Virtumonde.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Crixler, Jun 24, 2008.

  1. Crixler

    Crixler Private E-2

    Ok, so I've got virtumonde.
    Many sites do not load, they just sit there and continue attempting to load.
    Among them are myspace, google, hotmail, and the forum for a Star Wars costuming club I am part of.
    This started on Friday.
    Nothing I have tried has been able to remove it completely, it always comes right back.
     

    Attached Files:

  2. Crixler

    Crixler Private E-2

    And the rest of the logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\system32\affv14~1.sys
    C:\WINDOWS\system32\SySWAVCJ.dat
    C:\WINDOWS\system32\fpecpkjr.dll
    C:\WINDOWS\system32\fccbyWnN.dll
    C:\DOCUME~1\CRIXLE~1.COR\LOCALS~1\Temp\jbridgep.sys
    
    Folder::
    C:\Temp
    C:\tmp___
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1BF52956-20D3-44E0-8032-1E5A168388F8}]
    
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a129b8a1-8ed7-4ad0-a51b-4c233fea23d3}]
    
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BA6EE66B-BFF7-42F2-9CC5-DF0A1C3C250C}]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.
     
  4. Crixler

    Crixler Private E-2

    Here they are.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good.....let's just do this:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now tell me if you are having any issues. :)
     
  6. Crixler

    Crixler Private E-2

    Ok, I did that, and then started a SAS scan to see if it still finds anything.
    It came up clean =]
    Are there any other sort of tests I should do right now?
    Or is this it?
     
  7. Crixler

    Crixler Private E-2

    Ok, I also did a Spybot Search & Destroy scan...
    It found one virtumonde.dll thing.
    it's a file called cbXOEtRH.dll_old.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Could you please attach that log (spybot).
     
  9. Crixler

    Crixler Private E-2

    Here you go.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    SpyBot said it was fixed..but you can use windows explorer to see if you can locate it and manually delete it.

    Any other issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2. Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  11. Crixler

    Crixler Private E-2

    Found some more stuff.
    Malwarebytes AM found a malware.trace registry key.
    Should I run Ad-Aware and McAfee now as well?
    I noticed none of these threads have mentioned Ad-Aware. Is it not any good?
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We find that Super-Antispyware and MalwareBytes do a much better job. I don't know what your surfing habits are but I would recommend you keep those two programs as backup scanning tools.

    It is more than likely that you will need to run those at least weekly (possibly more often) depending on what you are doing regarding internet sites and email spam.
     
  13. Crixler

    Crixler Private E-2

    Well my computer has always shown up clean before, although I only pretty much used Ad-Aware and Spybot S&D for scans before. But alright, I'll scan more often now. So go on the steps you said a few posts above now?
     
  14. Crixler

    Crixler Private E-2

    I don't know if this is connected, but my add or remove programs is having issues. It does not have a complete list, and it only has the remove button for one program.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    These are the only programs showing in both the newfiles log and the getunkey log:
    What is displayed in CCleaner tools?
     
  16. Crixler

    Crixler Private E-2

    CCleaner shows everything that Add or Remove Programs shows, but I know I have more than that installed.
    Some things shown on the list I do not recall seeing on there before, specifically all the MS Office proof and MUI things. I do have Office installed though.
    I first noticed the change in the list after restarting my computer right after uninstalling a few games on my computer shortly before I came here for help. Some things apart from the games I uninstalled are no longer on that list, some flac utilities, for example. I don't intend on uninstalling the flac tools, I just find it odd that they are missing. And then there's the missing remove button, as well...
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then it sounds like something is messed up in the registry....try posting in software as this preceded any malware issues and does not appear to be malware related. :)
     
  18. Crixler

    Crixler Private E-2

    No, I was already having problems and I had uninstalled the games because I hadn't played them in over a year, so they were just taking up hard drive space and slowing down scans, which I knew I would have to do a lot of.
    Does it still belong in the software forum?
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, I believe it does. Good luck and I will try to keep an eye on your thread there. :)
     
  20. Crixler

    Crixler Private E-2

    Alright, I'll go post a thread there then.
    Thank you so much for all your help! =D
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem...good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds