Flux rss

Cleaning the trojan- Vundo/Virtumonde

Published by aakai1056, last update on Wednesday October 22, 2008 08:24:10 AM by aakai1056

Cleaning the trojan- Vundo/Virtumonde




Intoduction


Vundo also known as Virtumonde/Virtumondo is a trojan that download and displays popup and advertising for antispyware program such as Winfixer. This trojan is quite difficult to clean from your computer and cause a constant degradation in the performance of your computer and may even restrict some access on your computer.

Getting Started


Download and install HiJackThis.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html

Make a complete scan of your computer system using HijackThis and detect the Trojan.

Below is a report of HijackThis scan showing the presence of this Trojan in bold.

Logfile of HijackThis v1.99.1
Scan saved at 13:13:20, on 17/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://google.dospop.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2EDB63B7-7432-42B8-B484-B7DE2779F848} - C:\WINDOWS\system32\gebcaxw.dll
O2 - BHO: (no name) - {4C8DB378-7DAD-46A6-AA86-7BD344296187} - C:\WINDOWS\system32\mljgh.dll
O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\reejepwh.dll

O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\kfoefyyx.dll",realset
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{F79A0EAF-8E03-4AF2-AA8C-548940B99FDD}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: gebcaxw - C:\WINDOWS\SYSTEM32\gebcaxw.dll
<gras>O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll </gras>
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

In the above report, you will notice the line 02 and 020 which is the infection. However it may happen the lines bearing the infection may be hidden. To unhide the infection, rename the tools, for example yourname.exe. Then relaunch HijackThis for another report.

First Method : Vundofix


Procedure for cleaning trace of the virus.

Downlaod and install Vundofix.exe on below link:
http://www.softpedia.com/get/Antivirus/VundoFix.shtml

Once install, double click on VundoFix.exe and click on “Scan for Vundo”.
When the scan is completed, click on the button fix Vundo.
A pop box will appear and will ask if you wish to delete the files, click on Yes to confirm deletion.
Then desktop will then disappear for a moment (During file deletion).
A new pop up box will appear telling you that your PC will turn off, click on OK to restart your PC.
The report of your scan will be found in C:\vundofix.txt. Open it to read the content and ensure that for all file.dll detected bear the notice “Has been deleted”

Then make once again a complete scan with the tool Hijackthis and check whether the line 02 and 020 has been deleted. If it is still present on your report, but mentioned “file missing” near the two lines, it means that the Trojan has been cleaned up shown as per below.

O2 - BHO: (no name) - {2EDB63B7-7432-42B8-B484-B7DE2779F848} - C:\WINDOWS\system32\gebcaxw.dll (file missing)
O2 - BHO: (no name) - {4C8DB378-7DAD-46A6-AA86-7BD344296187} - C:\WINDOWS\system32\mljgh.dll (file missing )


You just have to launch HijackThis and chose the option «Do a scan only».

Then check the lines and click on fix checked to make a complete deletion.

====Second Method= VirtumundoBegone====

Download and install VirtumundoBegone on below link:

http://antivirus.vt.edu/alerts/trojan.vundo.asp

Once download completed , double click on the file VirtumundoBeGone.exe and follow the instructions.

Once complete, restart your computer and the report VBG.TXT will be created on your desktop.

Notice : if you received a message from a blue screen stating “Fatal Error”, don’t panic . This is expected.

Make another report from HijackThis and and fixed the corresponding line as already indicated above.

Notice: This tool is very effective only to detect the line 02 and 020 by examining the key in the registry reported by HiJackThis . (KEY HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects) for the line 02 and(Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
)
for the line 020. It focus only on the files no name which appear in the report. If those lines are detected, this tool will clean the Trojan.

====3rd Method : Combofix=====

Download ComboFix to your desktop:

http://www.plunder.com/ComboFix-rar-download-134496.htm

Then restart your computer in safe mode.
Double click on combofix.exe
Press the Y Key to start a scan.
The report will be created under C:\Combofix.txt
Make a report of HijakThis and fixed the corresponding line 02 or 020.
Under Vista

Disable Users account (You can reactivate after cleaning up of Trojans)
Go to Menu Start > Control Panel
Double click on User Accounts
Select disable > Validate
Restart in Safe mode
Right click on Combofix on your desktop and select “Execute as administrator")
Double click on combofix.exe
Select the Y key to start the scan.
The report will be generated under C:\Combofix.txt

For more information on the ComboFix utility, go to below website:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

In case of difficulty to read the scan report, you can post it on the website forum for remote assistance.
The above tools can be used in combination in view to eradicate the Trojans completely from your system.
How to totally clean trojan W32.Agent.ajh ? Hello all, My computer use Kaspersky AntiVirus 2009 ver 8 and detected trojanW32.Agent.ajh . How to clean it bcoz still detected even its deleted by Kaspersky. Can anyone guide me? TQ en.kioskea.net/forum/affich-22559-how-to-totally-clean-trojan-w32-agent-ajh
Trojan help Hello, I have a Trojan on my computer and Norton can't remove it, so I was wondering if anyone knows how I can get rid of it. The Trojan is called "khfdawt.dll", if someone knows where I can get a virus remover that would help a ton.Thx. en.kioskea.net/forum/affich-5-trojan-help
Viruses - Trojan horses A Trojan horse is a computer program which carries out malicious operations without the user's knowledge. The name "Trojan horse" comes from a legend told in the Iliad (by the writer Homer) about the siege of the city of Troy by the Greeks. Legend... en.kioskea.net/virus/trojan.php3
Portable Antivirus on your Usb keyPortable Antivirus on your Usb key ClamWin Portable Multi Virus Cleaner HiJackFree Avast Portable There are several ways where a portable antivirus can be of great assistance. For example, I hold a farming business and the site is... en.kioskea.net/faq/sujet-285-portable-antivirus-on-your-usb-key
Getting rid of Vundo TrojanGetting rid of Vundo Trojan What is a Vundo Trojan? How to remove a Vundo Trojan Manually Step 1: Locate the Trojan Step 2: Use Registry Editor to eliminate Registry Values Step 3: Using Command Prompt for Vundo unregistration Download... en.kioskea.net/faq/sujet-259-getting-rid-of-vundo-trojan
3wPlayer – Trojans ?3wPlayer – Trojans ? 3wPlayer is a media player who load harmful trojans on your computer once same installed on your computer. This program is designed to play in movies in ZIX format and can be freely downloaded on websites. However... en.kioskea.net/faq/sujet-438-3wplayer-a-trojans
Troj/virtum-genHello, My PC is infected with troj/virtum-gen. I currently have spysweeper and norton antivirus, and these two programs were not able to fix the problem. Is there anything I can do to fix this. My computer is runnning very very slow. Please help me. I... en.kioskea.net/forum/affich-9977-troj-virtum-gen
Virus/ trojan power cutHello, I got a virus and trojan...while I was cleaning the mess by using AVG anti virus and Spybot... when spybot windows suggest me to HEAL the trojan the computer switch off sudddenly! as if the power was cut... since then, my tower is off...no fans... en.kioskea.net/forum/affich-20212-virus-trojan-power-cut
Your computer is infectedDear sirs/Madam On scanning my computer with McAfee Enterprize I discovered a Trojan Horse named A0005253 on my computers system Volume\restore which Mc Afee couldn't move or clean it. I shall be much grateful should you let me know how to remove... en.kioskea.net/forum/affich-192-your-computer-is-infected
Download Instant Memory CleanerInstant Memory Cleaner an optimizer of your virtual memory is. He allows to force the launching of the pages which exceed physical memory and reduced the size of ongoing processes at the very least. Instant Memory Cleaner allows a direct display of... en.kioskea.net/telecharger/telecharger-525-instant-memory-cleaner
Download VundoFixVundoFix is utilitarian of protection against spywares and viruses. He allows your system of scanner entirely and to eradicate any form of threats: Win32, win antivirus, virtumonde, etc. It is light and honest a simple interface which introduces only... en.kioskea.net/telecharger/telecharger-1048-vundofix
Download The CleanerThe Cleaner must not be confused with CCleaner, and was originally written to counter trojan Back Orifice. In a very short time, it detects quickly thousands of hostile programs and continues to do it nowadays. . This version is not a shareware... en.kioskea.net/telecharger/telecharger-1306-the-cleaner
Processes - autorun - autorun.exe The process autorun.exe (autorun) is a generic Windows 98/NT/Me/2000/XP process which automatically runs a program from a CD-ROM when the CD is inserted in the disk drive. The process autorun is not in any way a virus, a worm, a Trojan horse,... en.kioskea.net/processus/autorun-exe.php3
Viruses - Removal tools A virus removal tool is a small executable file for cleaning a machine which has been infected by a particular virus. Each removal tool is therefore uniquely capable of eradicating a particular kind of virus, or a particular version of a virus. The... en.kioskea.net/virus/desinfection.php3
Processes - explorer - explorer.exe explorer.exe is a Windows NT/2000/XP generic process. It is a process which manages the user interface (shell) as well as the Windows graphical interface (the desktop). The process explorer is not in any way a virus, a worm, a Trojan horse, spyware,... en.kioskea.net/processus/explorer-exe.php3