Vundo/Virtumonde trojan removal

G

geir.moi@gmail.com

Here's what is did. I removed Virtumonde successfully.
I have Windows Vista Home Premium

To remove the Virtumonde Trojan, please proceed with the following
steps at your own risk.


STEP 1: Clean Temp folders
Start > All Programs > Accessories > System Tools > Disk Cleanup >
push OK

STEP 2: Run Vundo Fix.
Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
Reboot PC
http://www.atribune.org/ccount/click.php?id=4

STEP 3: Run Virtumundobegone.exe
Run > Run > Continue > Start > Yes > Reboot (may need to perform
manual reboot if PC freezes)
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

STEP 4: Run Vundo Fix again.
Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
Reboot PC
http://www.atribune.org/ccount/click.php?id=4

STEP 5: Hijackthis Log
Save to Desktop > Double click on icon 'hijackthis' > Run > 'Do a
system scan only and save logfile' > save log in notepad and attach to
e-mail.
http://nod32-av.com/utilities/HiJackThis for Troubleshooting/hijackthis.exe

STEP 6: Run ComboFix USE THIS STEP WITH CAUTION!!!!!
Save to Desktop > Double click on icon 'combofix' > Run
http://download.bleepingcomputer.com/sUBs/ComboFix.exe



STEP 7: Run Vundo Fix again.
Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
Reboot PC
http://www.atribune.org/ccount/click.php?id=4

STEP 8: Smitfraudfix
Save to Desktop > Double click on icon 'smitfraudfix' > Run > Option 2
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
 
M

Milo

Thanks for sharing

How much time did you extend removing the vundo in your system?

--
Milo



"geir.moi@gmail.com" wrote:

> Here's what is did. I removed Virtumonde successfully.
> I have Windows Vista Home Premium
>
> To remove the Virtumonde Trojan, please proceed with the following
> steps at your own risk.
>
>
> STEP 1: Clean Temp folders
> Start > All Programs > Accessories > System Tools > Disk Cleanup >
> push OK
>
> STEP 2: Run Vundo Fix.
> Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> Reboot PC
> http://www.atribune.org/ccount/click.php?id=4
>
> STEP 3: Run Virtumundobegone.exe
> Run > Run > Continue > Start > Yes > Reboot (may need to perform
> manual reboot if PC freezes)
> http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
>
> STEP 4: Run Vundo Fix again.
> Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> Reboot PC
> http://www.atribune.org/ccount/click.php?id=4
>
> STEP 5: Hijackthis Log
> Save to Desktop > Double click on icon 'hijackthis' > Run > 'Do a
> system scan only and save logfile' > save log in notepad and attach to
> e-mail.
> http://nod32-av.com/utilities/HiJackThis for Troubleshooting/hijackthis.exe
>
> STEP 6: Run ComboFix USE THIS STEP WITH CAUTION!!!!!
> Save to Desktop > Double click on icon 'combofix' > Run
> http://download.bleepingcomputer.com/sUBs/ComboFix.exe
>
>
>
> STEP 7: Run Vundo Fix again.
> Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> Reboot PC
> http://www.atribune.org/ccount/click.php?id=4
>
> STEP 8: Smitfraudfix
> Save to Desktop > Double click on icon 'smitfraudfix' > Run > Option 2
> http://siri.urz.free.fr/Fix/SmitfraudFix.exe
>
 
J

Jim

Quicker solution. Pop Windows Setup CD. Unplug PC. Wait 30 secs. Boot from
CD and run setup
:)

<geir.moi@gmail.com> wrote in message
news:56355b58-743b-47a5-a6bb-e08eaf63ffc1@e23g2000prf.googlegroups.com...
> Here's what is did. I removed Virtumonde successfully.
> I have Windows Vista Home Premium
>
> To remove the Virtumonde Trojan, please proceed with the following
> steps at your own risk.
>
>
> STEP 1: Clean Temp folders
> Start > All Programs > Accessories > System Tools > Disk Cleanup >
> push OK
>
> STEP 2: Run Vundo Fix.
> Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> Reboot PC
> http://www.atribune.org/ccount/click.php?id=4
>
> STEP 3: Run Virtumundobegone.exe
> Run > Run > Continue > Start > Yes > Reboot (may need to perform
> manual reboot if PC freezes)
> http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
>
> STEP 4: Run Vundo Fix again.
> Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> Reboot PC
> http://www.atribune.org/ccount/click.php?id=4
>
> STEP 5: Hijackthis Log
> Save to Desktop > Double click on icon 'hijackthis' > Run > 'Do a
> system scan only and save logfile' > save log in notepad and attach to
> e-mail.
> http://nod32-av.com/utilities/HiJackThis for Troubleshooting/hijackthis.exe
>
> STEP 6: Run ComboFix USE THIS STEP WITH CAUTION!!!!!
> Save to Desktop > Double click on icon 'combofix' > Run
> http://download.bleepingcomputer.com/sUBs/ComboFix.exe
>
>
>
> STEP 7: Run Vundo Fix again.
> Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> Reboot PC
> http://www.atribune.org/ccount/click.php?id=4
>
> STEP 8: Smitfraudfix
> Save to Desktop > Double click on icon 'smitfraudfix' > Run > Option 2
> http://siri.urz.free.fr/Fix/SmitfraudFix.exe
 
M

Milo

That's the last option, Reformating / or clean installing your system means
you've been defeated by those who made it.

I'de say you give it 30 Minutes to an hour

get a proper support from here or some support group. We are here to help and
give you another avenue than formatting.

--
Milo



"Jim" wrote:

> Quicker solution. Pop Windows Setup CD. Unplug PC. Wait 30 secs. Boot from
> CD and run setup
> :)
>
> <geir.moi@gmail.com> wrote in message
> news:56355b58-743b-47a5-a6bb-e08eaf63ffc1@e23g2000prf.googlegroups.com...
> > Here's what is did. I removed Virtumonde successfully.
> > I have Windows Vista Home Premium
> >
> > To remove the Virtumonde Trojan, please proceed with the following
> > steps at your own risk.
> >
> >
> > STEP 1: Clean Temp folders
> > Start > All Programs > Accessories > System Tools > Disk Cleanup >
> > push OK
> >
> > STEP 2: Run Vundo Fix.
> > Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> > Reboot PC
> > http://www.atribune.org/ccount/click.php?id=4
> >
> > STEP 3: Run Virtumundobegone.exe
> > Run > Run > Continue > Start > Yes > Reboot (may need to perform
> > manual reboot if PC freezes)
> > http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
> >
> > STEP 4: Run Vundo Fix again.
> > Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> > Reboot PC
> > http://www.atribune.org/ccount/click.php?id=4
> >
> > STEP 5: Hijackthis Log
> > Save to Desktop > Double click on icon 'hijackthis' > Run > 'Do a
> > system scan only and save logfile' > save log in notepad and attach to
> > e-mail.
> > http://nod32-av.com/utilities/HiJackThis for Troubleshooting/hijackthis.exe
> >
> > STEP 6: Run ComboFix USE THIS STEP WITH CAUTION!!!!!
> > Save to Desktop > Double click on icon 'combofix' > Run
> > http://download.bleepingcomputer.com/sUBs/ComboFix.exe
> >
> >
> >
> > STEP 7: Run Vundo Fix again.
> > Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
> > Reboot PC
> > http://www.atribune.org/ccount/click.php?id=4
> >
> > STEP 8: Smitfraudfix
> > Save to Desktop > Double click on icon 'smitfraudfix' > Run > Option 2
> > http://siri.urz.free.fr/Fix/SmitfraudFix.exe

>
>
>
 
J

Jim

"Milo" <jfcoel@hotmail.com> wrote in message
news:DADC98CA-B01D-4B1D-A1E3-C1F402E0BB7C@microsoft.com...
> That's the last option, Reformating / or clean installing your system
> means
> you've been defeated by those who made it.


Really? I'd say you're defeated the moment your PC got hit.

> I'de say you give it 30 Minutes to an hour


An hour to clean up infections? I'm impressed. I wasted a week trying to
remove friggin trojan infections. Ended up reformatting/reinstalling OS.
It's quicker, easier and guaranteed it's 100% clean.

> get a proper support from here or some support group. We are here to help
> and
> give you another avenue than formatting.


Unlike some people I don't have days/weeks to spend cleaning craps from PCs.
I admit that sometimes I'm curious too. So I spend a day or two attempting
to get rid of infections. If it keeps popping back... heck... format it.
Somehow I don't feel safe using a PC even after virus infections have been
cleaned unless the PC gets reformatted and the OS is freshly reinstalled.
99.9999% of the time I end up reformatting. Yeah, I'm that kind of person.

> --
> Milo
>
>
>
> "Jim" wrote:
>
>> Quicker solution. Pop Windows Setup CD. Unplug PC. Wait 30 secs. Boot
>> from
>> CD and run setup
>> :)
>>
>> <geir.moi@gmail.com> wrote in message
>> news:56355b58-743b-47a5-a6bb-e08eaf63ffc1@e23g2000prf.googlegroups.com...
>> > Here's what is did. I removed Virtumonde successfully.
>> > I have Windows Vista Home Premium
>> >
>> > To remove the Virtumonde Trojan, please proceed with the following
>> > steps at your own risk.
>> >
>> >
>> > STEP 1: Clean Temp folders
>> > Start > All Programs > Accessories > System Tools > Disk Cleanup >
>> > push OK
>> >
>> > STEP 2: Run Vundo Fix.
>> > Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
>> > Reboot PC
>> > http://www.atribune.org/ccount/click.php?id=4
>> >
>> > STEP 3: Run Virtumundobegone.exe
>> > Run > Run > Continue > Start > Yes > Reboot (may need to perform
>> > manual reboot if PC freezes)
>> > http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
>> >
>> > STEP 4: Run Vundo Fix again.
>> > Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
>> > Reboot PC
>> > http://www.atribune.org/ccount/click.php?id=4
>> >
>> > STEP 5: Hijackthis Log
>> > Save to Desktop > Double click on icon 'hijackthis' > Run > 'Do a
>> > system scan only and save logfile' > save log in notepad and attach to
>> > e-mail.
>> > http://nod32-av.com/utilities/HiJackThis for Troubleshooting/hijackthis.exe
>> >
>> > STEP 6: Run ComboFix USE THIS STEP WITH CAUTION!!!!!
>> > Save to Desktop > Double click on icon 'combofix' > Run
>> > http://download.bleepingcomputer.com/sUBs/ComboFix.exe
>> >
>> >
>> >
>> > STEP 7: Run Vundo Fix again.
>> > Run > Run > Scan for Vundo > Remove Vundo (when scan is completed) >
>> > Reboot PC
>> > http://www.atribune.org/ccount/click.php?id=4
>> >
>> > STEP 8: Smitfraudfix
>> > Save to Desktop > Double click on icon 'smitfraudfix' > Run > Option 2
>> > http://siri.urz.free.fr/Fix/SmitfraudFix.exe

>>
>>
>>
 
Back
Top Bottom