Virtumonde/Vundo infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by disoriented, Aug 29, 2008.

  1. disoriented

    disoriented Private E-2

    I've been infected by Virtumonde while clicking on a link while browsing on either Mozilla or IE, I don't remember which one I had open. AVG popped up and I quarantined whatever it found. It's still there though because it kept showing up in the SpyBot S&D scan and the popups! I immediately disabled internet access.

    I'm in the process of running all the steps in READ ME FIRST PROCESS and have a problem with the combofix. When dropping the Windows Recovery Console ontop of ComboFix.exe, a window pops up that says:

    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access them."

    So I try switching to admin, by booting into safe mode. When it boots into safe mode, combofix.exe and the windows recovery console is not there. Do I grab my flashdrive and transfer the files on the desktop, or is it not there because I cannot run it while on safe mode? I'm afraid to try because I might mess something up.

    Also... I couldn't get SuperAntiSpyware to remove the malware(Vundos) it found because the blue screen showed up even after the reconfigure. So the step was skipped.

    Thank you.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    If you saved ComboFix.exe and the Microsoft file to the other user's Desktop, then that is the only user account that will see them. If you are going to clean that user account, you need to run the procedure on that account. Running it on the Administrator account in safe mode may help you to get the Recovery Console installed but cleaning the Administrator account will not necessarily fix things in your normal user account unless they are common files and registry keys. So if you want to see those files when you boot in safe mode with the Administrator account, you have to copy the files to the Administrator's Desktop.

    Try running SAS again after you have run Malwarebytes which I assume you have now already run since you are up to ComboFix. Make sure you are using the current version of SAS as given in the READ & RUN ME link.
     
  3. disoriented

    disoriented Private E-2

    So do I drag and drop the recovery console while in safe mode as admin, then go back to my user account and run combofix?

    Yes, I have run Malwarebytes. I'll try running SAS again.

    Thank you.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can do that or you could just log into your user account in safe boot mode if you don't have a problem with permissions trying it on your user account.
     
  5. disoriented

    disoriented Private E-2

    I have completed the process. I hesitantly plugged my network cable back in and I haven't gotten a random pop up.. yet. I'll attach the logs just to make sure they're not hiding.

    Some notes:
    -I re-ran SAS and it did not find anything.
    -While running combofix on safe mode, my desktop never came back but the log did pop up. I had to manually shut down the computer. It seems the log was created, so maybe it's fine.
    -While my computer boots up, a window pops up: "Windows cannot open this file: File: Service Manager.norun" Then it gives me a choice whether I want to use Web service to find the program or Select a program from a list. I just X out.
    -On the taskbar, there is a MSN messenger icon, but I don't have messenger installed when I check "Add/Remove Programs" on Control Panel. I think I uninstalled it awhile back because I don't use it, but why does it still load?
    -I didn't uninstall Viewpoint Player before I started the process. I think I missed it... I shall do that.

    Thank you for your help.
     

    Attached Files:

  6. disoriented

    disoriented Private E-2

    MGlogs
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But in your original scans it did. You should have attach that log so we could see what it found. ;)

    It is not MSN Messenger. It is Windows Messenger which you don't need. We will remove it below. If you have not already uninstall Viewpoint Media Player then uninstall it now.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: Service Manager.norun
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)

    After clicking Fix, exit HJT.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. disoriented

    disoriented Private E-2

    Thank you!

    It seems like AVG put combofix.exe in the virus vault along with other files from C:\System Volume Information\_restore{numbers...

    Should I place another copy of combofix.exe on my desktop or was the one I worked with configured in a certain way for the final steps to work? Also, C:\Combofix is empty. Not sure if there was something in there as well that disappeared.

    I've attached the original SAS log that crashed.
     

    Attached Files:

    Last edited: Sep 3, 2008
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just disable AVG while doing these steps. You need to have ComboFix.exe on you Desktop to complete the instructions given.
     
  10. disoriented

    disoriented Private E-2

    I rebooted and it's running fine, I think.

    You are amazing! Thank you again! :cool
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  12. disoriented

    disoriented Private E-2

    Phew... All done!

    One more question. Should I empty AVG's virus vault? I've attached a log that shows the files in it. I know the PUPs they caught were from combofix, but the 2 trojans, I don't know.

    Many thanks to you and majorgeeks.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you should empty AVG's Vault.


    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds