Vundo/Virtumonde Infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by blacksurge, Mar 2, 2008.

  1. blacksurge

    blacksurge Private E-2

    I believe my computer has been infected with Vundo/Virtumonde. A few months ago I had become infected with Vundo, and all I experienced were numerous pop ups on every site, and a slightly slower computer. I tried to get rid of it, and after about 2 days I gave up, and then about a week later it was somehow gone, probably because of McAfee.

    But recently, as of Thursday night I have an even more serious infection. This time Vundo/Virtumonde is basically taking over Internet Explorer. Every time I open it up, it spends 10 minutes loading then fails to load, or I get lucky (1/10th of the time), and my homepage loads, but after that nothing else loads. After doing somewhere between 5 and 8 McAfee manual scans, I went into safe mode and researched on how to remove the program. I downloaded Spyware Doctor, did a scan, found I had something like 64 Virtumonde infections and a few other infections related to Vundo/Virtumonde. I clicked fix problem, but lucky for me you have to buy Spyware Doctor in order to do that. Yay.

    Then I tried VundoFix. It said it found nothing, but my problem isn't solved yet. I tried some Virtumonde cleaner (I forget the name, but it had Virtumonde in it.). After a couple seconds a notepad memo popped up and had some programming language, then said SCAN COMPLETE at the bottom. Problem isn't fixed. I then found this site and went through the READ FIRST post, and updated my java (I had an older version; I think this is why I got Vundo/Virtumonde in the first place), and downloaded and ran CCleaner.

    I am still unable to gain full access to internet explorer when not in safe mode. I do not know what to do, please help!

    On another note: I just bought some girlscout cookies. Yum :]
     
  2. blacksurge

    blacksurge Private E-2

    Oh, and I don't know if this helps or not, but every time I start the computer when not in safe mode, I get an error saying something like:

    Error, cannot start C:/somethingsomethingsomething/hvknnwxd.dll

    Something like that, but I know that that is the correct arrangement for the random letters. Thanks!
     
  3. blacksurge

    blacksurge Private E-2

    Well I just did used SpyBot. It found a couple Virtumondes and a couple "WildTangent"'s. It succesfully deleted all of them. I then did another CCleaner run. Internet Explorer still does not work.

    And I found out exactly what the message says when I turn on my computer:

    RUNDLL error

    Error loading C:\WINDOWS\system32\hvknnwxd.dll

    The specified module could not be found.


    I also noticed that some people are posting "logs" attatched to their posts. Is there any way I can do this and would it help someone solve my problem any quicker?

    Thanks!
     
  4. blacksurge

    blacksurge Private E-2

    Well I downloaded Firefox from safe mode. Luckily, I have access to Firefox from normal mode! :]

    I have also attached a hijack this log at the bottom. Thanks!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You must complete all of the instructions in the READ & RUN and they must be run in the order given. Then when finished, you should be attaching three logs for your Windows version. This was stated in the READ ME. The logs are:
    After you run SUPERAntispyware and then ComboFix, you will have to get a new log from MGtools. I suggest that you download the current version of MGtools since it was just updated.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds