The pop-ups that VirtuMonde causes can vary widely. Sometimes gives a "Run a DLL as an APP" error when some of the randomly named DLLs have been deleted. Deletes the network connection under My Network Places.

On reboot into normal, I tried to update Combofix for a scan, and after it had finished downloading its update files, it closed and the program tried to restart.

Boot into Safe Mode: * Restart your computer and start pressing the F8 key on your keyboard. * Select the Safe Mode option when the Windows Advanced Options menu appears, and Makes me a little nervous. Do not worry, because all will be restored later. • Wait for the scan to be completed. • If it requires a reboot, please do it.

I had "stuff" come up that I had to attend to. What to Watch Out for and What to Do to Avoid VirtuMonde An important thing to remember about VirtuMonde is that it does not advertise its presence. The page continues to load even with the error msg, but is quite slow. The application should ask for permission to restart your computer - click Yes.

SAS showed 15 adware trackers, MBAM showed nothing. This can occur if the auto-update feature is disabled and the root certificate auto-update feature in Add/Remove Programs is not removed. Apr 18, 2009 #19 kimsland Ex-TechSpotter Posts: 14,524 Platform: Windows XP SP2Click to expand... I then ran a full system scan with Avira and nothing was found.

Method of Infection There are many ways your computer could get infected with Virtumonde. Many of the popups advertise fraudulent programs such as AntiSpywareMaster, WinFixer, and MS Antivirus|AntiVirus 2009. Virtumonde.dll consists of two main components, Browser Helper Objects and Class ID.

Your antivirus and anti-adware programs can show warning - better is to turn off that program before next steps. Click Add/Remove Windows Components. (on the left side of the screen) 3. VirtuMonde is still one of the most common Trojans causing infections, and over the years, it has become more and more dangerous and harder to remove.

VirtuMonde is known to search for and delete Spybot Search & Destroy and Malwarebytes Antimalware, and it can disable certain functions in Norton Antivirus and then use Norton itself to download

Vundo can impede download progress.

Windows Automatic Updates (and other web-based services) may also be disabled and it is not possible to turn them back on. You are running both Symantec and McAfee antivirus programs.

In any case, I've attached the MBAM scan after HJT fix, Combo-Fix file + Combo fix quarantine file and the rescan with HJT. Reboot into Normal Mode> NOTE: ignore and close the nag message after checking 'don't show again.' Stay in Selective Startup.

Installs adware that sometimes is pornographic. Right click on Start> Explore> Programs> Nortons Ghost> Disable for now Boot into Normal Mode: NOTE: You will get a nag message that you can ignore and close after cheking 'don't Unfortunately, at least one or two of the infected .dll's will still be running and generating more infected dll files and registry keys. O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console

Vundo may cause webpages to fail to load after sessions of browsing and present a blank page in the browser instead of the webpage. The page continues to load even with the error msg, but is quite slow. After detection of Virtumonde, the next advised step is to remove Virtumonde with the purchase of the SpyHunter Spyware removal tool. This website does not advocate the actions or behavior of Virtumonde and its creators.

Run ComboFix. You can try deleting or renaming the infected dll files, but you won't be able to delete the ones that are actively running. CPU usage isn't stuck in 50-100%, all programs are able to update just fine (I used the chance to update SAS, MBAM, Avira). It will go thorough the list and remove all of the tools it finds and then delete itself (requiring a reboot).

Please disable all security programs, such as antiviruses, antispywares, and firewalls. Rather than pushing fake antivirus products, the new "ad" popups for the drive by download attacks are copies of ads by major corporations, faked so that simply closing them allows the Can you get into Safe Mode? 3.

Avira found 5 files which were subsequently removed. After downloading the tool, disconnect from the internet and disable all antivirus protection. VirtuMonde is known to promote WinAntiSpyware, SysProtect, and WinFixer in this way, along with countless other rogue anti-malware applications (which are ultimately scams). Write down any suspicious files - those with the date of the infection that are 8 random characters.

Otherwise, the system is now stable. Panda Software, Symantec's Norton Anti-virus and AVG Free (free security suite) are some of the many options. Not really sure what's going on with the system, but it's returned to the state it was in prior to