Virtumonde will not remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by angelicdiablo515, Jan 18, 2009.

  1. angelicdiablo515

    angelicdiablo515 Private E-2

    I have Webroot System Analyzer and it keeps seeing a Virtuemonde infection. This computer was a lot worse but I have removed several viruses and other spyware thanks to the help from the XP cleaning procedure.

    Any suggestions would be greatly valued

    Malwarebytes will not load: Runtime error '0' and Runtime error '440' Automation error. I will need to uninstall and reinstall and scan to get the logs but will have to do tomorrow.
     

    Attached Files:

  2. angelicdiablo515

    angelicdiablo515 Private E-2

    This is the results from System Analyzer

    - <results>
    - <section name="header">
    <rc>1120</rc>
    <sid>0</sid>
    <lang>en</lang>
    <loc>USA</loc>
    <sourceid>6</sourceid>
    <computer_name>MAMABEAR011905</computer_name>
    <report_name>MAMABEAR01190514</report_name>
    <report_date>1/18/2008</report_date>
    <report_time>06:20 PM</report_time>
    </section>
    - <section name="spyscan">
    - <spies category="Trojans">
    <needtoknow>A Trojan horse is generally disguised as a harmless software program, but is a malicious program that can allow a hacker to make changes or take control of your computer.</needtoknow>
    </spies>
    - <spies category="System Monitors">
    <needtoknow>A system monitor can track the private use of your computer, including the entry of passwords and account numbers, and can report information to others over the Internet.</needtoknow>
    </spies>
    - <spies category="Adware">
    <needtoknow>Adware is any software application that may display advertisements on your computer. Some adware may track your surfing habits.</needtoknow>
    <spyname serial="vm103">virtumonde</spyname>
    </spies>
    - <spies category="Adware Cookies">
    <needtoknow>Tracking cookies are small files downloaded from websites to record information. They aren't generally harmful to your computer, but they are used to track your surfing habits and sometimes include personal information including usernames and passwords.</needtoknow>
    </spies>
    <recommend>Adware was found on your computer. We recommend evaluating whether these programs should be removed.</recommend>
    <spyscore>145</spyscore>
    </section>
    <section name="coupons" />
    <section name="footer" />
    </results>
     
  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

  4. angelicdiablo515

    angelicdiablo515 Private E-2

    here are the new logs thanks!
     

    Attached Files:

  5. angelicdiablo515

    angelicdiablo515 Private E-2

    the virtumonde seems to be gone... thank you very much for your time and help!
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Pre-Instructions:
    1. First, please disable any antivirus and/or antispy programs you have installed so they will not block this fix.
    2. Print out these instructions or save them to a text file so that you can operate with All Browser Windows CLOSED.

    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed.


    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Again, make sure ALL browser windows are closed when you click FIX.

    Step 3:
    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Step 4:
    Default Security Settings

    To Default Security Settings:
    For Internet Explorer 6 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up navigate to the Security Tab and click Default Level for the following:
    • Internet
    • Local Intranet
    • Trusted Sites
    • Restricted Sites.
    Click OK to exit.

    For Internet Explorer 7 users:
    Click Start > Run > type inetcpl.cpl and press ENTER, when Internet Properties comes up, navigate to the Security Tab and simply click the "Reset all zones to default level" button. Click OK to exit.

    NOTE: If it's "grey" then it's already at the default level.​
    Step 5:
    Please download ATF-Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF-Cleaner menu to close the program.​

    Step 6:
    Next I would like you to install the current version of Sun Java: Sun Java Runtime Environment

    Step 7:
    Finally, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds