Question:
I have a really bad infection of a black door trogan which keeps throwing pop-ups as soon as I try to download
anne k
2007-11-08 18:48:35 UTC
Im running Nod32 as well as Spybot search & destroy which seem to have been ineffective, Nod32 identified it originally as "Win32/Adware.Virtumonde application" but seems to have either opened the door to others too numerous to mention-warning windows from Nod32 are popping up as fast as I can click them off now. I download a so-called free program that the net recommended for virtumonde, ran a scan that took hours then ticked a box to start remove only to be told I have to purchase the software? Has anyone had any success with this spyhunter or can recommend any other help short of taking it down to the computer shop to probably have the hard drive wiped ?
Nine answers:
Charley Horse
2007-11-08 19:00:14 UTC
Super Antispyware is the best out now. You can use it for free and it will remove whatever it finds.

If one of the programs you have now has identified one malware as a "backdoor" trojan, you have to consider that your computer has been completely compromised. Any info concerning banking, credit cards, paypal, passwords, etc. have been accessed by the malware and sent on.

You should consider reformatting and reinstalling.



Install Super Antispyware free. Run it in safe mode. Allow it to quarantine whatever it finds.

http://www.superantispyware.com/

For expert help in removing the malware I recommend Bleeping Computer. Their service is free. No Gimmicks.

http://www.bleepingcomputer.com/
anonymous
2007-11-08 19:09:43 UTC
First off, it's called a back door trojan and it can be a ***** to get rid of, however, a disk erase is the last resort. Try Microsoft's knowledge base first. Do a search for the name of the trojan and see if they have a fix for it, like a remover. Next, go to a reliable machine and Google the name of the virus and see what info you can glean from them. Third, on a good machine, download Xoftspy and Spybot Search & Destroy and install them on your infected machine and run a scan. Last, download Killdisk Suite on a CD, put it in your drive and nuke your disk.
Mike M
2007-11-08 19:07:53 UTC
VundoFix.exe is a removal tool developed to remove Virtumonde infections. To use the tool follow the instructions below.



*to begin download, click link below- save to desktop*

http://www.atribune.org/ccount/click.php?id=4



Double-click VundoFix.exe to run it.

When VundoFix re-opens, click the Scan for Vundo button.

Once it's done scanning, click the Remove Vundo button.

You will receive a prompt asking if you want to remove the files, click YES

Once you click yes, your desktop will go blank as it starts removing Vundo.

When completed, it will prompt that it will reboot your computer, click OK.



Note: It is possible that VundoFix encountered a file it could not remove.

In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the

Scan for Vundo button." when VundoFix appears at reboot.



Repair file credit to:

http://www.atribune.org



Posted here, these instructions will make it possible to avoid any new browser windows.



Follow this up with a scan using this free anti-spyware:

*be sure to update before scanning-

superantispyware

http://www.superantispyware.com



Hope this helps...

---



Use protection,

your computer will thank you.
reinbold
2016-12-08 21:18:35 UTC
AVG is absolute crap ware. there's no longer lots worse apart from style micro. AVG won't take care of your computing device from Trojans. They walk suited previous it like it particularly is no longer even there. AVG has no root kit protection. AVG is stressful to replace. AVG has the backside record in detection. AVG's actual time protection is a shaggy dog tale. it is so undesirable i say it particularly does not have any. might as nicely no longer. It we could each little thing through. i could shop going approximately how sorry AVG is. yet what I even have indexed above could be sufficient to assist you already know what a sorry piece of junk ware AVG is. do away with it and get a paid version of Avira or Kaspersky. change to firefox internet browser and set it to no longer different than third social gathering cookies. which will circulate an prolonged way in helping you which includes your cookie difficulty. i haven't had any form of monitoring cookie in 2 years. in case you have extreme velocity internet you do no longer might desire to maintain cookies. you are able to set hearth fox to offload all cookies and temp records once you shut hearth fox. in the adventure that your on dial up then you fairly might desire to keep cookies. Dial up is lots slower. you elect the cookies and temp records to help velocity up internet site loading. yet no longer on extreme velocity.
engineer_retired
2007-11-08 18:58:21 UTC
Have you tried this: http://www.virtumonde-removal.com.removal-instructions.com/removeVirtuMonde.html it's FREE



Virtumonde in itself is one bear to get rid of this download should get you taken care of.



Edited: I downloaded the software and it turns out that it cost. It provides a free scan is all.
bitchy_scorpio
2007-11-08 19:00:56 UTC
start the computer up in SAFE MODE (f8 repetitively struck when you turn it on)choose safe mode with networking. Once your booted up run housecall virus scan. http://housecall.trendmicro.com/

Its free.

By running this program in safe mode you prevent most of the programs from starting up so they can be removed.

good luck.
?
2007-11-08 18:58:33 UTC
Have you tried using housecall.com for a free scan?

I use PC Cillian anti virus and it works very well.
?
2007-11-08 19:02:44 UTC
pls try the below links and see if they are of any help
anonymous
2007-11-08 19:02:01 UTC
Try the following. All are free. There is a rootkit variant (see below) that is not removed by many standard cleaners.



Vundo Fix

Windows all

VirtumundoBegone (if VundoFix does not work)

VirtumundoBeGone has not been tested on Vista platforms

http://www.bleepingcomputer.com/forums/topic18610.html

http://www.atribune.org/



Vundo Rootkit Removal

http://wiki.castlecops.com/Vundo_Rootkit_Detection_and_Removal_Procedure

========================

General Cleaning Procedure



OS Reinstallation vs. Virus Removal

http://safecomputing.umn.edu/guides/rebuild_repair.html



In addition to a firewall you must have full time (active) virus protection and full time (active) spyware protection.



All the following programs are free.

---------------------------------------------

Full Time (Active) Virus Protection

Run a full scan.

If you do not have active virus protection, install only one. All are excellent.



AVG Antivirus 7.5 Free Edition

Windows 98/Me/NT/2000/XP/Vista

http://free.grisoft.com/freeweb.php/doc/avg-anti-virus-free/lng/us/tpl/v5

http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10669237.html?tag=lst-0-1

or

Free antivirus - avast! 4 Home Edition

Windows 95/98/Me/NT/2000/XP/Vista

http://www.avast.com/eng/avast_4_home.html

or

Avira AntiVir PersonalEdition Classic

Windows 95/98/Me/NT/2000/XP/Vista

http://www.free-av.com/

http://www.download.com/3120-20_4-0.html?tg=dl-20&qt=Avira&tag=srch

---------------------------------------------------------

Full Time (Active) spyware protection



Run a full scan. If you do not have active spyware protection, install:



Windows Defender (Included with Vista) XP SP2, Vista

http://www.microsoft.com/athome/security/spyware/software/default.mspx

---------------------------------------------------------

Install the following four programs and run weekly or at least monthly. You need all four. They are not a substitute for full time spyware and virus protection. They will greatly increase your protection. Spybot Search & Destroy and SpywareBlaster immunize your computer against over 47,000 threats Install and run now.



Ad-Aware SE Personal (update + full scan)

Windows 2000 (Pro and Server), Windows Server 2003, Windows XP (Home and Pro), Windows Vista (32-bit)

http://www.lavasoftusa.com/products/ad-aware_se_personal.php



Spybot Search & Destroy (update + immunize + scan)

Windows 98/Me/NT/2000/XP/Vista

Do not enable Tea Timer and SDHelper

After installation: update + scan + immunize

http://www.safer-networking.org/en/mirrors/index.html



SpywareBlaster 3.51: Update then open and click “enable all protection”.

Windows All

http://www.javacoolsoftware.com/spywareblaster.html

http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/SpywareBlaster.shtml



SUPERAntiSpyware free version: (update + scan)

Windows 98/Me/2000/XP/2003 Server/Vista

http://www.superantispyware.com/

------------------------------

Install:



CCleaner:

Windows 95/98/Me/NT/2000/XP/2003 Server/Vista

http://www.ccleaner.com/

Do not install optional toolbar.

Removes tracking cookies, unneeded files, history

In options.

Set to run when computer starts.

Place cookies you want to keep in save list

-------------------------------------------------

Install either one not both:

Helps protect you from all kinds of Web-based security threats including spyware, adware, spam, viruses, browser exploits, and online scams. I use McAfee Site Advisor.



McAfee Site Advisor: Internet Explorer and Firefox

IE: Windows 98/ME/2000/XP/Vista (XP recommended)

Firefox: Windows 98/ME/2000/XP/Vista, Linux and Mac OS X

http://us.mcafee.com/root/product.asp?productid=sa



TrendProtect™

XP SP2, XP ProX64 SP1, Win 2000 SP4, Vista

http://www.trendsecure.com/portal/en-US/free_security_tools/trendprotect.php

--------------------------------

Note if a scan detects a problem but is unable to remove, start the computer in safe mode with the internet line disconnected and run a full scan.



In severe cases your system restore files will also be infected. In these cases you will need to turn off system restore to prevent malware hiding in the system restore files and reinfecting the computer during removal or during a future system restore. Turning off system restore deletes the system restore files.



Right click on "my computer"> Properties > System Restore Tab > Check box turn of system restore



After the malware is removed turn on system restore.

------------------------------

Run this time and monthly:



Microsoft Update:

Run in "Custom Mode". Install everything, reboot and repeat until nothing is left to install.

http://www.update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us



Microsoft OneCare Live Safety Scan, run “full service scan”

Updates windows, virus and spyware scan, disk cleanup, disk fragmentation (if needed), backs up registry and then cleans registry, and checks for open firewall ports

Microsoft Windows XP, Windows 2003, or Windows 2000

http://onecare.live.com/site/en-us/default.htm

Safety Scan for Windows Vista

http://onecare.live.com/site/en-US/center/whatsnew.htm



Malicious Software Removal Tool (run “full scan”)

Vista, XP, Win 2000, and Server 2003

http://www.microsoft.com/security/malwareremove/default.mspx

------------------------------

Rootkit Removers

Pick any 2 install and run one each month.



AVG Anti-Rootkit

MS Windows 2000 (32-Bit) or MS Windows XP (32-Bit)

http://free.grisoft.com/doc/download-free-anti-rootkit/us/frt/0



F-Secure BlackLight

Windows 2000, XP (32 and 64-bit), 2003 Server (32 and 64-bit) and Vista (32-bit only)

http://www.f-secure.com/blacklight/



Panda Anti-Rootkit

Windows 2000/XP

http://www.pandasecurity.com/homeusers/downloads/register?Tipo=1&CodigoProducto=39&Idioma=2&TipoUsuario=1&sec=down&Country=US-en&TipoLead=2&Ref=WWEN-ROOTK-DES&track=36355

http://www.download.com/Panda-Anti-Rootkit/3000-2239_4-10717197.html?tag=lst-0-1



Sophos Anti-Rootkit

Win NT 4.0 (SP 6a with IE 4.0), Win 2000 , XP, Server 2003

http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

------------------------------

Run this time only:



CWShredder: run

XP/2000/Me/98 SE/ NOT FOR VISTA

http://www.trendmicro.com/cwshredder/



Shoot The Messenger

NT/2000/XP / NOT FOR VISTA

http://www.grc.com/stm/shootthemessenger.htm



VX2 tool for Ad-Aware and run tool (Install and run)

Windows 2000 (Pro and Server), Windows Server 2003, Windows XP (Home and Pro), Windows Vista (32-bit)

http://www.lavasoftusa.com/support/securitycenter/vx2_cleaner.php

-----------------------------------------

Special Removal Tools

Run only if indicated



Roguefix.bat Windows XP only

http://www.internetinspiration.co.uk/roguefix.htm



SmitFraudFix

SmitFraudFix only works with Windows XP or 2000

http://www.geekstogo.com/forum/How_to_use_SmitFraudFix-t109268.html



Vundo Fix

Windows all

VirtumundoBegone (if VundoFix does not work)

VirtumundoBeGone has not been tested on Vista platforms

http://www.bleepingcomputer.com/forums/topic18610.html

http://www.atribune.org/



Vundo Rootkit Removal

http://wiki.castlecops.com/Vundo_Rootkit_Detection_and_Removal_Procedure

------------------------------

Online Free Scanners:

Run Trend Micro, Kaspersky, and Panda Scan now.

Run a different one each month.



BitDefender Online Scanner

http://www.bitdefender.com/scan8/ie.html

CA eTrust® PestScan

http://pestpatrol.com/pestscan/index.htm

ESET Nod32 Online Scanner

Win 98/ME/NT 4.0/2000/XP/Vista

http://www.eset.com/onlinescan/index.php

ewido anti-spyware

http://www.ewido.net/en/onlinescan/

eTrust Antivirus Web Scanner

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

F-Secure Online Virus Scanner

http://support.f-secure.com/enu/home/ols.shtml

Kaspersky - Free Online Virus Scan

http://www.kaspersky.com/virusscanner

McAfee - Free Scan

http://us.mcafee.com/root/mfs

Panda Software - ActiveScan

http://www.pandasecurity.com/homeusers/solutions/activescan/?

Symantec (norton) - Security Check

http://security.symantec.com/sscv6/default.asp

Trend Micro™ HouseCall

http://www.trendmicro.com/hc_intro/default.asp


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...