Vundo/ Virtuemonde generic

Discussion in 'Malware Help (A Specialist Will Reply)' started by borgnine, Dec 24, 2008.

  1. borgnine

    borgnine Private E-2

    Hi, Usual stuff. Ran the scans but am still having problems with Internet:

    No pictures will appear unless I open each one individually,
    My desktop screen wont stay on a selected background- it keeps returning to black.
    These are the main leftover problems I've noticed from the original infection - which occured when I tried to download a bootleg registry key for Nero. Stupid, I know.
    In advance, I'd like to say thanks for your time and patience with people like me. James.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not attach the log from MGtools as requested.

    Also you did not install the version of SUPERAntiSpyware given in the READ & RUN ME. You are way out of date. Please do the below immediately.


    Please uninstall your current version of SUPERAntiSpyware (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this first log later.
    • Since this infection has been reappearing after a reboot, you will have to reboot again and then run an additional scan to make sure it comes back clean. Attach this second log too.
     
  3. borgnine

    borgnine Private E-2

    Hi Chaslang. Here are the other logs you requested.

    BTW, the reason I was using the old SAS was because when I originally got the virus, it wouldn't let me access ANY programs or sites that would help to get rid of it- that included you guys. So I downloaded the old copy I had from my external hardrive. This allowed me to begin the disinfection process.

    Do you think it would be a good idea to keep copies of the current anti-malware in my external hardrive in the event a similar situation happens in the future?
    Thanks. James.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may or may not help. In situations where the malware is only blocking the downloading, like his time, it may help you get started. However, most of the real troublesome malware is more aggressive and block the ability to run the installers and/or the actual program files after they are installed. Sometimes renaming the files ( as suggested in the READ & RUN ME ) can help, other times it does not since smarter malware does not look for the file names, the look for the footprint of the program itself and terminate it before it can run. This kind of malware is doing the samething but in reverse that antivirus and antispyware programs attempt to do when the block malware from running.

    Now let's continue with your cleanup.

    I recommend that you uninstall the outdated and ineffective SpyCatcher Express 2007 that you just recently installed.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 7
    Spybot - Search & Destroy 1.4 <-- way out of date and now you have the current one from the READ ME


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now goto this link Using MGtools and download the new version of MGtools.exe using the black bold print link in the first sentence.

    Run MGtools.exe then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 29, 2008
  5. borgnine

    borgnine Private E-2

    Hi Chaslang- Thanks for all your help so far.

    Following your instructions I sucessfully saved the registry add-on and downloaded Java.

    I also got the two logs as requested. Note that during the combofix run, it indicated that AVG was still scanning even though I had it turned off.

    As far as the computer functioning, I still don't get web-page photos or icons unless I open each one individually, i.e. in EBay there are no photos of the items for sale- only the photo icon which I have to open manually.

    That's the most irritating thing!!! Should I do a system restore? I haven't done it yet because I don't want to loose this thread.

    Thanks. James.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is more than likely not an issue due to any remaining malware. Issues like this are normally caused by settings in your browser or in your security applications that are blocking images. You need to check to make sure you are not blocking them. For example, in Internet Explorer, click Tools, Internet Options, Advanced tab and then scroll down to the Multimedia area and make sure that Show pictures is checked and that Show image download placeholders is unchecked. Then click Apply.


    Apparently Spy Catcher's uninstall did not do a complete job. You need to delete the below folders from it.
    C:\Documents and Settings\James\Application Data\Tenebril
    C:\Documents and Settings\All Users\Application Data\Tenebril
    C:\Program Files\Tenebril
    C:\WINDOWS\system32\tenarchlib

    Also delete the below left over folder from malware:
    C:\WINDOWS\VXNlcg


    Also we still need to fix a few registry keys.
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    And I have a question on whether you recognize what any of the below are for? There are a load of registry keys like this. I do see "Belle's Beauty Boutique™" installe on your PC. Perhaps all of this junk is related to "Big Fish Games Client" which is also installed?

    Other than the above your logs are clean.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
    Last edited: Jan 2, 2009
  7. borgnine

    borgnine Private E-2

    Hi Chaslang. I installed the registry keys successfully. The stuff regarding Big Fish Games comes from my daughter who keeps downloading stuff from them. I try to keep on top of it by deleting inactive programmes, but they do pile up!!

    Any suggestions?

    Everything else seems to be working fine. Once again I'd like to thank you for your help. The information and help has been instructive, competent and efficient. I hope I won't need to contact you again- I mean that in a good way! Keep up the good work. Take care. James.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! What was stated in How to Protect yourself from malware! and that is give kids Restricted User Accounts.;)



    You're welcome. Surf Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds