Virtumonde

Discussion in 'Malware Help (A Specialist Will Reply)' started by homunculus, Jun 27, 2006.

  1. homunculus

    homunculus Private E-2

    Ewidoguard started alerting me to a virtumonde infection. I ran the generic malware removal instructions and the specific virtumonde removal instructions and couldn't get rid of the infection but I noticed that VundoFix.exe tried to delete iifdaxu.dll but couldn't and I changed it to iifdaxu.dll.old. None of the malware scanners picks it up now and the registry doesn't seem to have any new virtumonde entries. Just wondering, am I out of the woods? and is it safe to delete the .old file now? The hijack this log is from after the file change.
     

    Attached Files:

    Last edited: Jun 27, 2006
  2. homunculus

    homunculus Private E-2

    Here is the hijack this log and the symantec log. Symantec's FixVundo tool couldn't find the infection while all the other detection software could.
     

    Attached Files:

  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Download
    - Pocket Killbox

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh Hijack This log.
     
  4. homunculus

    homunculus Private E-2

    OK, I did all of that and here's the new HJT log. Thanks for the help. :)
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HIjackThis log is clean.

    How is your computer running?
     
  6. homunculus

    homunculus Private E-2

    Pretty good. As well as can be expected, and thank you for all your help! :D
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds