also @ TechSpot: Tech Tip: Turn Off your Display Using a Windows Shortcut and More
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Virtumonde

Closed Thread
Bookmark Thread Tools
  #1  
Old 09-04-2008
Newcomer, in training
 
Member since: Aug 2008, 1 posts
Virtumonde

after i run adaware and spybot(my 2 usuals) it usually finds and gets rid of virtumonde. it keeps coming back though. and lately something else has been popping up. when i try to look at mypictures, dr watson(i believe) shuts it down and then my desktop blinks and a message window at top left comes up. it comes and goes so fast that all i can see is 'personalized settings' at the top and c:
recycler............and a bunch of other characters. ive tried deleting c:\recycler to get rid of contents(from what i understand it'll come back after reboot) but still have same problem. just checked and still does it after everything i did as you instructed.
wasnt able to do online scan. something about siging up for something. i hope you can help. and any help you give will be greatly appreciated
Attached Files
File Type: log hijackthis.log (7.7 KB, 3 views)
File Type: txt mbam-log-09-02-2008 (17-14-27).txt (1.3 KB, 3 views)
File Type: txt ComboFix.txt (36.3 KB, 3 views)
  #2  
Old 09-11-2008
TechSpot Booster
 
Location: Illinois, USA
Member since: Feb 2007, 905 posts
System specs
I suggest that you repeat the Malware Removal procedures.

Combofix.log appears to be incomplete.
System Restore archive shows past infection with Purity.
HJT analysis courtesy of Castlecops gives conflicting info for "MSCONFIG.EXE" from the program files/pchealth.

MSCONFIG.EXE (pchealt) is on the startup list. I consider this usage suspect.

Dr. Watson being invoked as you describe does not sound reasonable. Suspicious.

One strain of Purity adds /Windows/??system32 directory. Windows Explorer lists this directory before the legit copy of 'system32'. '??system32' filename contains non-printing characters. Command prompt > dir c:\windows\*system32* > analyze results

Purity malware could have impacted the wbem directory, as well. I believe that the removal of the infection by my AV protection made a bad decision and quarantined the legit copy of the directory. I'll never know since this was over a year in the past.
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 09-11-2008
Blind Dragon's Avatar
TechSpot Evangelist
 
Location: Tampa FL
Member since: Oct 2007, 4,048 posts
System specs
Actually the combofix log will always cut off if it is too long - by design

and the legit msconfig file has been moved to a bak folder and replaced with a malicious file

Did you run Smitfraudfix? If so attach rapport.txt

If not,

Run Smitfraudfix
  • Download Smitfraudfix by S!ri from HERE
  • Double-click SmitfraudFix.exe
  • Select 1 and hit Enter
  • The report can be found at the root of the system drive, usually at C:\rapport.txt

======================================

FindAWF

Click here to download FindAWF.exe and save it to your desktop.
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to Press any key to continue.
  • Press 1 and then Enter, and the FindAWF tool will begin scanning your computer for the infected AWF files and the backups the trojan created.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or to the same location as FindAWF.exe.
  • Attach AWF.txt file in your next reply.


Attach Here:
1)C:\rapport.txt
2)AWF.txt
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Help cant get rid of Trojan Virtumonde Virus & Malware removal 5 09-01-2008 08:48 AM
Virtumonde infection Virus & Malware removal 2 08-11-2008 01:51 PM
Recurring virtumonde Virus & Malware removal 9 08-09-2008 03:56 PM
'Virtumonde' Virus Virus & Malware removal 2 06-26-2008 04:13 PM
Darksma & virtumonde help Virus & Malware removal 1 04-25-2008 09:17 PM


All times are GMT -4. The time now is 05:41 AM.