shell=Explorer.exe logon.exe
    O4 - HKLM\..\Run: [personalguard] C:\Program Files\Personal Guard 2009\personalguard.exe
    O21 - SSODL: SysNet - {6B1E1556-DE7F-41F7-8295-89A585FD2A99} - C:\Documents and Settings\All Users\Microsoft AData\sysnet.dll

    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the new logs from proper versions of SUPERAntiSpyware and Malwarebytes.
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 7, 2009
  4. blnoni

    blnoni Private E-2

    Thank you so much for your reponse. I didn't realize you needed to be so exact using the procedure you outlined. Before I got your response, I kept cleaning things out until finally it would boot only to a blank screen with cursor. No matter what I did I could get no further even in Safe Mode.
    So I bit the bullet, formatted and clean installed. What a lot of work!
    Again thanks and I guess you can close this thread.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It is extremely important to follow instructions exactly. We even stated not to do anything on your own once the procedure is begun and to only do what we request. ;)

    Since you have reinstalled, you should work thru the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds