Spyware Cleanup Conclusion (Part 2)

Part 1 is here.

OK, so I did a little research, and found a few tools I thought my help me. I decided to tackle this one problem at a time. First, let’s get rid of that stupid desktop wallpaper. A quick trip to Display Properties then the Desktop tab, Customize Desktop and the Web tab to get rid of any extra entries there. Then I used this reg file from bleepingcomputer.com to fix the registry entries that were keeping me from changing the wallpaper. One restart later, and that was taken care of.

One problem down. One much more complicated problem left to tackle.

Ewido at least identified what I was dealing with. Something called Adware.Virtumonde. Since this sucker was running even in safe mode, I borrowed an NTFS boot disk from work, and had a couple of tools I found to help specifically and went to town. First I tried out Symantec’s removal tool. Unfortunately, this tool’s scan returned nothing. Couldn’t even find the infection. Not sure if the dll’s had been programmed to hide from Symantec’s tool, or if it was looking for a different version, but either way, this was useless.

The next tool to try was the VundoFix from atribune.org. This was the jackpot. It found the infected dll’s and even managed to kill running processes long enough to get rid of them. After letting it do it’s thing, and restarting, there were no alerts any longer.

At this point, I wanted to do a couple more things. I used the boot disk to make sure the dll’s that had been identified as infected were actually gone. They were. Then I started normally and ran a deep scan using AdAware. When it found nothing, and Process Explorer and Ewido showed no unusual processes, I had a good feeling that we were relatively safe, at least safe enough to run behind my Hawking firewall/router at home, so it was time to hookup to the Internet and start getting updates. Except I couldn’t connect to Windows Update. Seems the hosts file had a whole bunch of entries pointing to 127.0.0.1 including windows update, most A/V company sites, and links to anti-spyware downloads. Seems AVG updates weren’t on that list, and since I was loading programs from my thumb drive, I really hadn’t run into this until now. So I wiped out the hosts file and went back to getting my updates.

After I had all the updates, I grabbed a copy of Windows Defender as well, and ran a full scan with that. It found a couple of left-behind fragments, but nothing that was running currently. I did a quick install of a previous version of Zone Alarm to verify that nothing was trying to connect to the Internet, and then uninstalled it because I’ve been having so many problems with it on our work laptops.

The last thing I did was set-up this machine in a simple, yet relatively safe, configuration. I left AVG, Windows Defender and AdAware installed. I turned on the Windows firewall. I turned on Automatic Updates, and set AVG and Windows Defender to get updates automatically as well. I typed up a description of what I had done along with some recommendations for safe surfing, and I turned it back over to it’s owner Friday morning.

Monday, my wife was handed a nice thank you card and a batch of made-from-scratch, delicious, chocolate chip cookies to take home to me.

In Part 3, an epilogue if you will, I’ll go into detail on why I made some of the choices I did, and try to list some more useful links to help cleanup malware, so if you have any tools that you have been using, let me know so I can add them. Thanks!

Technorati tags: Spyware, VundoFix, smitfraud.reg, WindowsDefender, Ewido, AVG, Vitumonde

Similar Posts

  • Disconnect

    So not only was I home sick yesterday, but our cable internet went on the fritz for a good part of the afternoon, and then, just as I was getting used to having it back, we discovered that the phone was dead. Talk about feeling out of it! It’s very possible that we will be…

  • Good times

    As fate would have it, Erik is in town this week as part of his consulting gig, working with a client located just outside of Columbus. We arranged to meet up for dinner last night, me and my lovely wife, Erik and his lovely coworker, Dave. 😉 After some initial confusion over directions, (no really…

  • It’s been a long week

    It really has. There’s just been so much going on at work, and outside work with doctor visits (nothing serious, no worries), board meetings, website updates, etc. But now we’re off the Vegas for 5 days of forgetting that I even have a job! I’m taking the laptop though, taking lots of photos, and I…

  • Installing

    OK, I’ve got the MS Office beta, OneNote beta, InfoPath beta and Publisher beta installed. It wasn’t overly difficult and ran into only one small problem. Outlook on first start needed me to reinsert the Office CD in order to create the first “welcome message”. It was ok 1 minute later. Activation took about a…

  • I was a young blogger

    I just noticed something. Over on the list of folks who subscribe to this blog via Bloglines, there are a couple listed as having been subscribed since January 1, 1970. That means I was blogging at 1.5 years old, right? Gee I hope I’ve gotten better since then. Tags: Bloglines ESBN 56326-060227-480400-27 Rate content: Follow…

  • Excuse me…

    Pardon the interruption in normal blogging patterns. I’ve been spending an inordinate amount of time this afternoon losing an argument with a tape drive. I’m in the right on this argument, but I’m afraid it’s circular logic pattern has left us both stuck with quite the conundrum. (If a tape drive doesn’t detect a tape…

One Comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)