This self-help guide will allow you to remove Virtumonde - DEL-457 (StopGuard, VIPFares, Hostx.exe)
What this program does: May modify the cookies on your machinea s well as display popups.
Tools Needed for this fix: Related Tutorials: Symptoms in a HijackThis Log (May be different file names):
O2 - BHO: CATLEvents Object - {77849D67-5672-4B68-93E2-CCEFF1E3949E} - C:\WINDOWS\TEMP\DAAVAJ.DAT
O4 - HKLM\..\Run: [*JAVAAD] C:\WINDOWS\APPPATCH\JAVAAD.EXE
O4 - HKLM\..\RunOnce: [*JAVAAD] C:\WINDOWS\APPPATCH\JAVAAD.EXE rerun
O4 - HKCU\..\RunOnce: [*MS Setup] C:\WINDOWS\FONTS\WINCAB.EXE ren
How to spot the infection:
- There will be entries with the
rerun argument or a ren argument as shown above.
- The O2 entry will be named CATLEvents Object and the filename
for it will be an
anagram for one of the O4 entries.
- The names of the O4 entries will be preceded by a *. Some entries with
are a preceeding start are valid. See the warning below.
- This infection will always install a file called c:\windows\system32\bkinst.exe and sometimes a file called c:\windows\system32\host.exe that will not show via HijackThis.
Warning: If you are using Windows ME you may see the following entry in your log O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
This is a valid entry and should be left alone.
Below are some example file names you may find associated with this infection. Please be aware, that there may be some legitimate programs that use these names, so you must see if the other symptoms exist as well. keybas.exe avmsvc.exe bkinst.exe hostx.exe dvdcat.exe tapinet.exe hardcab.exe oledisk.exe asras.exe keyiis.exe vbcab.exe srvwin.exe cabmfc.exe pctcp.exe acxml.exe svcsys.exe
Instructions: Updated Information 11/29/04 : A new tool has been released by Symantec that has the ability to remove this infection in some cases. It is advised that you use this utility first when attempting to remove this infection. Download the utility from the following link: Symantec Virtumonde Removal Tool Once it is downloaded, run the tool and and let it scan your machine. It will remove any files that it finds. If you are still having a problem after running this tool, then follow the manual removal method below. Manual Removal:
- Download HijackThis from the above link and extract it to c:\hijackthis.
- Navigate to the c:\hijackthis directory and double-click on HijackThis
- When the program starts, double-click on the HijackThis icon and then click
on the Scan button.
- Examine the log for those entries that look like they apply to
this infection. Use the criteria given above to do so.
- Write the filenames in these entries down on a piece of paper,
including the pathname. For example C:\WINDOWS\APPPATCH\JAVAAD.EXE.
- Now download and extract killbox from the above link. Extract the
program to your desktop and double-click on its folder for it and
then double-click on Killbox.exe to start the program.
- In the killbox program, select the Delete on Reboot option.
- In the field labeled Full Path of File to Delete enter
the name of the first file found in Step 2. For example, C:\WINDOWS\TEMP\DAAVAJ.DAT
- Press the button that looks like a red circle with a white
X in it. When it asks if you would like to Reboot now, press
the NO button.
- Redo steps a through c for
each of the other files found in step 2.
- When those files are completed, do steps a through c again
and enter the file c:\windows\system32\hostx.exe as
the filename to delete. When it asks to reboot you should press NO this
time.
- No do steps a through c again
but this time enter the last file c:\windows\system32\bkinst.exe as
the filename to delete. When it asks to reboot you should press YES this
time.
- In the killbox program, select the Delete on Reboot option.
- After the computer reboots run HijackThis again and press the Scan button.
- Put a checkmark next to each of the entries found in Step 2 and
then press the Fix button.
- Reboot your computer and confirm that it is working properly.
- Examine the log for those entries that look like they apply to
this infection. Use the criteria given above to do so.
Now your computer should no longer be infected with the Virtuomonde malware.
This is a self-help guide. Use at your own risk.
BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum.
If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.



Back to top







