Author Topic: *CONFIRMED FIX for the Vundo/Virtumonde / Avast Start / &evenAdobe acrobat error  (Read 11753 times)

0 Members and 1 Guest are viewing this topic.

lenny24

  • Guest
*Again this program worked for me but I take no responsibility if you think it messes up your system. All I know is I downloaded it, it deleted all the Virtumonde / vundo files that vundofix could detect but not delete, as well as additional corrupted Avast, Adobe acrobat, and other files that no other program could detect, remove, or fix. After last Windows boot avast no longer asks for restart, all virus files are gone, and reboot speed is back to normal. Also remember to update your sun java after Virtumonde / vundo infected files are removed. Full info below.

Alright major and GOOD update, I may start a separate thread on this so it gets attention:

I found this thread: http://www.dslreports.com/forum/r19208560-Vundo-Vundo-Removal

The person seemed to have the same problem, could detect but not delete with vundofix. I downloaded combofix mentioned in the middle of the thread and it seems to have kicked Vundo / Virtumonde's @$$ into next Tuesday!  Cool

There are no longer any Vundo files on my system, at least right now, even after reboot.

Combofix also deleted a bunch of other stuff, including some stuff in the avast and Adobe acrobat (another user mentioned) folder, as well as a n=bunch of quicktime stuff.

Avast is still working, I did get the start error during the combofix mid process reboot but not thereafter, and the thing that caused all of this appears to be gone and boot is completely back to normal. Here is a log of what combofix deleted:

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\QuickTime\qttask                 .exe
C:\Program Files\QuickTime\qttask                .exe
C:\Program Files\QuickTime\qttask               .exe
C:\Program Files\QuickTime\qttask              .exe
C:\Program Files\QuickTime\qttask             .exe
C:\Program Files\QuickTime\qttask            .exe
C:\Program Files\QuickTime\qttask           .exe
C:\Program Files\QuickTime\qttask          .exe
C:\Program Files\QuickTime\qttask         .exe
C:\Program Files\QuickTime\qttask        .exe
C:\Program Files\QuickTime\qttask       .exe
C:\Program Files\QuickTime\qttask      .exe
C:\Program Files\QuickTime\qttask     .exe
C:\Program Files\QuickTime\qttask    .exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\opnopqr.dll
C:\WINDOWS\system32\qtutv.ini
C:\WINDOWS\system32\qtutv.ini2
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\vtutq.exe
« Last Edit: January 01, 2008, 01:43:46 AM by lenny24 »

lenny24

  • Guest
Or to be brief  ;D

Go to the thread in the above post, download and run combofix, and after the whole combofix process is done (requires a reboot in mid-process ), reboot again and everything will be fine, vundo / virtumonde will be gone, and avast will be back to normal.

Then update your java past 1.5.

Then thank me & guy who made combofix.  ;D

Edit: I jus noticed that the essex guy posted about combofix as a reply in another thread, so he can be thanked as well,  ;D though this one is definitely easier to find.  8)
« Last Edit: January 01, 2008, 02:10:15 AM by lenny24 »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67195
This is a tutorial for Combofix:

Download ComboFix from Here or Here to your Desktop.

Double click combofix.exe and follow the prompts.

When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

Note: Do not mouseclick combofix's window while its running. That may cause it to stall.
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
If you get this then you will need to run another tool to replace the infected files - not quite as straight forward as it seems

C:\Program Files\QuickTime\qttask           .exe
C:\Program Files\QuickTime\qttask          .exe
C:\Program Files\QuickTime\qttask         .exe
C:\Program Files\QuickTime\qttask        .exe
C:\Program Files\QuickTime\qttask       .exe
C:\Program Files\QuickTime\qttask      .exe
C:\Program Files\QuickTime\qttask     .exe
C:\Program Files\QuickTime\qttask    .exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\QuickTime\qttask.exe

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67195
you will need to run another tool to replace the infected files
Which is it exactly?
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Renv also by sUBs http://download.bleepingcomputer.com/sUBs/Beta/RenV.exe this programme is less than a week old and being refined daily to try and wipeout this particularly nasty version of vundo.  It is a manually operated file programme though so you need someone who knows what is what to give instructions

After the search you need to do this

  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as Log.txt  (Overwrite the existing one)
  • Change the Save as Type to All Files
  • and Save it on the desktop
Code: [Select]
Insert List of files here


Refering to the picture above, drag Log.txt into RenV.exe and attach the resulting report to your reply.

lenny24

  • Guest
Thanks, too late though as I no longer have the log file.  :-[  If the rev program replaces those deleted files then I'll jus uninstall / reinstall quicktime if I have any issues with it, that would work right? The combofix definitely seems to have completely removed Vundo / Virtumonde as nothing is showing with a new search for it, and everything seems to be perfect right now, even with programs that had items removed with combofix. Haven't tried quicktime yet though.
« Last Edit: January 01, 2008, 04:34:25 PM by lenny24 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
No as long as there is just one infected file on your system it starts all over again.  It must be done in one sweep

Download and run the latest combofix and see what it says - delete your current version

lenny24

  • Guest
Alright this is interesting, I ran Combofix again and the system is clean, no bad files were found. It did however create a new folder called qoobox or something on it's second run that made another copy of the original log, so I can run the rev program if I want to, but do I want to since the computer is definitely clean and running perfect already? What does this rev program do again?

second run of combofix also created a quarantine folder. Actually they might have been there from the first run and I didn't notice heh.
« Last Edit: January 01, 2008, 08:02:04 PM by lenny24 »

lenny24

  • Guest
Alright I ran the rev program with the newer log file and it opened like every frigan program on my computer lol. Anyway says system is clean as well. Didn't use the old log because I didn't want those bad qt files replaced anyway.

Also qoobox was created with first run of combofix to quarantine the infected files. Combofix definitely took care of everything, still don't know what rev program did lol but combofix definitely was the solution the Virtumonde / vundo / avast restart issue.
« Last Edit: January 01, 2008, 11:31:54 PM by lenny24 »

lenny24

  • Guest
 ;D Alright I was going through the original log and thankfully for me the program files that were quarantined were not that important. I deleted one of the programs all together, and simply reinstalled quicktime so it wasn't a big issue for me. If however another Vundu infected user uses combofix, it may quarantine something important to them, so make sure afterwards you also have the rev program to disinfect and reinstall any important quarantined files. I was lucky as nothing that important or irreplaceable was deleted.... as I unfortunately deleted the qoobox before I used rev properly. Anyway listen to the other guy too, Combofix is the cure, but you also need to use the rev program to make sure you don't lose any important files after using combofix.  ;D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
You only need the rev programme if you have the newer version of Vundo combofix alone is sufficient for the older types