The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    can't get rid of Trojan Vundo.H help please!!!

    Discussion in 'Security and Anti-Virus Software' started by ferrarista, Jun 10, 2009.

  1. ferrarista

    ferrarista Notebook Consultant

    Reputations:
    6
    Messages:
    159
    Likes Received:
    0
    Trophy Points:
    30
    so Malwarebytes anti-malware detects these 3 files trojan vundo , it says it deleted them , but when I rescan they always pop up again.

    I tried alot of things even deleting manually in the registry , but always pop up.

    someone please tell me what to do. Its my cousin's laptop. I wanna try to fix without reinstalling the windows.

    thanks
     
  2. DarkSilver

    DarkSilver MSI Afterburner

    Reputations:
    378
    Messages:
    2,249
    Likes Received:
    0
    Trophy Points:
    55
  3. ferrarista

    ferrarista Notebook Consultant

    Reputations:
    6
    Messages:
    159
    Likes Received:
    0
    Trophy Points:
    30
    Yes I already have avira installed.

    I already did superantispyware. It doesn't remove.

    I had to go in safe mode and disable all the startup programs because the security system antivirus virus would not allow me to do anything.
     
  4. -L1GHTGAM3R-

    -L1GHTGAM3R- Notebook Deity

    Reputations:
    434
    Messages:
    1,034
    Likes Received:
    0
    Trophy Points:
    55
    let me see have u tried spybot search and destroy.........u should uninstall avira and install avast and do a system boot scan.....
     
  5. Aeris

    Aeris Otherworldly

    Reputations:
    474
    Messages:
    805
    Likes Received:
    20
    Trophy Points:
    31
    VirtuMonde is an exotic Trojan Horse, it is mutating constantly, and there is no 100% rate of disinfection, I recommend you:

    -- Disable System Restore. (Right-Click on My PC / Computer, System Protection)

    -- Download VundoFix.

    -- Download, Install and Update Malwarebytes Antimalware, Avast! or Avira Antivir, and SpyBot Search & Destroy.

    -- Download HiJack This! (Post the logs in this thread.)

    While in Safe Mode,

    -- Run VundoFix, Malwarebytes' Antimalware, Avast! or Avira Antivir, SpyBot Search & Destroy and HiJack This!.

    -- Keep them up to date and scan periodically, the VirtuMonde Trojan Horse cannot be removed fully unless you do so.

    It will take a while to "purge out" from your system.

    Keep their "Heuristics" Level on Maximum if you can.

    If the Vundo Trojan Horse cannot be annihilated by those programs, then a re-format will be needed to get rid of it, but remember, it is a last resource solution.
     
  6. ferrarista

    ferrarista Notebook Consultant

    Reputations:
    6
    Messages:
    159
    Likes Received:
    0
    Trophy Points:
    30
  7. Aeris

    Aeris Otherworldly

    Reputations:
    474
    Messages:
    805
    Likes Received:
    20
    Trophy Points:
    31
    I am glad to hear that you solved your problem, VirtuMonde is one of the hardest Trojan Horses to remove. (It cost me a reformat a year ago.)

    By the way, do not forget to scan continuously from now on, as VirtuMonde is never really purged out from your system, some traces will be left laying around, and those could cause another infection, so keep your antivirus and antispyware nearby, turn their active protection on, and keep an eye out.

    That site that you posted, Recovery Console, I had never heard of it, I guess that I will investigate more about it and try to integrate it into future fixes for malware that I may come up with.

    If you can, get an Antivirus / Antispyware that has Web Protection, as the so-called "Trojan Downloaders" carry VirtuMonde (Vundo) a 50% of the time, and every time that you download an infected file, you will be alerted and prompted to terminate the connection.

    Have a nice day.
     
  8. reality818

    reality818 Notebook Guru

    Reputations:
    60
    Messages:
    61
    Likes Received:
    0
    Trophy Points:
    15
    I find "autoruns" to be very useful, this helps you remove viruses, if you know what your looking for. It's kinda like msconfig.
     
  9. TeeJay 44

    TeeJay 44 Notebook Deity

    Reputations:
    1,020
    Messages:
    1,048
    Likes Received:
    0
    Trophy Points:
    0
    Hence the value of Avast. I only realised that once I was in the same boat.
    No matter of scanning etc. will remove the problem unless you do a system boot scan.

    BTW, not my own comp...but seriously infected comps of people I work with. Flash stick stuff. Avira did not clean up properly. Avast did.

    It found rootkits etc. etc.

    Hence my vote for rock solid Avast.
     
  10. ferrarista

    ferrarista Notebook Consultant

    Reputations:
    6
    Messages:
    159
    Likes Received:
    0
    Trophy Points:
    30
    thanks for the suggestions guys. As of now the computer is doing well. will try Avast antivirus .
     
  11. -L1GHTGAM3R-

    -L1GHTGAM3R- Notebook Deity

    Reputations:
    434
    Messages:
    1,034
    Likes Received:
    0
    Trophy Points:
    55
    yeah installing avast will be a smart move....hope you enjoy it..... :)