Virtumonde

Discussion in 'Malware Help (A Specialist Will Reply)' started by cocoabutter, Jun 16, 2008.

  1. cocoabutter

    cocoabutter Private E-2

    Hey,

    I had problems with Virtumonde trojan removal. I went through READ & RUN ME FIRST. Now, everything seems fine, but I'm not really sure if I got rid of the trojan. I'm posting you required logs. Thank you for your help.
     

    Attached Files:

  2. cocoabutter

    cocoabutter Private E-2

    I'm also attaching MGlogs.zip

    And I forgot to tell you, that Vundofix didn't find anything, so after that, I went through READ & RUN ME FIRST.

    Thanks!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  4. cocoabutter

    cocoabutter Private E-2

    I did what you said and I'm posting you MGlogs.

    After running GetLogs.bat I enabled NOD32. Should I do it before?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet....Your logs look clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2. Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  6. cocoabutter

    cocoabutter Private E-2

    Thank you soooo much! :) Although it took a lot of time, it worked, what's the most important.

    Before continuing to How to protect yourself from malware:

    May I now delete these two? (I'll keep Spybot due to the instructions in How to protect yourself from malware)

    SUPERAntiSpyware
    Malwarebytes' Anti-malware

    Currently I have NOD32 as anti-virus program. Should I remove it and download e.g. Avast! ? Is it better?

    And there in the instructions, it is written that I should have SP2, but I already have SP3. Is that ok?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome!

    If you wish to.....I keep both on hand for backup scans when I sense trouble.

    No anti-virus will catch 100% ...just the nature of the beast. Choice of anti-virus is a personal decision relating to how the user feels with the program: i.e. does it slow the system, is it easy to use, etc.

    SP3 just came out, so the reference is really for the many posters who have not downloaded even SP2. So you are fine. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds