Winfixer/Vundo/Virtumonde problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by turbodump31, Nov 18, 2005.

  1. turbodump31

    turbodump31 Private E-2

    Hello:

    I am having great difficulties with the Winfixer/Winfixer 2005/Vundo/Vertumonde adware popups. It only effects Internet Explorer, but slows down my computer even when it is not in use. The worst thing is that Norton Antivirus 2005 detects it and I have a huge error alert PERMANENTLY on my screen that says "High Risk: Norton Antivirus has detected a virus on your computer. Object Name: C:\WINDOWS\System32\gebyx.dll Virus Name: Trojan.Vundo. Action Taken: Unable to repair File"

    A virus scan does not delete it. Adaware and Microsoft Spyware both detect it but it just comes back on a reboot. I have downloaded the Vundo and Virtumonde removal tool from symantec but they both are unable to detect it. I have tried running all these scans and tried to manually delete in safe mode as well, no luck.

    Anyways I followed the instructs in READ AND RUN ME FIRST. I shut off system restore, enabled view of hidden files, downloaded scanners, made a log with hijackthis and saved a log of bitdefender's online virus scanner. I have tried cCleaner before and the winfixer popups kept coming back.

    Attached are the bitdefender online virus scanner log and a hijackthis log file. It would be great if you could help me out.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you look at the Special Removal Procedures thread that was listed in the READ & RUN ME? See the reference to Virtumonde aka WinFixer.
     
  3. turbodump31

    turbodump31 Private E-2

    Yes, I have read over that section.

    I thought I had to post my hijackthis log so the forum staff can tell me which lines to delete. Hijackthis stuff is obviously over my head, so I figured somebody could tell me what is wrong with the hijackthis log.

    I might be confused. I thought posting the log is the first step in getting it fixed.

    Thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedure for Virtumonde aka Winfixer tells you what to look for and what to do. Also your Norton program pointed out the problem filename to you. Just follow the procedure and note that your lines of concern are:


    O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\System32\gebyx.dll
    O20 - Winlogon Notify: gebyx - C:\WINDOWS\System32\gebyx.dll

    The procedure was meant to be generic so that anyone could follow it without assistance.
     
  5. turbodump31

    turbodump31 Private E-2

    Ok I get it. I misread the other page I guess.

    Thanks a lot for the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Let me know how things go. Post your HJT log as an attachment when finished with the procedure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds