My computer is Virtumonde infected, please help

Status
Not open for further replies.
First use hijackthis to remove these items:
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4a2feca7-6ac8-468d-bcd0-c76cf8f653c6} - C:\WINDOWS\system32\yedonuse.dll
O2 - BHO: OTS Software Toolbar - {e41b29e5-88b5-40b1-903e-080e0f2c4b65} - C:\Program Files\OTS_Software\tbOTS_.dll
O4 - HKLM\..\Run: [shawnotify] c:\progra~1\shaw\update\siuloader.exe /notify
O4 - HKLM\..\Run: [hugozepuhu] Rundll32.exe "C:\WINDOWS\system32\tijayefe.dll",s
O4 - HKLM\..\Run: [e81b346f] rundll32.exe "C:\WINDOWS\system32\vevesadi.dll",b
O4 - HKLM\..\Run: [CPMeb2807f3] Rundll32.exe "c:\windows\system32\tumaveko.dll",a
O4 - HKUS\S-1-5-19\..\Run: [hugozepuhu] Rundll32.exe "C:\WINDOWS\system32\tijayefe.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [hugozepuhu] Rundll32.exe "C:\WINDOWS\system32\tijayefe.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: avgrsstx.dll C:\WINDOWS\system32\monigula.dll c:\windows\system32\tumaveko.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\tumaveko.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\tumaveko.dll

Download and run the Avenger from here: http://swandog46.geekstogo.com/
Let it scan for rootkits and check the box asking it to automatically remove the ones it finds.

Download and run super antispyware http://www.superantispyware.com/download.html
Do a complete scan and remove all items it finds.

Download and run malwarebytes http://www.malwarebytes.org/
Do a complete scan and remove all items it finds.

Keep scanning with super anti spyware and malwarebytes this until it can find and remove nothing.

Update your antivirus and make sure it's working properly. A recommended one is AVG. http://free.avg.com/

Switch to using Mozilla Firefox http://www.mozilla.com/en-US/firefox/ and DO NOT use Internet Explorer - it's a great big security hole.

Good luck
 
i have done all step by step as directed by SEANC and uninstall my old avg and i am trying to istall new ANG antivius but its giving problems
first it says some installation files are currupted...please download fresh copy
and some times its starts installing but says instaltion folder is missing

here is my fresh log
 
I'll have to give Avira a shot and see what it's like.

I quite like AVG but if there's a better free alternative then it's worth a try.

I got free licenses of Kasperskey Internet Security 2009 via my bank but was let down by a process that likes to stick at 100% and can only be cured by a reboot.
 
Put it this way I check and repair about 20+ Virus\Malware posts a day (although some days -- none)
And I always say get rid of what they have (really a huge assortment of things)
And install Avira.
Every single one has been then resolved (obviously doing other things too)
But in my view free Avira (with the annoying splash screen, only when it updates) is the best
Oh, and I use it too ;)
 
randyhawk

Things are looking brighter but there's still a couple of files I've identified in your hijackthis log:

R3 - URLSearchHook: (no name) - {e41b29e5-88b5-40b1-903e-080e0f2c4b65} - (no file)
O20 - AppInit_DLLs: c:\windows\system32\henebevi.dll c:\windows\system32\sivaforu.dll
O4 - HKUS\S-1-5-19\..\Run: [hugozepuhu] Rundll32.exe "C:\WINDOWS\system32\mikomuyo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [hugozepuhu] Rundll32.exe "C:\WINDOWS\system32\mikomuyo.dll",s (User 'NETWORK SERVICE')

Please remove those, they're most likely the cause of your AVG problems.

Also run a couple more complete cycles of Malware Bytes and Super Anti Spyware (make sure they're updated!)
Did the log for avenger say it had found and removed a rootkit?
 
thanks for all your help guys, i am up and running again. i am using firefox and comodo firewall with avira anti virus
is it safe to use widows xp fireball with comodo at same time and am not able to delete 2 hugozepuhu entries in ht they are coming back again and again
 
I'm still waiting for the first Malware Bytes and Super Anti Spyware logs
Many users forget to remove found entries
And in most cases Malwarebytes (updated) needs to be run multiple times
Did you want to post these logs for the first time (as per the guide) ?
 
Yes please Attach all the logs
ie
MalwareBytes <= Ideally a recent updated scan, and manually removal of found issues, completed
SuperAntiSpyware <== It's amazing how many spywares this scan can find and remove, by itself
HijackThis<== After restarting; running this one, is the world's best way, of knowing what's running (Malware wise)

But your choice ;)
 
Malwarebytes' Anti-Malware 1.31
Is now old

As stated above, you must update it first
There is an update tab in the Malwarebytes program to do this
Please update it, and then run a full scan with the new updates installed

Oh, update it first ;)
 
I don't mean to be rude, but your above post is usually what most users post on Post#1, but it has taken 15 posts for you to get there

In all cases of Virus\Malware issues, it is best to post these 3 logs, as per the guide, otherwise, well, it's just a waste of posts getting there.
I believe member seanc has helped extremely well under the circumstances (ie limited info supplied) But just to let you know, I personally don't check anything until the logs are supplied

1. Download VundoFix; Trojan.Vundo Removal Tool; VirtumundoBeGone and ComboFix.
2. Go Offline - pull the cable network, turn off wireless card, turn off your modem.
3. Restart computer and press F8 to run Windows in Safe Mode
4. Run VundoFix.. Click on the Scan for Vundo. Scanning will begin, which takes a long time. In the white box will display the names of infected files. After the scan is complete click Remove Vundo, removal will begin. Confirm by clicking Yes. The application should ask for permission to restart your computer - click Yes. Start Windows in Safe Mode again.
5. Run FixVundo. Click Start, and then follow the instructions. It should be noted that this application can deal only with older mutations Vundo (Virtumonde).
6. Run VirtumondoBeGone. Click Continue and wait for the report.
7. Run ComboFix. Then, in the two windows that appear click Yes, and start scanning and removal of any Vundo (Virtumonde) infection. During this operation, you are not allowed to move the mouse or perform other actions. After the scan is complete, program will show a text file - a report from the program's action.
8. Restart computer and run Windows normally.
9. Attach the report, and a new HJT log ;)
 
That's ok

Please Scan with HJT and tick and fix all the following:
(best to have any Internet browser closed first)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O24 - Desktop Component 0: (no name) - http://www.acura.ca/assets/pages/models/mdx/img/gallery/wallpaper/exterior/wallpaper_01_1024x768.jpg

Then run CCleaner again
Then restart

Clear & Reset System Restore's Cache
Go to Start >> Run - type or copy/paste control sysdm.cpl,,4 and then press Enter
* Tick on the checkbox - Turn off System Restore on all drives
* Click Apply
Turn it back 'On' by unticking the same checkbox & click Apply, and then OK

Then you're done :)
 
Status
Not open for further replies.
Back