Virtumonde

Discussion in 'Malware Help (A Specialist Will Reply)' started by HUDIK, May 18, 2010.

  1. HUDIK

    HUDIK Sergeant

    How do you know if you have Virtumonde??
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. HUDIK

    HUDIK Sergeant

    I ran Superantispyware - 1 tracking cookie can't copy this in quarantine
    I ran MGTools (looked like dos - run) said to hit any key and disappeared
    I ran Root Repeal and there is a log

    How do I get this to you. Please help me here I don't know what or how to proceed.

    Thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. HUDIK

    HUDIK Sergeant

    Can't find C:\MGlogs.zip.
    What am I doing wrong ??
    The program runs but there is no log I have searched, and used explore and looked in MGTools.....
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you please run COmbofix and attach that log.

    Where do you have MGTools.exe saved to? If running Vista, did you turn off the UAC? Did you right click it and choose to run it as administrator?
     
  7. HUDIK

    HUDIK Sergeant

    I ran MGtools again and saved it to a text file. There are 2 of them.

    Also enclosed the Root Repeal log.

    Where is COmbofix??
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There is absolutely no need to do this because the actual logs are automatically zipped for you, you should look for the C:\Mglogs.zip file created from running MGTools.exe and attach it for Tim into your next reply. :)
     
  9. HUDIK

    HUDIK Sergeant

    Kestrel12! now I found C:\*Mglogs.zip. Thanks so much. Could not find the other one.:)

    Thanks too TimW for all your help, which I really need:-o
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs as yet. Please attach the latest MBAM log which is here:

    What issues are you having?
     
  11. HUDIK

    HUDIK Sergeant

    TimW
    I am enclosing the MBAM Log you asked for. There was a Homepage Hijack in that one that was caught and has been quranteend by Malwarebytes.
    The reason I asked about Virtumonde was cause something was happening in Spybot SD that said Virtumonde, and I didn't know if I had been infected.
    However I wanted to make sure as I know this trojan is bad.
    Have had no crashes, slowdowns, pop-ups or anything else out of the ordinary, but you never know where things are hiding, and I am not very familiar with malware removal should I have it.
    I hope all is OK, and again want to thank you so very much for helping me:), unless there is something else you think I should check.
    Have also ran TrendMicro Housecall and it found nothing.
    I wanted to give you a 'Thank you', but could not find it.......sorry

    Hudik
     

    Attached Files:

    Last edited: May 19, 2010
  12. HUDIK

    HUDIK Sergeant

    TimW I found the 'Thanks' and clicked it you really deserve it.:):)

    Hudik
     
  13. HUDIK

    HUDIK Sergeant

    So sorry wrong log am enclosing the one you asked for........:-o
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are fine. I have not seen any malware and probably Spybot removed what it found.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  15. HUDIK

    HUDIK Sergeant

    TimW
    There is no MGclean.bat file in MGtools. What should I do
     
    Last edited: May 19, 2010
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    According to your logs there is:

    Code:
    C:\MGtools\"
    mgclean.bat   Mar 29 2010        4836  "MGclean.bat
     
  17. HUDIK

    HUDIK Sergeant

    Found that one, so sorry, got nervous, thanks again TimW
    All is OK.:)
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem!! Safe surfing. :)
     
  19. HUDIK

    HUDIK Sergeant

    TimW there is only thing I like to add. You are a supergeek !! Hope the cake you are licking is delicious......
    You have no idea how much I appreciate what you helped me with. If I could give you a zillion 'thank you's' I would.

    Hudik out......
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    LOL....you are most welcome. Any one of the malware helpers would have done the same!! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds