Spyware Cleanup Conclusion (Part 2)

Part 1 is here.

OK, so I did a little research, and found a few tools I thought my help me. I decided to tackle this one problem at a time. First, let’s get rid of that stupid desktop wallpaper. A quick trip to Display Properties then the Desktop tab, Customize Desktop and the Web tab to get rid of any extra entries there. Then I used this reg file from bleepingcomputer.com to fix the registry entries that were keeping me from changing the wallpaper. One restart later, and that was taken care of.

One problem down. One much more complicated problem left to tackle.

Ewido at least identified what I was dealing with. Something called Adware.Virtumonde. Since this sucker was running even in safe mode, I borrowed an NTFS boot disk from work, and had a couple of tools I found to help specifically and went to town. First I tried out Symantec’s removal tool. Unfortunately, this tool’s scan returned nothing. Couldn’t even find the infection. Not sure if the dll’s had been programmed to hide from Symantec’s tool, or if it was looking for a different version, but either way, this was useless.

The next tool to try was the VundoFix from atribune.org. This was the jackpot. It found the infected dll’s and even managed to kill running processes long enough to get rid of them. After letting it do it’s thing, and restarting, there were no alerts any longer.

At this point, I wanted to do a couple more things. I used the boot disk to make sure the dll’s that had been identified as infected were actually gone. They were. Then I started normally and ran a deep scan using AdAware. When it found nothing, and Process Explorer and Ewido showed no unusual processes, I had a good feeling that we were relatively safe, at least safe enough to run behind my Hawking firewall/router at home, so it was time to hookup to the Internet and start getting updates. Except I couldn’t connect to Windows Update. Seems the hosts file had a whole bunch of entries pointing to 127.0.0.1 including windows update, most A/V company sites, and links to anti-spyware downloads. Seems AVG updates weren’t on that list, and since I was loading programs from my thumb drive, I really hadn’t run into this until now. So I wiped out the hosts file and went back to getting my updates.

After I had all the updates, I grabbed a copy of Windows Defender as well, and ran a full scan with that. It found a couple of left-behind fragments, but nothing that was running currently. I did a quick install of a previous version of Zone Alarm to verify that nothing was trying to connect to the Internet, and then uninstalled it because I’ve been having so many problems with it on our work laptops.

The last thing I did was set-up this machine in a simple, yet relatively safe, configuration. I left AVG, Windows Defender and AdAware installed. I turned on the Windows firewall. I turned on Automatic Updates, and set AVG and Windows Defender to get updates automatically as well. I typed up a description of what I had done along with some recommendations for safe surfing, and I turned it back over to it’s owner Friday morning.

Monday, my wife was handed a nice thank you card and a batch of made-from-scratch, delicious, chocolate chip cookies to take home to me.

In Part 3, an epilogue if you will, I’ll go into detail on why I made some of the choices I did, and try to list some more useful links to help cleanup malware, so if you have any tools that you have been using, let me know so I can add them. Thanks!

Technorati tags: Spyware, VundoFix, smitfraud.reg, WindowsDefender, Ewido, AVG, Vitumonde

Similar Posts

  • Something to think about..

    Kevin is working on a year-end podcast. He has an assignment: Since this will be my last podcast before Christmas, I’m giving you all an assignment for a End of Year Podcast. Either send in audio feedback, ..OR.. call the listener line (206-888-4488), ..OR.. call the Skype line (callto://inthetrenches), and leave your input regarding 1)…

  • What I’m Reading (weekly)

    Test shows if your ISP is throttling Internet speed tags: Tech MM The Importance of Cyber Security: Real Threats to the Legal Industry tags: MM Security LitSupport Flickr Starts Auto-Tagging Photos, Creates a Mess Flickr tags: MM SocNetPres Microsoft Turns OneNote Pages Into WordPress Posts With New Plug-in tags: MM OneNote Blogging Posted from Diigo….

  • Important issues

    Last night I listened to the latest In the Trenches podcast. Kevin and his guest, Chuck Tomasi were discussing a number of issues that I feel strongly about, and have been reminded of recently in my own workplace. They were talking about the image you, as an IT person, project to the people you support…

  • A note to end users

    Now, normally the things I write about here are for other IT folks, sharing information, commiserating about work, or software companies, stuff like that. Today, however, I want to take a moment to talk to the end users and offer up some advice. Now I offer this advice for a very simple reason. When other…

  • It’s 2006!

    Hard to believe another year has passed. So many things have changed that it’s hard to imagine what I was doing last year at this time was only a year ago, but at the same time, it’s also hard to believe this is the 5th new year I’ve welcomed in with my wife since our…

  • Early birthday

    I got so busy yesterday that I forgot to mention that my lovely wife picked up my birthday present a couple of weeks early over the weekend. Since we have thousands of digital photos sitting on the hard drive of my desktop machine at home, and I worry about the ability to back them up…

One Comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)