Virtumonde Removal Just Keeps Getting Harder
Over the years this site has written many free guides to help people out in trying to fully remove the virtumonde threat. The issue is all the traces of Virtumonde keep mutating and now every infection we come across has a rootkit virus that needs to be removed before Virtumonde can fully be killed.
Every computer we have encountered over the last 30 days that was infected with Virtumonde now also has several other threats as well. Because of this the free guides will no longer work and if you really want to remove Virtumonde you will have to pay for Virtumonde removal software. IT SUCKS I know but even as an expert at removing viruses I can’t remove this thing with out software. Granted I have bulk licences to items normal people do not and can still remove this for practically free but even most experts can not remove this threat anymore with out extreme help from several programs.
WHAT AM I TO DO ?
The only advice we can offer is to recommend solutions that will work. The first is to donwload Spyware doctor with Antivirus from www.pctools.com . You will need to purchase the software for it to remove virtumonde but it still does a great job of it. If you have further issue you can use their free support or if you are not happy with it then you can get a full refund. This is the software I personally have on my computer and it works great.
For those that just don’t want to deal with this threat at all we still recommend the guys over at www.onlinecomputerrepair.org. It will cost you 89 bucks but there is no waiting around and in about an hour or two you will have your computer up and running like new. They will even give you a free computer tune-up when you pay for an infection removal but you will need to mention this site. They give our clients this freeby because we send them many customers. This is an online computer repair company based in the good old USA. They know what they are doing and if for any reason they can not help you out then you do not have to pay a cent.
For those that are using McAfee, I feel your pain. This software does almost nothing it seems to stop it and it is unable to fully remove the virtumonde threat. Norton does a far better job and Trend Micro works a little better then Norton but we still recommend Spyware Doctor with Antivirus over them because it actually does work to remove the rootkit part.
Please note you may have to go under custom settings and check the “scan for rootkits” box.









May 28th, 2009 at 3:49 am
I just gave up on this thing. I used the onlinecomputerrepair.org service. I was tired of messing around with all the BS. My computer was down for seven days. This thing really is bad stuff and hard to remove. The guys you recommend took about 2 hours but they got the job done. It’s only been a day but it looks like I am virus free. No issues anyways. My tech was named Ryan. I chatted with him and he knows his stuff. I don’t know if you can request someone but I would suggest him as your tech
July 1st, 2009 at 1:15 pm
Just purchased Pctools removal\ Virus protection software. It found the “Virtumonde” on my PC and indicated that it had removed it after the scan, however a repeat scan found it again and again actually not removing it at all! Now what?
July 1st, 2009 at 8:05 pm
Hi Rich,
Did you purchase Spyware Doctor with antivirus? I know some people tyr to go the cheaper route and just purchase the antivirus client or the spyware client only and not both as suggested. You need both of them to fully remove virtumonde.
If it did not work for you we suggest ensuring that the client is up to date and boot into safe mode. Run a full scan in safe mode. Also ensure that scan for hidden root kits is checked under settings. If that does not work for you then you still have a few options.
Go out and download Malwarebytes and Spybot Search and Destroy. Both of these clients are free to use. Update them both then re-boot into safe mode and run full scans on both clients as well. In almost every case this should remove the virtumonde threat. Keep in mind Spyware Doctor with antivirus also does offer free tech support. They will help you remove this threat as well. We do suggest selecting the option under setting to send PCtools your scan results. This will help everybody out who ends up getting your strain of Virtumonde in the future.
My guess is you have a root kit that is re-installing Virtumonde on re-boot each and every time. We need to find and kill this root kit to resolve your issue.
Please let us know how it worked out for you. If you have more questions we will be here to help.
July 7th, 2009 at 12:47 am
that onlinecomputerrepair.org site was my savior. Had two computers infected because of my teenagers. the computers had nothing but constant pop-ups and they were so slow. I do own Mcaffee but it could not remove any of it. For the price I think this company is the way to go.
July 10th, 2009 at 8:31 pm
I have the Spyware Doctor and it hasn’t removed the Virtumonde, although it identifies it with every scan. I am going to doublecheck and see if I have the antivirus as well as the anti-spyware. My pc will no longer boot in safe mode, apparently there is something in the trojan that disables safe mode for Win XP. Also, it blocks me from changing any settings in MSconfig, although I am logged as administrator, I get an error that says I must relog as an administrator to make changes to MSconfig. Super frustrating.
July 10th, 2009 at 11:00 pm
The PCtools software is a step in the right direction. Go ahead and download malware bytes adn spybot Search and destroy and run a full scan. As stated above virtumonde just keeps getting harder and more frustrating to remove as the years go on.
Run the scans and see if it helps. If your are am advanced computer user I would recommend Combofix.exe. If not then DON’T use it as you will most likely destroy your OS.
PCTOOLS does offer free support as well so shooting them an e-mail is a good idea. At least send them the infection info so they can work on a solution for everyone else.
July 10th, 2009 at 11:06 pm
Spyware doctor with antivirus worked for me. I updated the client and booted into safe mode and ran a scan.
Before this product I was using Norton 360. I also did a scan first with spybot search and destroy. It did catch a whole lot of things but I was still infected so I ended up purchasing a copy of what you guys recommended. It worked 100%. Man this virus really sucks. I downloaded and installed a fake video codec, that is how I got infected. Yes I know I should not off but I figured I was safe because I did have an updated version of Norton 360.
Anyways your solution worked for me and I thought others should know.
You guys need to have another section of the blog were people can post their highjackthis log settings. I downloaded the program but had no idea how to use the thing. It looked really intimidating to me and I did not want to make matters worse