Virtumonde/Smitfraud/others PLEASE HELP!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by stopthemusic, Dec 22, 2008.

  1. stopthemusic

    stopthemusic Private E-2

    Hey everyone. It started with Avast notifying me that I had a virus (Win32.agent.wmrr, I think?). I moved that item to the chest, did a scan, and found nothing else. I later ran Spybot S&D, which found Virtumonde, Smitfraud, and Win32.xxxxx (assorted). I deleted those items, rebooted, and scanned again with Spybot. And lo and behold, everything is back again. :(

    I was getting IE pop-ups (don't know if I still am...I haven't been back online on that computer in some time), and a balloon keeps appearing in my tray telling me that automatic updates have been turned off. When I try to turn them back on through Windows Security, I get an "I'm sorry" message, and when I go to the control panel, it says they're already on. :confused

    I want to run the Smitfraud fix, but I have no idea if Virtumonde and Smitfraud are connected, and I don't want to get rid of one only for it to come back because the other is still there.

    I see many people referring to something called "Hijack This," but I have no idea what that is.

    This is really frustrating, and I'm traveling in a few days so I really need this computer to be in top shape, so I'd really appreciate any help!
     
  2. stopthemusic

    stopthemusic Private E-2

    Okay, so with Malwarebytes, I was able to get rid of mostly everything, and I can now turn on automatic updates. However, I'm still get pop-ups, and Malwarebytes keeps detecting these two keys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo)

    MB deletes them, but they reappear upon reboot.

    This is really frustrating, and I don't want to give up and do a factory restore on my computer, because I don't have much time. Please help!!! =(
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds