Virtumonde - Does anyone know how to clean this?

Reply

Join Date: Apr 2006
Posts: 9
Reputation: grungetta is an unknown quantity at this point 
Solved Threads: 0
grungetta grungetta is offline Offline
Newbie Poster

Virtumonde - Does anyone know how to clean this?

 
0
  #1
Jun 22nd, 2006
Hi there,

I'v had heaps of problems lately, symptoms like popups to anti-virus software sites, adult sites, system restarting. It seems I have successfully removed some trojans, but with this particular one, it just keeps coming back.

Whenever I attempt to delete the Virtumonde in the registry - even in safe mode, after it has been deleted from AdAware, TrojanHunter, and even PCCillin, I immediately see my explorer in the background flash and reset, and when I scan again, the registry key has been replicated.

I have been using HijackThis, AdAware, TrojanHunter, Ewido, PCCillin, in safe mode and in normal mode, and I have been using CTCleaner and restarting my Windows after each fix, but to no avail, this one just keeps coming back!

If you have any information that could be of assistance, your post will be much appreciated.

Cheers!
Reply With Quote Quick reply to this message  
Join Date: May 2006
Posts: 599
Reputation: kylethedarkn is an unknown quantity at this point 
Solved Threads: 36
Team Colleague
kylethedarkn's Avatar
kylethedarkn kylethedarkn is offline Offline
A.K.A. The Laughing Man

Re: Virtumonde - Does anyone know how to clean this?

 
0
  #2
Jun 22nd, 2006
To do anything we need your HiJackThis log if you don't have this downloaded you can download it from here.

After you download the zip extract the contents to a permanent folder such as C:\HJT or something similar.

Post the HJT log in your next reply.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 1,542
Reputation: tayspen is on a distinguished road 
Solved Threads: 98
Team Colleague
tayspen's Avatar
tayspen tayspen is offline Offline
<Insert title here>

Re: Virtumonde - Does anyone know how to clean this?

 
0
  #3
Jun 23rd, 2006
Along with that, go ahead and do this.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Firefox
Ewido
Tune up windows
Get detailed system information
My Fixes

Member - Alliance of Security Analysis Professionals - Since 2006
Reply With Quote Quick reply to this message  
Join Date: Mar 2007
Posts: 2
Reputation: EddyJawed is an unknown quantity at this point 
Solved Threads: 0
EddyJawed EddyJawed is offline Offline
Newbie Poster

Re: Virtumonde - Does anyone know how to clean this?

 
0
  #4
Dec 23rd, 2007
Hi,

Another way to fix Vundo is:

1. Get a free spyware scanner to locate the .dll file. Make a note of this file and where its kept (in my case the trojan kept dropping the file in C:\Windows\System32 folder with all kinds of names for the dll files).

2. Get your windows XP startup recovery disk, boot your PC up with it - and using recovery console option 'R' go to the file location in the Dos like console, and delete it.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC