Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Hardcore Virtumonde Infection
![]() |
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Hardcore Virtumonde Infection
I hope that it is okay I am posting this, Google showed me a person with a similar problem getting help so I am assuming this is the right place... I'm almost at a loss here (but not quite yet). I honestly don't know where this spyware came from for once, but this is one vicious bug that seems indestructible.
I had SpySweeper (been great up till now) and recently downloaded AdAware and Spybot S&D. All three of them detect Virtumonde and pathetically attempt to restore it, but it just keeps coming back after a restart. SpyBot even did a run before Windows started (it seemed) and looked like it got rid of it... I still got about 5 errors that a .dll was not found. Later Windows Explorer encountered and error and needed to restart (I have Vista), after that the bastard was back (I can tell because it brings my internet to a crawl). I even found some program specifically for removing Virtumonde, and it couldn't even find it... which was really wierd... I saw some posts about AVG Free and Hijack this, so I downloaded them from a different computer and put them on my computer using a USB Drive. You can view the log file here: zaletanski dot com / hj.txt (can't post links wtf?) AVG is downloading extremely slowly for some reason so I will try to get a log from that (or whatever) later tonight or tommarow, but I have to go for now. Any help to get rid of this will be extremely appreciated! |
|
#2
|
||||
|
||||
|
Malwarebytes' Anti-Malware
|
|
|
|
#3
|
|||
|
|||
|
First off I'm sorry this took so long to reply, it was hardly the tonight or tomnarow deadline I set for myself. I got AVG running, and Malwarebytes' Anti-Malware like you suggested, and they are both following the "hay I see it, but when I delete it the damn thing just keeps coming back!" trend.
I attached the Malwarebytes logfile as you asked. I don't know how much help it will be, this is the most viscous thing I have ever seen. It seems like there are 2 trojans and the virtumonde thing that are on the computer. I think I need to uninstall AVG because it keeps seeing the other anti-spyware things as threats.... On startup I get 3 'cannot find X.dll' error messages now, which is an improvement, but whatever is trying to execute them in the first place is still screwing me over. As I said before, it is preety messed up, any help is going to be greatly appreciated. |
|
#4
|
||||
|
||||
|
No worries, we can clean it up
Highjackthis Instructions
|
|
#5
|
|||
|
|||
|
Okay here's the updated log file.
|
|
#6
|
||||
|
||||
|
From the looks of your log you uninstalled AVG but didn't delete the associated folders so I am including this in my instructions, if you did not delete AVG then disregard that part.
----------------------------------------------------------------------- Update your Java Runtime Environment
--------------------------------------------------------------------------------------- You may want to copy and paste this into notepad and save to your desktop to have while in safe mode Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: (no name) - {DD1425D8-DC79-42CB-9D13-98434010C3A1} - C:\Windows\system32\ssqpNDtR.dll (file missing) O4 - HKLM\..\Run: [14ab4cb8] "rundll32.exe" "C:\Windows\system32\umyaljwa.dll",b Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode. Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode. Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present): AVG Please note any other programs that you don't recognize in that list in your next response. Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present): C:\Program Files\AVG Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present): C:\Windows\system32\ssqpNDtR.dll C:\Windows\system32\umyaljwa.dll After that, Reboot, and post a new HijackThis log here in a reply |
|
#7
|
|||
|
|||
|
I did uninstall AVG, and there was no folder or anything left over to delete. Thanks for the instructions! It looks like its getting better if not solved because there's no more error(s) on startup!
New log file attached. |
|
#8
|
||||
|
||||
|
yep looks much better but lets get a 2nd opinion from an online scan just to be safe
Run Kaspersky Online AV Scanner Order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
|
|
#9
|
|||
|
|||
|
Attached Kaspersky logfile.
|
|
|
|
#10
|
||||
|
||||
|
The only thing on there is an infection in your internet cache. We need to clean up temp files any way so we can do this then clean up.
Download and Run ATF Cleaner Download ATF Cleaner by Atribune to your desktop. Double-click ATF Cleaner.exe to open it. Under Main choose: Windows Temp Current User Temp All Users Temp Cookies Temporary Internet Files Prefetch Java Cache *The other boxes are optional* Then click the Empty Selected button. Firefox or Opera: Click Firefox or Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click NO at the prompt. Click Exit on the Main menu to close the program. ---------------------------------------------------------------------------------------- Manually clear cache
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
here are some additional utilities that will enhance your safety
__________________
|
![]() |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Particularly Nasty Virtumonde Infection | sexconker | Security and the Web | 5 | 01-06-2008 07:29 AM |
| Need help finishing of virtumonde virus infection | jaredc | Security and the Web | 0 | 08-08-2007 12:45 PM |
| Hardcore Gamer !!! | Didou | Gaming and Consoles | 15 | 06-29-2002 05:14 PM |
| Hardcore Disk Defraggling | Didou | Storage & Networking | 18 | 06-21-2002 07:20 PM |
All times are GMT -4. The time now is 02:42 AM.





