Virtumondo :-(

F

~ Free Spirit ~

I hope someone can help. A friend called to day all upset because MSAV
found Virtumondo on his PC and can't remove it. It takes him to some
strange websites. How can I help him as he's almost computer illiterate.
Any ideas? He's running WXP-Pro, with the usual AV, MSAV, Spybot etc.

Any and all suggestion are welcome.
 
D

Dave M

Hello FS;
Virtumondo is a tough one. Your friend is going to need some major help... no
doubt.
See the thread below in this forum:
From: <[email protected]>
Subject: Help getting rid of Virtumondo
Date: Tue, 25 Oct 2005 18:31:02 -0700
 
F

~ Free Spirit ~

Dave M said:
Hello FS;
============
Thanks,... I'll pass everything I find below on to him. I sent him some
info from a few websites last night. I think he'll need to bring his PC to
a shop for this one.

FS~
 
J

Jim Byrd

Hi FS - Four approaches to removing Winfixer (Vundo)

1 - Symantec has a new Vundo remover:
http://securityresponse.symantec.com/avcenter/FixVundo.exe
http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.removal.tool.html


2 - It's been reported that the McAfee Removal Tool here is worthwhile:
http://forums.mcafeehelp.com/viewtopic.php?t=57049


3 - Then, courtesy of MVP Suzi Turner and Mosaic1:

"Atribune, a guy in the forums, has a Vundo fix tool as well:

Instructions for use by user as posted in the SpywareWarrior forum:

'Please download VundoFix.exe to your desktop. Here's a link:

http://www.atribune.org/downloads/VundoFix.exe

Double-click VundoFix.exe to extract the files
This will create a VundoFix folder on your desktop.
After the files are extracted, please restart your computer into Safe Mode.

Once in safe mode open the VundoFix folder and double-click on KillVundo.bat

A command window will open and it should look like this:

VundoFix V2.1 by Atri
By pressing enter you agree that you are using this at your own risk

At this point press enter one time.

Next you will see:

Type in the filepath as instructed by the forum staff
Then Press Enter, to continue with the fix.


At this point please type the following file path (make sure to enter it
exactly as below!):
C:\WINDOWS\system32\geeby.dll

Press Enter.

Next you will see:

Please type in the second filepath as instructed by the forum staff

At this point please type the following file path (make sure to enter it
exactly as below!):
C:\WINDOWS\system32\ybeeg.*

Press Enter to continue.

The fix will run then HijackThis will open.
In HijackThis, please place a check next to the following items and click
FIX CHECKED:


O2 - BHO: MSEvents Object - {52B1DFC7-AAFC-4362-B103-868B0683C697} -
C:\WINDOWS\system32\geeby.dll
O20 - Winlogon Notify: geeby - C:\WINDOWS\system32\geeby.dll

After you have fixed these items, close Hijackthis.

The fix will tell you to shutdown using the Power button. Hold in your power
button until the computer shuts down. Wait about 15 seconds and then restart
the computer into regular windows.

Chkdsk will run. This is normal. It will take a few minutes and is checking
your file system because of the Bad Shutdown we caused.

Go for free online Virus scans here:

http://housecall.trendmicro.com/housecall/start_corp.asp
http://www.pandasoftware.com/activescan/

Allow them to clean

Panda will have the option to create a log after the scan has finished.
Click
the See Report button. Then click the save Report button. It will be saved
under the name activescan.txt Do that and post that log into your next reply
here.

Run hijackthis and post the new log and the vundofix.txt file from the
vundofix folder into as well.'
----------------------------------------------------------------------------
--

The forum helpers have reported this fix from Atribune works. I don't know
about the Symantec tool.

If you'd like to join Spyware Warrior, you could see the thread where the
helpers are discussing this.

Suzi"


4 - Finally, you can try the fix and tool outlined here:
http://forums.mcafeehelp.com/viewtopic.php?t=57049 It has been reported to
be successful in several cases.

_____________________________________________________

Here's the HijackThis info you may need:

Download HijackThis, free, here:
http://209.133.47.200/~merijn/files/HijackThis.exe (Always download a new
fresh copy of HijackThis [and CWShredder also] - It's UPDATED frequently.)
You may also get it here if that link is blocked:
http://www.majorgeeks.com/downloadget.php?id=3155&file=3&evp=3304750663b552982a8baee6434cfc13

There's a good "How-to-Use" tutorial here:
http://computercops.biz/HijackThis.html

In Windows Explorer, click on Tools|Folder Options|View and check "Show
hidden files and folders" and uncheck "Hide protected operating system
files". (You may want to restore these when you're all finished with
HijackThis.)

Place HijackThis.exe or unzip HijackThis.zip into its own dedicated folder
at the root level such as C:\HijackThis (NOT in a Temp folder or on your
Desktop), reboot to Safe mode, start HT then press Scan. Click on SaveLog
when it's finished which will create hijackthis.log. Now click the Config
button, then Misc Tools and click on Generate StartupList.log which will
create Startuplist.txt


Then go to one of the following forums:

Spyware and Hijackware Removal Support, here:
http://forums.spywareinfo.com/
or Jim Eshelman's site here: http://forum.aumha.org/
or Bleepingcomputer here: http://www.bleepingcomputer.com/
or Computer Cops here: http://www.computercops.biz/forums.html
or Tom Coyote here: http://forums.tomcoyote.org/index.php?act=idx
or Net-Integration here:
http://www.net-integration.net/cgi-...86d536d57b5f65b6e40c55365e;act=ST;f=27;t=6949

Register if necessary, then sign in and READ THE DIRECTIONS at the beginning
of the particular site's HiJackThis forum, then copy and paste both files
into a message asking for assistance, Someone will answer with detailed
instructions for the removal of your parasite(s). Be sure you include at
the beginning of your post a description of "What specific
problem(s)/symptoms you're trying to solve" and "What steps you've already
taken."




*******
ONLY IF you've successfully eliminated the malware, you can now make a new,
clean Restore Point and delete any previously saved (possibly infected)
ones. The following suggested approach is courtesy of Gary Woodruff: For XP
you can run a Disk Cleanup cycle and then look in the More Options tab. The
System Restore option removes all but the latest Restore Point. If there
hasn't been one made since the system was cleaned you should manually create
one before dumping the old possibly infected ones.
*******


When you get things cleaned up, take a look at my Blog, Defending Your
Machine, addy in my Signature below, for some additional curative and
preventive measures you might want to implement to help prevent this type of
thing in the future.
 
F

~ Free Spirit ~

Jim Byrd said:
==============
Thanks I just sent him the whole message. I hope his brother can give him a
hand with this. Do you know how this gets ON a PC? He hasn't downloaded
anything from the net, no new programs or anything........ ????

FS~
 
J

Jim Byrd

Hi FS - Well, in addition to getting it directly from Winfixer.com, it's
thought that the most usual infection vector is by a user downloading and
installing "free programs" from untrusted sites or file sharing networks
which also install this and/or other "malware" at the same time. The moral
here, of course, is to read carefully any EULA before installing ANYTHING to
be sure that you aren't also acquiescing to inviting in bad boys at the same
time by failing to "Just Say NO", and to be especially careful about "free"
things which generally derive their revenue from some form of advertising.
There have also been some reported infestations from some Limewire
installations and from an unauthorized/modified IE7 Beta that's been
floating around.

In addition, we have recently come to suspect that this "malware" _may_
possibly be exploiting a bug in some earlier versions of Sun Java, and are
now recommending that Sun Java 5 be installed and that ALL earlier versions
be REMOVED from your computer, since it's thought that "malware" may
possibly be
utilizing them via this exploit even if a latter version is currently being
used in your browser if they are still present on your machine.

Your friend (and you) need to make sure that you stay up-to-date with ALL
critical patches/updates to your system and to your various anti-virus and
anti-malware tools. There's extensive detailed information in my Blog,
Defending Your Machine, addy below in my Signature about steps you can take
and resources available to clean up your machine and to help prevent this
from happening again.


Perhaps this will help some.
 
S

Steve Wechsler [MVP]

One note from Jim's instructive post ... the .dll's file name :

C:\WINDOWS\system32\*geeby.dll*

will be different on different systems. What you can do to identify it
is to scan the system with HijackThis and look at the O2 BHO and/or O20
Winlogon entries to find out it's name. Close all other programs and
browsers prior to scanning with HJT.
REMEMBER that there is a hidden file that will have the name of the .dll
spelled backwards. Enter that name when the VundoFix requests the path
to the second file.

Grinler, a Security MVP, has another removal method that can be used if
the recommended method fails :
http://www.bleepingcomputer.com/forums/topic18610.html

Steve Wechsler (akaMowGreen)
MS-MVP 2003-2006
===============
*-343-* FDNY
Never Forgotten
===============
 
F

~ Free Spirit ~

Jim Byrd said:
Thanks Mow - I've added that to the post. :)
===========
I want to thank all of your for the information. His brother was able to
remove it from his PC last night. He thinks his college age son got it from
one of those share programs like WinMX.

FS~
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top