GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Virtumonde Virus, anyone have experience? (https://gfy.com/showthread.php?t=876771)

Fletch XXX 12-20-2008 07:12 AM

Virtumonde Virus, anyone have experience?
 
Hey, anyone have experience with Virtumonde?

I got it on my work machine and have been fighting it for a few days.

Its weird, I thought I cleared the machine - ran Spy Bot and Malwarebytes in safe mode this morning, it quarantined and removed the files successfully, but something strange happens...

If I run the proggies and get rid of the infected files, after I remove them, I run Malwarebytes again., and the infected registry entries are still there??

Of course ive googled and followed directions on "vortmonde removal" pages etc, but nothing seems to actually get rid of it...

Fletch XXX 12-20-2008 07:13 AM

ps i am in safe mode right now so the board is hard to surf lol must be 480 width or someshit in safe mode lol

TeenCat 12-20-2008 07:17 AM

maybe instead of "vortmonde removal" you can try "virtumonde removal" ... nothing of the manuals works? but sorry dont know how to help you better :)

GrouchyAdmin 12-20-2008 07:19 AM

Try posting comments on YouTube for a couple of hours. Maybe the sheer stupidity of the posters there will kill it off.

Iron Fist 12-20-2008 07:19 AM

http://www.bleepingcomputer.com/malw...ndo-virtumonde

Fletch XXX 12-20-2008 07:20 AM

Quote:

Originally Posted by TeenCat (Post 15222597)
maybe instead of "vortmonde removal" you can try "virtumonde removal" ... nothing of the manuals works? but sorry dont know how to help you better :)

that was a typo... of course i googled the correct thing.

Fletch XXX 12-20-2008 07:20 AM

i have the 3 infected registry keys and am going in manually via start > run > regedit

and remove them manually, hopefully that kills it...

klinton 12-20-2008 07:22 AM

try combofix

Fletch XXX 12-20-2008 07:23 AM

the three files are:

run > mibutamiku
browser helper object
and root clsid regkey

removing them manually...

Barefootsies 12-20-2008 07:30 AM

Yep. Had this a few weeks ago. I posted on it then.
Yes. It's a bitch to get rid of. Wasted an afternoon dealing with that madness.

Here is my steps to clearing that shit up.
fucking-around-and-business-discussion/872735-virtumonde.html

Fletch XXX 12-20-2008 07:31 AM

driving me insane, i deleted the reg keys manually and they seem to reappear... right back in the list after i close window

Iron Fist 12-20-2008 07:33 AM

Quote:

Originally Posted by Fletch XXX (Post 15222635)
driving me insane, i deleted the reg keys manually and they seem to reappear... right back in the list after i close window

This sounds like a fake thread, or you have me on ignore... haha. Good luck with it. :2 cents:

Fletch XXX 12-20-2008 07:33 AM

how in the hell can you delete a file and have it reaappear simply by clicking out of the folder????

Fletch XXX 12-20-2008 07:35 AM

Quote:

Originally Posted by sharphead (Post 15222603)

ive ran malwarebytes more than 10 times, it claims to remove it, yet it does not.

As I said above, I have gone in through start > run > regedit and the files are not being deleted by malwarebytes,... the same 3 reg keys keep being detected even after deleting with Malwarebytes

Barefootsies 12-20-2008 07:36 AM

Quote:

Originally Posted by Fletch XXX (Post 15222645)
how in the hell can you delete a file and have it reaappear simply by clicking out of the folder????

That is one of the beauties of that virus.

You have to nuke that shit in SAFE MODE. Turn off restore. Clean registry. Kill virus. Restore back on.

Fletch XXX 12-20-2008 07:40 AM

Quote:

Originally Posted by Barefootsies (Post 15222658)
That is one of the beauties of that virus.

You have to nuke that shit in SAFE MODE. Turn off restore. Clean registry. Kill virus. Restore back on.

im in safe mode, not doing any restore stuff... how you clean registry other than in safe mode >delete?

Fletch XXX 12-20-2008 07:42 AM

k turned OFF sys restore, maybe that was it...

now to deleting...

Barefootsies 12-20-2008 07:44 AM

Quote:

Originally Posted by Fletch XXX (Post 15222675)
im in safe mode, not doing any restore stuff... how you clean registry other than in safe mode >delete?

Turn off system restore.
Go into SAFE MODE.

THEN you use the

1. Microsoft Malware tool first. It should already be on your machine. Find it. Then run it twice.
2. Registry Cleaner (run G search for the program). Run it twice.
3. Run Spybot Search and Destroy, twice.

Once clean, turn restore back on.

Fletch XXX 12-20-2008 07:46 AM

man I keep deleting these files and they do not go away.

sys restore off

in safe mode

will run MBAM again and see, but the files come back..

Barefootsies 12-20-2008 07:49 AM

Quote:

Originally Posted by Fletch XXX (Post 15222695)
man I keep deleting these files and they do not go away.

sys restore off

in safe mode

will run MBAM again and see, but the files come back..


You can not manually delete them chief.


I tried that as well a half dozen times. Stop wasting your time. Find, and download if you do not have them, the programs I said. Run them like I said. You should be fine.

Fletch XXX 12-20-2008 07:50 AM

why do i need a reg cleaner? I am deleting them manually...?

this is fucking silly... as I have said, everytime I run MBAM i get the same 3 reg keys shown to me as infected, i have the registry open to the file locations and manually delete, yet the reappear as soon as I delete them...

Fletch XXX 12-20-2008 07:51 AM

what reg cleaner?

i am downloading this

http://www.malwarebytes.org/regassassin.php

Barefootsies 12-20-2008 07:53 AM

Quote:

Originally Posted by Fletch XXX (Post 15222707)
why do i need a reg cleaner? I am deleting them manually...?

this is fucking silly... as I have said, everytime I run MBAM i get the same 3 reg keys shown to me as infected, i have the registry open to the file locations and manually delete, yet the reappear as soon as I delete them...

Every time I would run S&D, it would find the virus as well. It would do the same thing you claim. It would also say it removed it, but did not. I tried manually deleting, then would run S&D again. It would find it again. The files would be back again.

Do the steps I said, with the programs I said. Otherwise, enjoy your morning of wasted time.

Fletch XXX 12-20-2008 08:07 AM

Quote:

Originally Posted by Barefootsies (Post 15222687)
Turn off system restore.
Go into SAFE MODE.

THEN you use the

1. Microsoft Malware tool first. It should already be on your machine. Find it. Then run it twice.
2. Registry Cleaner (run G search for the program). Run it twice.
3. Run Spybot Search and Destroy, twice.

Once clean, turn restore back on.

well in trying to follow your directions:

1. http://www.microsoft.com/security/ma...e/default.mspx

doesnt seem to do anything after I download it, I click it open and it just goes away.

2. What registry cleaner? a google search for "registry cleaner" yields 4,920,000 results, I tried regassassin, didnt delete the keys.

3. I have spybot, and have trun it with same conclusion as you above, it isnt getting the files removed, and I keep trying other things.

Darkcrni 12-20-2008 08:13 AM

My god, why don't you reinstall the fucker , just to be sure!!!

Fletch XXX 12-20-2008 08:36 AM

well, ive tried to download and run this more than once, same thing, it just opens then closes without running

http://www.microsoft.com/security/ma...e/default.mspx

polish_aristocrat 12-20-2008 09:00 AM

so malwarebytes didn't help?

Fletch XXX 12-20-2008 09:09 AM

Quote:

Originally Posted by polish_aristocrat (Post 15222866)
so malwarebytes didn't help?

no, MBAM finds and *claims* to remove the same 3 files over and over, no matter how many times the prog is ran.

it finds the files, then claims to delete... but doesnt.

Forest 12-20-2008 09:13 AM

sounds fuckign nasty

polish_aristocrat 12-20-2008 09:16 AM

are you on XP or Vista?

I know Combofix is a great program, someone mentioned it here, but a page says its only for XP

http://remove-malware.com/malware-ti...monde-removal/

Virtumonde removal can be successfully accomplished via the following steps below. Please note that this fix only works on Windows XP. NEVER RUN COMBOFIX ON WINDOWS VISTA!!!

Manual Steps for Windows XP

1. Download the latest version of combofix from here.

2. Save combofix in the root of your c: drive ( c:\combofix.exe)

3. Reboot the pc in safemode (edit* 4/22/08 - ComboFix may not work in safemode on some computers. If ComboFix does not work for you in safe mode I would suggest that you run malwarebytes' anti-malware in safemode...it removed Virtumonde without a problem).

4. Login and Run ComboFix.

5. Follow the on screen prompts to clean your pc.


here's a more detailed guide to Combofix
http://www.bleepingcomputer.com/comb...o-use-combofix

ive used combofix in the past to remove some other trojans.. but:

combofix may theoretically fuck up your system for good, it says 1/100 machines don't survive the scan
unlike the guide says, you should rather save combofix as some random characters like abs456.exe instead of combofix.exe

and after running combofix it not only removes some shit, but produces a log, and then after looking at the log, some additional steps may be nesessary but i never had to do that

anyway if you're on XP, you can try

edit: dont do anything, dont even move your mouse while Combofix is running

DeanCapture 12-20-2008 09:56 AM

Fletch, I had that a while back and used two programs to rid myself of it. Since then, I've turned others on to this and they also got rid of it.

First, download & install Eset Smart Security.

Secondly, download & install SUPER Anti Spyware

Thank me later...:thumbsup

Fletch XXX 12-20-2008 01:37 PM

Quote:

Originally Posted by DeanCapture (Post 15223041)
Thank me later...:thumbsup

I shall do so right now. Thanks...

Man oh man,.. that is some nasty shit. I'm not the best with these things, but I can run the progs find, target, kill. But I downloaded and ran both of those and was able to remove most of the parts it seems... although, I have noticed a few "browser helper ojbects" that have returned, I at least for now it seems mostly neutralized.

The problem was killing the "in use memory module" stuff. I downloaded Dr Delete anf numerous free downloads, but took your advice on those. The frustrating thing is waiting for these things to scan a large HD, meanwhile you *know* where the reg keys are, but can't delete em, but in the end between a few programs I was able to put a stop on them and the main reg key that was calling upon other system32 .dlls.

Im still cleaning it up, but at least was able to finally get out of safe mode and plug it back online...

nasty stuff

vundo virtumonde, whatever it is i had(ve) em...

Fletch XXX 12-21-2008 07:20 AM

well, didnt work.

The shit is still on my machine and I am still trying to rid myself of it.

the same registry keys that are causing this simply will not be removed by any of the programs, ... and upon a reboot it seems to come right back...

arrhgg

SUPERANTispyware even updates their virii definition list YESTERDAY with 6 vundo updates and it still didnt fix it!!!

Fletch XXX 12-21-2008 07:29 AM

nothing will delete these two

O4 - HKUS\S-1-5-19\..\Run: [mibutamiku] Rundll32.exe "C:\WINDOWS\system32\tapusura.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [mibutamiku] Rundll32.exe "C:\WINDOWS\system32\tapusura.dll",s (User 'NETWORK SERVICE')

manual delete dont work, delete upon reboot from MBAM dont work, Hijack this dont work... SuperAntiSpyware dont even find it...

Fletch XXX 12-21-2008 07:57 AM

the frustrating thing is very simple, I dont need *another virii or malware scanner*, I dont need another reg cleaner, I dont need another blahblahblahfixit.exe

I know EXACTLY where the regkeys are, I know exactly what the names are, but simply CANNOT REMOVE THEM, nor effectively stop them from autorun on reboot unless removed.

If i could simply delete the regkeys I am thinking that would be about the last traces of it,... but until then, I think it keeps making copies of itself or some of the .dll files and the process just starts over, very frustrating.

I think I must have the latest most recent vesion of this vundo/virtumonde trojan, because Superantispyware updated on the 19th with new virus definitions for vundo, but so far, it has not stopped this thing...

Fletch XXX 12-21-2008 08:23 AM

found a task i hadnt killed... and disabled: C:\WINDOWS\system32\rundll32.exe "C:\WINDOWS\system32\tuvWpMGv.dll",d (was set to run every 2 hours)

also found this file: WMSysPr9.prx (old trojan file) not sure if related, but cleaning this shit has me digging DEEEEEP into the abyss...

Fletch XXX 12-21-2008 08:28 AM

another .dll removed

system32/tudoniga.dll

trojan.fakealert

Fletch XXX 12-21-2008 08:32 AM

found a .dll that seems to be in-use and is not windows related, setting up Dr Delete to kill it upon reboot now...

system32/vuzinaku.dll

Fletch XXX 12-21-2008 09:01 AM

k vuzinaku.dll cannot be deleted, must be a main part of this... tried dr delete at start up but its not allowing this thing to be removed, acces denied. I unchecked "read only" etc...

cant even unregister the .dll at cmd prompt... as suggested here http://www.spywareremove.com/securit...ove-dll-files/

this is a headache

Fletch XXX 12-21-2008 09:05 AM

i quarantined the vuzinaku.dll with ESET, but it couldnt move it from sys32 folder


All times are GMT -7. The time now is 02:07 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123