Trojan Help Needed

tanuj_chadha

Devil
Vista Guru
Hi All,

My System seems to be infected with a Trojan Virtumonde virus :cry:. As per Trojan Remover. It states as the file is hidden. I have tried to find the file manually but was unable to find it. I have run scan using Mcafee, Malware Antibytes, Super Antispyware. But still the system is slow & Trojan remover reports the same infection again & again. Can anyone please give me any last minute idea's before I re-install the operating system.

P.S.: Data is safe on other hard drive partitions.
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM
tanuj_chadha,
DONT REINSTALL YET! WAIT A LITTLE LONGER SINCE ALL YOUR DATA IS SAFE!
Post this in our Security Team Forum and we will be happy to help you. Just post there!
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Hi Tanuj,

Have you tried the Malwarebytes scan in safe mode, most up to date info I have suggests that that should remove this pest, of course it's so adaptable that you could be unlucky enough to have a new variant which is evading everything :cry: if that's the case then a re-install or re-image might be the most time efficient solution
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Graphics card(s)
    Asus nVidia GTX750TI-OC-2GD5 (2GB DDR5)
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal
    Crucial CT256MX100SSD1 256GB SSD,
    Seagate ST2000DM001-1CH1 2TB,

    External (USB3)
    Seagate Backup+ Hub BK SCSI Disk 8TB
    2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs)
    NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel

My Computer

System One

  • Manufacturer/Model
    Airbot 2.0
    CPU
    Core i7 920 (D0) @ 4Ghz, 26c idle- 65c full load on air
    Motherboard
    Asus P6X58D Premium -Sata 6Gb/s - USB 3.0
    Memory
    12GB Corsair Dominator -CMD12GX3M6A1600C8
    Graphics Card(s)
    EVGA Nvidia GTX 480 -Fermi
    Sound Card
    ASUS Xonar D2X
    Monitor(s) Displays
    LG 24" Flatron W2453V-PF Full HD 1080p 2ms response time
    Screen Resolution
    1920x1080@60hz
    Hard Drives
    1 OCZ Vertex2 180GB SSD
    1 TB Samsung Spinpoint F1 7200RPM 32MB cache
    2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

    Pioneer DVD Burner DVR-S18M
    PSU
    Corsair HX1000W
    Case
    Cooler Master HAF 932
    Cooling
    Case Fans -3 230mm, 1 140mm/CPU - Tuniq Tower 120 Extreme
    Keyboard
    Logitech Wireless MK700
    Mouse
    Logitech Wireless MK700
    Internet Speed
    100 MBPS DL 30.17Mbps UL 0.98Mbps
    Other Info
    Windows 7
    Processor-7.7 RAM- 7.9 Graphics-7.9 Gaming Graphics- 7.9 HDD- 7.8

    W.E.I final score= 7.7

    Windows Vista=5.9
I have tried to run malware removal tool in safemode it found approx 35 infections. Removed all of them. Then ran super antispyware & it also removed a trojan from the system. After that ran a scan through trojan remover got the same infection again. What I don't understand is that it states that it has found an infection & the file is hidden. But I am unable to find that file. I have also run the virtumonde fix & rouge fix.

I have not yet run Microsoft Windows Malicious Software removal tool. I would run when I get back home.
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM
I have tried to run malware removal tool in safemode it found approx 35 infections. Removed all of them. Then ran super antispyware & it also removed a trojan from the system. After that ran a scan through trojan remover got the same infection again. What I don't understand is that it states that it has found an infection & the file is hidden. But I am unable to find that file. I have also run the virtumonde fix & rouge fix.

I have not yet run Microsoft Windows Malicious Software removal tool. I would run when I get back home.

Virtumonde/vundo is notoriously hard to get rid of. It likes to replicate itself over and over and stay in the memory. Run MSRT and check your startup services/programs for any traces.
 

My Computer

System One

  • Manufacturer/Model
    Airbot 2.0
    CPU
    Core i7 920 (D0) @ 4Ghz, 26c idle- 65c full load on air
    Motherboard
    Asus P6X58D Premium -Sata 6Gb/s - USB 3.0
    Memory
    12GB Corsair Dominator -CMD12GX3M6A1600C8
    Graphics Card(s)
    EVGA Nvidia GTX 480 -Fermi
    Sound Card
    ASUS Xonar D2X
    Monitor(s) Displays
    LG 24" Flatron W2453V-PF Full HD 1080p 2ms response time
    Screen Resolution
    1920x1080@60hz
    Hard Drives
    1 OCZ Vertex2 180GB SSD
    1 TB Samsung Spinpoint F1 7200RPM 32MB cache
    2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

    Pioneer DVD Burner DVR-S18M
    PSU
    Corsair HX1000W
    Case
    Cooler Master HAF 932
    Cooling
    Case Fans -3 230mm, 1 140mm/CPU - Tuniq Tower 120 Extreme
    Keyboard
    Logitech Wireless MK700
    Mouse
    Logitech Wireless MK700
    Internet Speed
    100 MBPS DL 30.17Mbps UL 0.98Mbps
    Other Info
    Windows 7
    Processor-7.7 RAM- 7.9 Graphics-7.9 Gaming Graphics- 7.9 HDD- 7.8

    W.E.I final score= 7.7

    Windows Vista=5.9
Did you try a System Restore to just before you got the infection ?
 

My Computer

System One

  • Operating System
    Windows 10 Home
    Manufacturer/Model
    HP Envy x360 Convertible 15-bq0xx
    CPU
    AMD A9 Stoney Ridge Technology
    Motherboard
    HP 8312 (Socket FP4)
    Memory
    8.00GB Dual-Channel Unknown (?-0-0-0)
    Graphics Card(s)
    Generic PnP Monitor (1920x1080@60Hz) 512MB ATI AMD Radeon R5
    Sound Card
    AMD High Definition Audio Device Realtek High Definition Aud
    Monitor(s) Displays
    Generic PnP Monitor on AMD Radeon R5 Graphics
    Screen Resolution
    1920 x 1080
    Hard Drives
    119GB SanDisk SD8SN8U-128G-1006 (SSD)
    931GB Hitachi HGST HTS721010A9E630 (SATA
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft Optical Wheel Mouse
    Internet Speed
    62.86Mbps down 18.19Mbps up
    Other Info
    EPSON78D0CF (XP-332 335 Series) (Default Printer)
Malwarebytes.org

That will help get rid of it for the most part - after that you can concentrate on backing up your data for the eventual re-install.
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro X64 Insider Preview (Skip Ahead) latest build
    Manufacturer/Model
    The Beast Model V (homebrew)
    CPU
    Intel Core i7 965 EE @ 3.6 GHz
    Motherboard
    eVGA X58 Classified 3 (141-GT-E770-A1)
    Memory
    3 * Mushkin 998981 Redline Enhanced triple channel DDR3 4 GB CL7 DDR3 1600 MHz (PC3-12800)
    Graphics Card(s)
    eVGA GeForce GTX 970 SSC ACX 2.0 (04G-P4-3979-KB)
    Sound Card
    Realtek HD Audio (onboard)
    Monitor(s) Displays
    2 * Lenovo LT2323pwA Widescreeen
    Screen Resolution
    2 * 1920 x 1080
    Hard Drives
    SanDisk Ultra SDSSDHII-960G-G25 960 GB SATA III SSD (System)
    Crucial MX100 CT256MX100SSD1 256GB SATA III SSD (User Tree)
    2 * Seagate Barracuda 7200.12 ST31000528AS 1TB 7200 RPM SATA II Mech. HD
    Seagate ST1500DL001-9VT15L Barracuda 7200.12 1.5 TB S
    PSU
    Thermaltake Black Widow TX TR2 850W 80+ Bronze Semi-Mod ATX
    Case
    ThermalTake Level 10 GT (Black)
    Cooling
    Corsair H100 (CPU, dual 140 mm fans on radiator) + Air (2 *
    Keyboard
    Logitech G15 (gen 2)
    Mouse
    Logitech MX Master (shared)
    Internet Speed
    AT&T Lightspeed Gigabit duplex
  • Operating System
    Sabayon Linux (current, weekly updates, 5.1.x kernel)
    Manufacturer/Model
    Lenovo ThinkPad E545
    CPU
    AMD A6-5350M APU
    Motherboard
    Lenovo
    Memory
    8 GB
    Graphics card(s)
    Radeon HD (Embedded)
    Sound Card
    Conextant 20671 SmartAudio HD
    Monitor(s) Displays
    Lenovo 15" Matte
    Screen Resolution
    1680 * 1050
    Hard Drives
    INTEL Cherryvill 520 Series SSDSC2CW180A 180 GB SSD
    PSU
    Lenovo
    Case
    Lenovo
    Cooling
    Lenovo
    Mouse
    Logitech MX Master (shared) | Synaptics TouchPad
    Keyboard
    Lenovo
    Internet Speed
    AT&T LightSpeed Gigabit Duplex
Yep sounds like you need to do a system restore for a while back.
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
I have a great mind. Before I got the infection i had cleaned my system using mcafee & also removed system restore points (accidentally).
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM
Ouch. That stink. So what type of system are you running?
If its a dell, then this will be very easy!
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Sorry, but I don't have a dell system. I have a custom made system. Working on windows vista.

But just out of curiosity, what would be the option if was using a Dell system.
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM
Here is most likely the best solution for your problem
To use PC Restore: This will reset you computer to its original state you had it when it first came out of the box. Your HDD with be wiped out and restored with the exact things as when you first got your computer.

1 Turn on the computer.

2 Immediately press <Ctrl><F11>.

If you do not press <Ctrl><F11> in time, let the computer finish restarting, and then restart the computer again.

Everything will be pretty much self explanitory after this.

You will be all set after you do this. Once again though I am only familiar with Dell systems using this method. Make sure you back up all files you want to keep though.

Let me know,
Ben
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Thanks for the info Ben. My friend is using a dell system with windows xp on it. Guess this would be useful for him. I am trying to search more to find if anything else can be done. As installing all the software's back after re-install would be a pain in the neck
:sa:. Which I am not in a mood for after a long weeks work.
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM
understandable
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Hi all,

The only thing I would like to add is ...

because of the design of system restore (it only operates on windows system files not user data files), although a restore to a point before the virus became visible would reset windows system files to a good state, (non infected), the actual dropper file for the infection is likely to be in a non system file and so may re-infect the system.

It is highly advisable that as soon as the system restore is completed appropriate steps are taken to fully eradicate the Malware from the system.
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Graphics card(s)
    Asus nVidia GTX750TI-OC-2GD5 (2GB DDR5)
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal
    Crucial CT256MX100SSD1 256GB SSD,
    Seagate ST2000DM001-1CH1 2TB,

    External (USB3)
    Seagate Backup+ Hub BK SCSI Disk 8TB
    2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs)
    NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel
Update: I ran the Malacious Software Removal Software. It Picked up no infections in the quick scan. Running a through scan now. And as usual cpu usage is 100% again.
Please help before my weekend goes down the drain in installing the software.
 

My Computer

System One

  • CPU
    T4200 Intel
    Memory
    2 X 1GB DDR2
    Graphics Card(s)
    Intel Integrated
    Hard Drives
    1 X 250GB 7200RPM
Hi Tanuj

This entry in of all places - Wikipedea - seems to mention the Hidden portions of the trojan, Plus it provides links to a few free applications which have been successful in the past, it may be worth you having a look at the links ...

Vundo - Wikipedia, the free encyclopedia
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro x64 Latest Release Preview
    Monitor(s) Displays
    Acer G276HL 27", (DVi) + Samsung 39" HDTV (HDMI)
    Screen Resolution
    2 x 1920x1080 @50Hz
  • Manufacturer/Model
    Real World Computers (Custom by Me)
    CPU
    AMD FX8350 Vishera 8 Core @4GHz
    Motherboard
    Asus M5A78L-M USB3
    Memory
    32GB [4x8GB] DDR3 1600 MHz
    Graphics card(s)
    Asus nVidia GTX750TI-OC-2GD5 (2GB DDR5)
    Sound Card
    ASUS Xoner DG + SPDIF to 5.1 System + HDMI
    Monitor(s) Displays
    Samsung 32" TV
    Screen Resolution
    1920 x 1080
    Hard Drives
    Internal
    Crucial CT256MX100SSD1 256GB SSD,
    Seagate ST2000DM001-1CH1 2TB,

    External (USB3)
    Seagate Backup+ Hub BK SCSI Disk 8TB
    2.5/3.5 Hot Swap Cradle, USB3 + eSata (client HDDs)
    NAS 4TB
    PSU
    Aerocool Templarius Imperator 750W 80+ Silver
    Case
    AeroCool X-Warrior Red Devil Tower
    Cooling
    Hyper103 CPU, Rear 120mm, Front 2x120mm, Side 2x120mm
    Internet Speed
    68 MB Down 18.5 MB Up
    Other Info
    Six Sensor Auto / Manual Digital cooling (Fan) control with Touch control Panel
Hi All,

My System seems to be infected with a Trojan Virtumonde virus :cry:. As per Trojan Remover. It states as the file is hidden. I have tried to find the file manually but was unable to find it. I have run scan using Mcafee, Malware Antibytes, Super Antispyware. But still the system is slow & Trojan remover reports the same infection again & again. Can anyone please give me any last minute idea's before I re-install the operating system.

P.S.: Data is safe on other hard drive partitions.
Also try smitfraudfix.
Download link: http://www.bleepingcomputer.com/resources/link243.html
 

My Computer

System One

  • Manufacturer/Model
    Compaq
    CPU
    intel core 2 duo T 5550 @ 1.83 MHz
    Motherboard
    intel 965 chipset family
    Memory
    2 GB DDR 2 SD RAM @ 667 MHz
    Graphics Card(s)
    On board upto 358 MB RAM
    Sound Card
    Onboard
    Monitor(s) Displays
    15"
    Hard Drives
    160 GB WDC
My uncle, is the head security expert at his corporation.
He said these recent viruses and Trojans are very very hard to get rid of and are almost immpossible to get ride of. He is actually working on a solution to get rid of these in his spare time.
Hopefully it is soon because these are starting to get very redicilous.
 

My Computer

System One

  • Manufacturer/Model
    Dell
    CPU
    Intel(R) Celeron(R) CPU 420 @1.60 GHz
    Motherboard
    Dell Inspion 530 Default
    Memory
    PNY 4GB 240-Pin SDRAM DDR2 800 (PC2 6400) Dual Channel
    Graphics Card(s)
    ATI Radeon HD 2400 PRO
    Sound Card
    Realtek HD Audio
    Monitor(s) Displays
    Gateway PnP Monitor
    Screen Resolution
    1024x768 @ 75 Hz
    Hard Drives
    Seagate 250G ATA SATA-II
    Case
    Dell Inspiron 530
    Cooling
    None
    Keyboard
    Logitech EX100 Combo
    Mouse
    Logitech EX100 Combo
    Internet Speed
    100 MB/s
Back
Top