Help, this Virtumundo is causing my Explorer instability

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hello,

This Virtumundo (malware) has resurfaced after going thru deletion
procession by using Ad-Aware SE. It's causing my Explorer instability. Any
advice would be appreciated. Thanks!
 
Hi Tay :-)

There are some variants of malware that can replicate themselves repeatedly,
and even mutate anew, if they are not removed properly. Although you may
have already run one or more of the programs, please do so again according
to the instructions below. Some variants of malware can replicate
themselves over and over if not removed properly. Please follow all
instructions carefully to be sure your system is thoroughly cleaned:

Step one:
Run Ad-Aware:
Download the latest version of AdAware at
http://www.lavasoftusa.com/support/download/

After installing AAW, and before running the program, you NEED to FIRST
update the reference file following these instructions.

Now do the following:

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."

- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."

Press "Scan Now"

- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:

Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"

Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.


Download:

1.) http://members.shaw.ca/techcd/VB_Projects/Killmsg118.exe

2.) -L2M.zip from- http://www10.brinkster.com/expl0iter/fr...2M/L2M.htm


Restart your computer, remain offline and run "Killmsg118.exe".
Your computer should restart.

Unzip "L2M.zip" , Double click on the "L2M.reg" file, and hit->yes to the
registry merge prompt.
That will remove all the related registry entries including the 'hijacked'
user agent key!

When done, search your hard drive and delete these files from any location:
(if exist)

-msg118.dll
-msguard.dll
-msg118.txt
-oe.bat

-----
Download and then extract Hijackthis.exe to a new folder. Do not run it
from the zip the desktop or a temp folder.

http://www.majorgeeks.com/downloadget.p...e6434cfc13

Do not remove anything using HijackThis. It lists many types of entries.
Some are good, and others need to be removed. Post the hijackthis log to
the one of the following forums to be analyized by the experts there to tell
you what corrective action to take, if necessary .

AumHa Forums: HijackThis
http://forum.aumha.org/viewforum.php?f=30
Computer Cops
http://computercops.biz/forum67.html

You will have to register to post your log, but, it is ok....there are no
spammers there. just experts to read and help you. Follow their
instructions:

You should also download, update and run the following programs as well, to
make sure your system is totally free of scumware:

Sysclean.com, from Trend Micro, here:
http://www.trendmicro.com/download/dcs.asp
along with the latest pattern file, here:
http://www.trendmicro.com/download/pattern.asp
Be sure to read the "How-to" info here:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
(You might also want to get Art's updater, SYS-UP.Zip, here for future
updating of these:
http://home.epix.net/~artnpeg/).
About:Buster
http://www.majorgeeks.com/download4289.html
http://www.atribune.org/downloads/AboutBuster.zip
SpyBot Search & Destroy
http://www.majorgeeks.com/download2471.html


If these steps do not resolve your problem, please post back to this thread
with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
Replies are posted only to the newsgroup for the benefit or other readers.

How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
Hi Tay :-)

Sorry, the links were good when I posted, I always check before I post.
However, I see they are not available at this time, and there are several
other links that have not been available for some reason today and
yesterday.

I suggest that you go here and get an online scan, then if you have not done
so yet, download the AdAware SE and HiJackThis and run them. Be sure to
update the AdAware 'before' you run it to be sure you have the latest
definitions. Post your HiJackThis log to either of the two forums below to
have it read by the experts there and let them advise you of any necessary
cleaning actions to be taken. DO NOT remove anything from the log yourself
if you do not know for user what you are doing. Removal of some files can
cause serious damage to your system.

Where to post HiJackThis logs:

You will need to register at these forums.

Aumha Forums:
http://forum.aumha.org/viewforum.php?f=30
or
ComputerCops
http://computercops.biz/forums.html
Under HiJackThis Section
(Note: This forum has had server problems and may be down again, if so, use
AumHa)

Download these programs here: These sites were available as of this
posting.

AdAware SE Personal - Free
http://www.majorgeeks.com/downloadget.php?id=506&file=11&evp=8dbaff7daca8f4b55bf695220993fc0f

AdAware VDX.exe plug-in - recommended - Free
http://www.majorgeeks.com/downloadget.php?id=4283&file=11&evp=34312f31f5a8511bfb7cf839b1eaff0b

HiJackThis - Free
http://www.majorgeeks.com/downloadget.php?id=3155&file=11&evp=3304750663b552982a8baee6434cfc13

Also.....

CAUTION!!!!! Before you try to remove spyware using any of the programs
below, download a copy of LSPFIX from any of the following sites:
http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html
(if your OS is Win2k or XP) The process of removing certain malware may kill
your internet connection. If this should occur, this program, LSPFIX, will
enable you to regain your connection.

Also, get a copy of WINSOCKXPFIX available at:
http://www.spychecker.com/program/winsockxpfix.html
and
WinsockXP Fix- WinXP
http://www.spychecker.com/program/winsockxpfix.html
Also, with instructions, at
http://www.iup.edu/house/resnet/winfix.shtm
also
From LavaSoft- all versions of Windows-
http://digital-solutions.co.uk/lavasoft/whndnfix.zip
also ....
(NOTE: It is reported that in XP SP2, the command netsh winsock reset
will fix this problem without the need for these programs.)


If these steps do not resolve your problem, please post back to this thread
with the details and any error messages.

Hope this helps

Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
Replies are posted only to the newsgroup for the benefit or other readers.

How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
Hi Robert :-)
Where did you find that?
I suspect (due to the ellipsis) that this is a copy of the anchor
and not the underlying link. In order to copy the link you should
use right-click, Copy shortcut

My fault on this one, I provided it for the OP in my previous response. I
had used it before, but, obviously, it is no longer available. :/


Jan :)
Smiles are meant to be shared,
that's why they're so contagious.

Please reply to the newsgroup so others may benefit.
Replies are posted only to the newsgroup for the benefit or other readers.

How to make a good newsgroup post:
http://www.dts-l.org/goodpost.htm
 
Back
Top