Advanced Trojan Removal Guide
This is were we would like to hear feedback for our Advanced Trojan Removal Guide. Please let us know how this guide worked for you and what step you found hard to follow. If you have any suggestions then add them here.
February 28th, 2008 at 12:30 am
I purchased a copy of Spyware Doctor, but it has not been able to eliminate the Vundo or Virtumonde virus from my PC. It will find it and say that it has removed it, but within a short while it returns again.
Has anyone else had this problem?
Thank you,
Brad
February 28th, 2008 at 2:33 am
I take it you did ensure spyware Doctor is up to date?
Lets start a thread in our forum for this and I’ll help you get through this. The forum is http://www.virtumonde.net/forum/
Register an account and start a new thread.
Also did you run the scan in Safe mode? If not then that is a must. As well please go ahead and download Vundo fix. You can find it under Vundo removal tools on the top of this page. Down load vundo fix and reboot into safe mode. Then run the vundo removal tool. Then run Spyware Doctor. Please also download Highjack this and save a log file. Then post that file in our forum and I’ll tell you what you need to remove from there.
February 28th, 2008 at 3:45 pm
I had that issue at first as well. Kind of funny because both my computers were infected with this. I installed Spyware doctor on both. Ran the scans. One was fixed and one was not. I then went back to this site and read the easy removal guide. I followed the guide and my other system was cleaned. I should of just ran the scan in safe mode first and saved myself the trouble. I did use the vundofix file on this site as well.
No more vundo. I wish we could sue the people who made it.
May 6th, 2008 at 4:34 am
I bought spyware doctor because i didn’t have the time to try and remove virumonde on my own, it did not detect it at all, it did remove other things but not virtumonde. I tried putting the computer in safe mode, ran Vundo removal tool and it found nothing, than I ran spyware doctor in safe mode and after four hours it found nothing as well, but then after that i ran spybot search and destroy, and it of course found virtumonde i removed it through spybot but it keeps coming back. Help!!!
May 6th, 2008 at 5:36 am
I have to ask. Did you update the Spyware Doctor Software?
Download and install Highjack this. When you run the program save a log file and e-mail and post it in our forum at http://www.virtumonde.net/forum/ You will have to create an account but that will only take a second.
Spyware Doctor does work to remove this threat but every once in a while it has some trouble. I am guessing there is one file that it did not fully remove. I would personally make sure SD is upto date and run it again in safe mode as well as Spybot. Then post back what file it was unable to remove as it will find all the traces on your system and let you know what it could not remove.
May 6th, 2008 at 5:57 am
Just in case you did not know Spyware Doctor also offers free online support. You can always ask them for a little help at http://www.pctools.com/contact/support/
Of course you would of had to purchase the software to get the support
May 7th, 2008 at 5:47 am
Thanks for the guide. Worked great for me. I bought Spyware Doctor and then did the system restore as suggested. Then installed the program and did a full scan. It did remove all of the spyware on my system. It’s been a few days now and no pop-ups.
May 8th, 2008 at 5:01 am
Spyware Doctor worked for me. The free spybot got rid of most of it but I had to to Spyware Doctor to remove the rest. Also I did have to run the program twice. The first time I think it killed all but one trace and the second scan fully removed this damn virtumonde thing.
May 31st, 2008 at 10:06 pm
First of I started by following the steps in easy removal, used all the programs but Vundofix found nothing, Spybot found several traces and then Spyware doctor (which I bought) also found several traces. I let SD clean. Rebooted and let SD run again and it found no traces, but Malwarebytes found more traces. I´m still trying to remove it now following the harder steps
But the thing I wanted to comment on mostly is that to begin with I had Trend Micro Pc-cilin a full bought version and yet I still got Virtumonde! It was the first program to tell me I might have Virtumonde yet with a full scan it found no traces. So a full virus protection program fully updated is not always enough.
June 1st, 2008 at 1:53 am
Hi Jana,
For Trend Micro was it the Internet Security suit or just the anti-virus? Also what version is it? 2008, 2007, 2006? This info will really help others. I have only had one past customer get infected with Virtumonde from having Trend Micro IS 2007 version but they did not have it updated.
Also do you know how you got infected and from what site?
June 1st, 2008 at 3:18 am
I have Trend Micro PC- cillin Internet Security 2007, with automatic updates turned on and am very fanatical about keeping it updated.
But I´m sorry to say that I´m not sure how or from what site I got infected, I suspect mininova but am not 100% sure as I said. Just noticed that my computer started acting weirdly the other day.
June 1st, 2008 at 5:18 am
Thanks for the update. Did you try doing a system restore yet? That will uninstall any software from the data you choose but often times helps in the Virtumonde removal process.
June 1st, 2008 at 2:35 pm
Yes, it was among the first things I did per your instructions
only I had only 2 date’s to choose from the same day and the day before, apparently I had just removed all the others earlier dates
. I have now done all the cleaning, am just about to re-boot to normal mode to see if anything is abnormal.
July 23rd, 2008 at 5:23 am
I love the challenge of fixing my friends’ computers, however the “rats nest” that I got involved with is a bit much. The two “V’s” (virtumonde and vundu) are brilliantly-devised programs. Extremely resilient and well-engineered.
Not having any idea of what I was getting into, I realized that the infestation was huge. Blue screens, everything, and sluggishly slow, WinXP.
Anyhow, it’s been a long story; not over yet. But was I really intended to say is that I REALLY appreciate how you have setup up this webpage; the choices you give, the good advice you provide.
Excellent!