Spyware Cleanup Conclusion (Part 2)

Part 1 is here.

OK, so I did a little research, and found a few tools I thought my help me. I decided to tackle this one problem at a time. First, let’s get rid of that stupid desktop wallpaper. A quick trip to Display Properties then the Desktop tab, Customize Desktop and the Web tab to get rid of any extra entries there. Then I used this reg file from bleepingcomputer.com to fix the registry entries that were keeping me from changing the wallpaper. One restart later, and that was taken care of.

One problem down. One much more complicated problem left to tackle.

Ewido at least identified what I was dealing with. Something called Adware.Virtumonde. Since this sucker was running even in safe mode, I borrowed an NTFS boot disk from work, and had a couple of tools I found to help specifically and went to town. First I tried out Symantec’s removal tool. Unfortunately, this tool’s scan returned nothing. Couldn’t even find the infection. Not sure if the dll’s had been programmed to hide from Symantec’s tool, or if it was looking for a different version, but either way, this was useless.

The next tool to try was the VundoFix from atribune.org. This was the jackpot. It found the infected dll’s and even managed to kill running processes long enough to get rid of them. After letting it do it’s thing, and restarting, there were no alerts any longer.

At this point, I wanted to do a couple more things. I used the boot disk to make sure the dll’s that had been identified as infected were actually gone. They were. Then I started normally and ran a deep scan using AdAware. When it found nothing, and Process Explorer and Ewido showed no unusual processes, I had a good feeling that we were relatively safe, at least safe enough to run behind my Hawking firewall/router at home, so it was time to hookup to the Internet and start getting updates. Except I couldn’t connect to Windows Update. Seems the hosts file had a whole bunch of entries pointing to 127.0.0.1 including windows update, most A/V company sites, and links to anti-spyware downloads. Seems AVG updates weren’t on that list, and since I was loading programs from my thumb drive, I really hadn’t run into this until now. So I wiped out the hosts file and went back to getting my updates.

After I had all the updates, I grabbed a copy of Windows Defender as well, and ran a full scan with that. It found a couple of left-behind fragments, but nothing that was running currently. I did a quick install of a previous version of Zone Alarm to verify that nothing was trying to connect to the Internet, and then uninstalled it because I’ve been having so many problems with it on our work laptops.

The last thing I did was set-up this machine in a simple, yet relatively safe, configuration. I left AVG, Windows Defender and AdAware installed. I turned on the Windows firewall. I turned on Automatic Updates, and set AVG and Windows Defender to get updates automatically as well. I typed up a description of what I had done along with some recommendations for safe surfing, and I turned it back over to it’s owner Friday morning.

Monday, my wife was handed a nice thank you card and a batch of made-from-scratch, delicious, chocolate chip cookies to take home to me.

In Part 3, an epilogue if you will, I’ll go into detail on why I made some of the choices I did, and try to list some more useful links to help cleanup malware, so if you have any tools that you have been using, let me know so I can add them. Thanks!

Technorati tags: Spyware, VundoFix, smitfraud.reg, WindowsDefender, Ewido, AVG, Vitumonde

Similar Posts

  • One of those days..

    Yeah, today’s another one of those days where there’s a ton of stuff to do, and little interruptions or setbacks just make it all take much longer than I had hoped it would. On the other hand, I’m beginning to see the light at the end of the tunnel on these projects, which is good….

  • Doing my best Kevin Spacey impression

    “I rule!” First off, I did figure out what was going on with my template here, turns out it was my fault, blogger didn’t like those ampersand characters in the javascript for the blogrolling.com stuff, so I’m going to simply keep a copy of my template code as a text file on the server and…

  • A little more politics..

    Which is the more offensive, or just plain stupid quote from this story?: Dick Gephardt: “When I’m president, we’ll do executive orders to overcome any wrong thing the Supreme Court does tomorrow or any other day,” (ed. note: this is the one getting big play on blogs today, because it’s obviously a total disregard for…

  • Movable Type upgrade

    Yes I did, finally, upgrade the Child Abuse blog to MT 3.11. I listed the reasons why over on that site, so I won’t get into all the details of comment spam again over here. The upgrade was pretty painless, and the upgrade of MT-Blacklist wasn’t too bad either. Both allow for a lot more…

  • OneNote video

    Saw a number of pointers to this post on jkOnTheRun: OneNote is one of the most capable programs I use and like all such versatile applications there are a lot of features and capabilities that I am sure I am not using. If you are a budding OneNote user or just trying to figure out…

  • More scary government stuff

    Thanks to My Wife for pointing out this Wash. Post article about the surveillance system the airlines and the FAA are contemplating. To quote: Federal aviation authorities and technology companies will soon begin testing a vast air security screening system designed to instantly pull together every passenger’s travel history and living arrangements, plus a wealth…

One Comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)