Virtumonde/Vundo impossible to remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by tarmstro, Aug 13, 2008.

  1. tarmstro

    tarmstro Private E-2

    Hi:

    I cannot remove Virtumonde/Vundo from my system. I already ran nod32, SuperAntiSpyware, SbybotS&D and MBAM in a row, all off them while not beeing connected to the internet at all. After all the tools said they removed things and cleaned my system, I ran them all again just to be sure, and none of them detected anything, so I was very happy!

    But after beeng connected for only about 10 minutes to the Internet (just using YahooMail and Facebook), nod32 detected Virtumonde trying to download some .exe file from the internet! I ran all the tools again, but now they cannot remove it.

    Attached you will find all the logs the FAQ asks to upload, taken from my last full scan of my system (yesterday night). I also ran MGtools a couple of minutes ago, so those logs are also attached.

    PLEASE HELP!!!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In the future please be more exact in following instructions. You did not update Malwarebytes and SUPERAntiSpyware to the latest definitions before running the scans. Thus they missed some items that the new detections may have helped remove.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 12

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    O2 - BHO: (no name) - {08D66F80-CDA5-4923-AE06-519F770DE171} - C:\WINDOWS\system32\cbXOIbyx.dll
    O2 - BHO: (no name) - {FFFB03AD-A461-4B99-9A23-D3B127D7C995} - C:\WINDOWS\system32\ddcbASjK.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [BM2f454ebb] Rundll32.exe "C:\WINDOWS\system32\vpurabhl.dll",s
    O4 - HKLM\..\Run: [2c767d27] rundll32.exe "C:\WINDOWS\system32\lrooyuew.dll",b
    O4 - HKCU\..\Policies\Explorer\Run: [NT Printing Service] chkdsks.exe
    O20 - Winlogon Notify: ddcbASjK - C:\WINDOWS\SYSTEM32\ddcbASjK.dll

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. tarmstro

    tarmstro Private E-2

    chaslang:

    Thanks for your help. I did everything you tols me, and after looking at the logs I noticed not everything was succesfully removed. So I tryed to manually remove the problematic file, but I could not access it!

    I discovered that for some reason the Documents and Setting folder for one of my users (I have separate accounts for each of my family members) was marked as 'private'. I made it public, went over your instructions, and now it worked.

    Afterward I ran SAS, S&D and MBAM again. Only MBAM detected Virtumonde/Vundo, but now only inside a system restore backup. This was cleaned without problems, and then I ran the three tools again just to be sure :). Now everything seems to be clean.

    So THANK YOU VERY MUCH !!!!

    Thomas


    PD: I intend to folof up this thread in some days just to let you now how it goes...
    PD2: looks that I will have to tell my little 6-year son how to keep away of trouble...
    PD3: you may add the 'private' folder issue to your standard instructions...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    According to the logs that you attached, you are still infected and you did not uninstall the old Java program I asked you to uninstall.

    If you have run Malwarebytes & SAS after attaching the logs, they may have cleaned up some of the problems. I need to see the new logs and I need to know did you update as I requested.

    Now run this new version of MGtools.exe and attach a new C:\MGlogs.zip file.
     
    Last edited: Aug 16, 2008
  5. tarmstro

    tarmstro Private E-2

    Thanks again for the help. I now did the following:
    1. Updated sas, s&d & mbam
    2. Ran SAS and S&D, no detections.
    3. Ran MBAM, which reports infected files in different quarantine areas (I deleted them manually) and inside a system restore point (I also deteted it)
    4. Ran MBAN again, no detections found :)
    5. Ran the new MGTools as directed, to get new logs.
    I am attaching all logs again.

    I don't know how to delete Java 1.5 r12. Does not appear separately in Add/Remove apps CPL, but Java CPL does report as you see in attached screenshots (sorry about spanish WinXp :). Do you have any Idea on how to uninstall this?

    Thanks again for the help, regards,

    Thomas
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now doubleclick the fixme.reg file on your desktop made in the previous fix and allow it to be added to the registry.

    Now run Ccleaner!

    Now download the current version of MGtools.exe and run it to create a new log.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!

    DO NOT reboot or power down you PC after attaching these logs. If you are still infected, it is spreading on each power down and/or reboot.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds