Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Spyware / AdWare » Help to Remove Virtumonde please.

Spyware / AdWare - Help to Remove Virtumonde please. posted in the Security & Safety forums; I have tried a few things and it comes back. It's a lot better now it had hijacked my browser w/ a link to antivirus. My spybot has it on ...

JOIN US NOW to remove these Ads

PC Help Forum, the number one FREE computer support website in the search engines
Post New Thread  Reply
  #1  
Old 11-15-2007
0nobody0's Avatar
Bronze Member
 
Join Date: Nov 2007
Posts: 10
PC Experience: Built my own core 2 duo
0nobody0 - See this Members User comments on their Profile page
Default Help to Remove Virtumonde please.

I have tried a few things and it comes back. It's a lot better now it had hijacked my browser w/ a link to antivirus. My spybot has it on immune now.
My spybot keeps finding the aldd, rdfa and aoprndtws in registry.

I delete the 3 reg's and they come back. It was 13 at first. Even tried safe mode.

Ran ccleaner. found a few
Ran Dr. web found a few

Am attaching a hijack this log. I put my faith in your ability.

am also sending smitfraud log.
Attached Files
File Type: txt Hijack this log.txt (6.1 KB, 2 views)
File Type: txt rapport.txt (3.4 KB, 0 views)



Last edited by 0nobody0; 11-15-2007 at 02:23 AM.
  #2  
Old 11-15-2007
0nobody0's Avatar
Bronze Member
 
Join Date: Nov 2007
Posts: 10
PC Experience: Built my own core 2 duo
0nobody0 - See this Members User comments on their Profile page
Default Re: Help to Remove Virtumonde please.

OK followed instructions of yours to the T. after doing so made a new hijack log.
AVG only found the 2 cookies.

SAS found something listed as unknown at .HKEY_USERS\S-1-5-21-1202660629-1547161642-839522115-1003
and 2 adware cookies

Aldd and rdfa and other still there.

Forgot to mention the attack was a toolbar for ie7 and my cookies block in control panel kept reverting to add all cookies and they could read already put here. Now high block status stays in place. After reboot.
Attached Files
File Type: txt Hijack this log.txt (6.9 KB, 0 views)



Last edited by 0nobody0; 11-15-2007 at 06:22 AM.
  #3  
Old 11-15-2007
0nobody0's Avatar
Bronze Member
 
Join Date: Nov 2007
Posts: 10
PC Experience: Built my own core 2 duo
0nobody0 - See this Members User comments on their Profile page
Default Re: Help to Remove Virtumonde please.

OK been doing my own work so far. I'm down to just the aldd coming back.
Looks like i'm on the right track. Am posting new log.

Wait...maybe. Does anyone know if virtumonde is part of a torrent programs?
That hku seems to be part of that area. That may be the unknown entry.

One more note punkbuster may be the thing. This is a anti cheat program for games online.
I'm down to a few possibles now. I have gone through what i can figure. the others are assoc. w/ language and so on w/ legit programs like office 11.

Any help.............Thanks.
Attached Files
File Type: txt hijck log.txt (6.6 KB, 0 views)



Last edited by 0nobody0; 11-15-2007 at 07:05 PM.
  #4  
Old 11-16-2007
0nobody0's Avatar
Bronze Member
 
Join Date: Nov 2007
Posts: 10
PC Experience: Built my own core 2 duo
0nobody0 - See this Members User comments on their Profile page
Default Re: Help to Remove Virtumonde please.

A small oddity. I ran killbox trying to get rid of this last item...it can't see it as if it's not there.

HKEY_USERS\S-1-5-21-1202660629-1547161642-839522115-1003\Software\Microsoft\aldd

Is this due to spybot having it on immune?

BTW computer working great now even though nobody here helped yet..... i thought i should post my attempts to maybe help others.

SPYBOT is an awesome program it blocks all reg changes unless i approve them. It'll my my spyware forever.
Too bad i didnt use it b4 this.



Last edited by 0nobody0; 11-16-2007 at 12:45 AM.
  #5  
Old 11-16-2007
0nobody0's Avatar
Bronze Member
 
Join Date: Nov 2007
Posts: 10
PC Experience: Built my own core 2 duo
0nobody0 - See this Members User comments on their Profile page
Default Re: Help to Remove Virtumonde please.

OK...am all clean now. I used a program call..... DR. Web !
I shut down all programs my avast,spybot, everything ...make sure you check toolbar below right for autoloading programs and close them and off of internet. Scan with Dr. Web. It found the last item and killed it....WoooHooooooo.

I reset my system restore and updated spybot and update immunize.



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
How Do I Remove Kazaa and its installed programs? the_machine General Application Tutorials 9 11-22-2006 07:01 PM
[Resolved] How to remove windows xp update KB917422 Cowburn199 Windows XP/2000 8 10-15-2006 02:39 AM
[Fixed] Adware please help! xmetalxheartsx_ [Fixed] Hijackthis! Logs 15 09-27-2006 02:55 AM
Missing devices in "Safely Remove Hardware" Major Pots Windows XP/2000 5 09-03-2006 06:02 AM
[Answered] how do i remove "my old disk structure? Ali2005 Hard Drives 1 08-21-2005 07:41 PM


All times are GMT +1. The time now is 02:38 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top