PDA

View Full Version : Another Virtumonde/Smitfraud victim



travlinsouth1
2008-08-11, 22:11
So it looks like I've fallen victim to these popular virii, as of last Wed (8/6/08). I seemed to get the worst of it, losing access to my desktop, C:drive, control panel, etc.

Prior to the infestation, I had an older version SBS&D (tea-timer not running) and AVG. As directed in the "before you post" procedure, I downloaded 1.6, and installed all the updates, and ran S&D again, catching a dozen or more files, and this restored some of the functionality. I got a (paraphasing here) "S&D recommends that you restart and run the search again If you want to do this, click 'yes', save your work and restart" dialogue box (twice), and clicked yes. I let it finish, closed S&D, and the machine seemed to reboot, and S&D scan ran again, catching 5 or so more files.

I've since run S&D several times from Safe mode, with each time it catching what look like the same 4 problems: 1 virtumonde .dll file, 2 virtumonde registry changes and 1 smitfraud .dll file, always with the two dialogue boxes advising to restart during the scan (both in the 131k range. the second one is at 131,438, I think, the first one in the 131200's). I've generally checked "yes" and let the scan finish, usually fixing the flagged files. My computer continues to behave as though infected, though, with a "services.exe" task taking up 95+% of my CPU time, according to my taskmanager. Because the scan takes more than an hour, and seems to be catching the same files over and over again, it seems more thorough methods are in order. I've also run it several times again in normal mode, with seemingly no progress.

When I'm in safe mode, the machine doesn't seem to restart the scan automatically, though it does when I run in normal mode. Several times in the initial run, and a few times since, I've been asked to "accept" or "decline" a registry chance, usually involving a "spybotdeleting" type entry. I've got tea-timer runing now, and presumably this is related. Unsure of what to do, I've both "accepted" and "declined", with no particular consistency.

I downloaded and tried to run HijackThis, but I've been having trouble: I get an "HijackThis.exe has generated errors and will be closed by windows. You will need to restart the program. An error log has been generated." dialogue box. Accordingly, I can't post a HijackThis log. This may be unrelated to the virus, since I occasionally got that message with other programs - notably Outlook - prior to Wednesday.

I'm running Windows 2000 5.00.2195 SP 4 on a Compaq Armada e500. I bought the machine used, and it's my understanding that the previous owner had a problem with viruses, but had the hard drive re-formatted and windows re-installed immediately before I purchased it.

Any help you can give in get my machine running more smoothly would be most grateful. Thanks in advance.

Blade81
2008-08-15, 13:02
BEFORE you POST
(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) ;)

Hi

Download and install TrendMicro HijackThis (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe)
* Once installed open HijackThis by clicking Start > Programs > HijackThis and click the button labeled
Do a system scan only

* Click the scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
* Once the scan is complete the scan button will now read save log. Click this button to save the log file to your PC. Once you select where you would like to save the file it will open in your systems default text editor. Typically this application is Notepad. Post the log here.

travlinsouth1
2008-08-15, 20:21
I downloaded and tried to run HijackThis, but I've been having trouble: I get an "HijackThis.exe has generated errors and will be closed by windows. You will need to restart the program. An error log has been generated." dialogue box. Accordingly, I can't post a HijackThis log. This may be unrelated to the virus, since I occasionally got that message with other programs - notably Outlook - prior to Wednesday.



Hi Blade,

Thanks so much for your help.

I guess I wasn't clear: I did download and install HijackThis, but it doesn't run. As I said, I don't think this is related to the infection, but I still don't know how to fix it. I've tried various configurations (safe mode, etc) but it still doesn't run.

Any further guidance you can give would be appreciated.

Thanks.

Blade81
2008-08-15, 21:22
Hi

Please try renaming HijackThis.exe file -> travlinsouth1.exe and running it again.

travlinsouth1
2008-08-21, 07:46
I did try renaming the HijackThis app, but still couldn't run it. I also tried Vundofix, to no avail. I've heard good things about vundobegone.exe, but, in the end, decided to go the reformat route, as I suspect I had problems deeper than just the vundo. Anyway, thanks for your help. Goodluck out there.

travlin'

Blade81
2008-08-21, 07:54
Ok. Thanks for letting us know. Positive thing is that after reformat system is clean for sure :)

Since this issue appears to be resolved ... this Topic has been closed.

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.