Virtumonde Removal Guide

Threat Level:
9/10
Rate this Article:
Comments (0)
Article Views: 439
Category: Adware

Virtumonde is a Trojan which forms part of the well publicized and despised Vundo family of Trojans. It does not seek the user’s permission before forcefully entering and rooting itself in the system, and will proceed to cause havoc on the user’s system. It carries the infection of rogue security applications, some of which have been identified as WinFixer, SysProtect and WinAntiSpwyare.

The Trojan will proceed to cause severely poor system performance and cause erratic system behavior. It will generate fake security pop up messages which will inform the user that he needs to purchase the proffered rogue antispyware application. It will also make the system more vulnerable to other malware infections, as Virtumonde opens up security holes in the infected system.

Through many evolutions over time, Virtumonde has evolved so much that it has become much more difficult to get rid of Virtumonde. Methods that Virtumonde uses to avoid detection and removal range from using random names, burying itself in random autorun locations, random CLSIDs and the use of rootkits in order to hide itself on the system. This makes it increasingly more difficult for users to manually remove Virtumonde.

Do not allow this harmful and seditious Trojan to cause permanent damage to your system. Use a genuine and powerful security tool to destroy Virtumonde and protect your PC against similar attacks in future.

Tested Virtumonde removal solution for 64/32-bit Windows 7/Vista/XP/2000
*The Spyhunter scanner download on this site is intended to be used as a detection tool. If you want to use its a removal function, you will need to purchase the full version of SpyHunter.

Virtumonde technical info for manual removal:

Files Modified/Created on the system:

# File Name File Size (Bytes) File Hash
1castlecops[1].exe151174 bytesMD5: 5b8577deb819495ffa0c1e03501eab77
2rqron.dll228960 bytesMD5: e15ce7b4780ad9f40d1a440b8ef2f060
3hgggdbx.dll37376 bytesMD5: 5b6e77af55dce55ff64eeeb0a3ac7266
4ddcabya.dll38400 bytes
5khfcdaw.dll31254 bytes
6tuvutus.dll36352 bytes
7mljgf.dll327168 bytes
8ddcca.dll243296 bytesMD5: a8c3bb2a95e2c0c28b309bf4f0ff66cd
9mljiggd.dll346112 bytesMD5: 03971499d8b1a48e59945a0a06ce0aed
10vljdgnh.dll139264 bytesMD5: 57c9bb2e12f131344b617a012854276b
11yayxuus.dll38912 bytes
12ssttr.dll262708 bytesMD5: 10b582828eaf28c34d23de94fb0f7c1b
13jkkll.dll228960 bytesMD5: 1485ef1e7c28347c418409b4fee869a3
14tuvwuss.dll31254 bytes
15ivrrwfps.dll70208 bytesMD5: 2fb9509f1b9134ae56fd535d4c4634f8
16ces005dr.exe30737 bytes
17dvigdtgi.dll70208 bytesMD5: 4865a39fe1e6a148eb85a3a3918ba005
18xxyvspp.dll351744 bytesMD5: 2ed1c1e93b3917a587fa762ee5258d6c
19khffefd.dll36352 bytes
20lemaba.dll129024 bytes
21vtuts.dll320608 bytesMD5: d4453218a781af7ec2a0c7153d8e4109
22ssqopqo.dll24288 bytesMD5: cb722ba8cd0b5ff62dc98d634fe6d5cc
23mljjk.dll285273 bytesMD5: 6319e1c59d531d82e9f17c1261d29626
24kadpbbdr.dll80000 bytes
25ssqpono.dll24336 bytesMD5: b783e387dd3b7921493c8cdfc4d0b6de
26jkhhf.dll298080 bytesMD5: da67e9a5676c0381c7d696011608a587
27vturspo.dll26694 bytesMD5: f5236876d4cd7c1f430b8de50b250701
28wspxxtfw.dll114688 bytesMD5: f45372d3b83cd7e9f8c153b335406724
29temlxopqgdk.dll212992 bytes
30xxyxwxv.dll43542 bytes
31iifdcdb.dll35328 bytesMD5: 56f180294d5d47128936f9a34318a83b
32ddcbabx.dll26678 bytesMD5: 19fb333000f260fd534c63945483994d
33awtttqr.dll44054 bytesMD5: 67f2bcd4263ff4f61764f600aeca8047
34mljgd.dll322656 bytesMD5: e7e4384da19a8cea4bdb7c96a48ad0e1
35ddcyx.dll285273 bytesMD5: 13a4630f5928d9380a668bdccf69286b
36xxywxxy.dll38400 bytesMD5: a8df1d39ea45217d4acffaab9f012a84
37mljighf.dll36864 bytes
38ykiijcvp.dll110336 bytesMD5: b615679e45460500fd640d07d8821f30
39mljkkhf.dll31254 bytesMD5: 3eba5d5ee0d0833b75babc403c46f764
40vumer.dll199698 bytes
41ssqrp.dll307808 bytesMD5: 0f90394deda6937ac102fecb79745a7b
42wvwxv.dll273920 bytes
43bndsrsqo.dll245760 bytesMD5: 1d5f61d151fcbb699c5d3e51312fbecb
44vtsss.dll298080 bytesMD5: 57a476f763feb384f5272d441fab4597
45mllmm.dll244832 bytesMD5: 22a9274ca7e69511cc29bec01a66894c
46ssqnolm.dll37376 bytesMD5: fabe066bc103c1b61015ada58e781153
47ljjgedc.dll43542 bytes
48hggdefc.dll34304 bytesMD5: ef8f2da9fa62e4624e643c429e7ee34d
49pmnlk.dll307296 bytesMD5: 371b61b663d7b1ca0c69d5e4f320d013
50EliStarA 1965.exe629771 bytesMD5: e4a1080cef208be3122e08ca56365e02
51opnnljj.dll33302 bytesMD5: 29a0dbb047ea5167b5c0897902045718
52mljhghe.dll31254 bytesMD5: c7a272c553efe200e928310537a7a728
53gebabcd.dll40448 bytes
54vtutron.dll23696 bytes
55opnnlmn.dll38912 bytesMD5: 76b37794a974e5fbcc08c9713d83dd17
56mljgh.dll320096 bytesMD5: 9f5d77a8f8b769b1621a7a573f8911c9
57odgkhiaq.dll11840 bytesMD5: 4c176113da7eb0700f2bd9a2b59a9e52
58rqrppon.dll43542 bytes
59pmnlmnk.dll39424 bytes
60ssqrs.dll266336 bytesMD5: 2f73da71f31c691081a8b08ccad4e81c
61sstts.dll313440 bytesMD5: fcb4bd697964018ecb3d025db568118f
62nnlif.dll320096 bytes
63xxyyxur.dll26048 bytesMD5: 362768e6afd97a288b4a0bebdb4efda9
64geeby.dll244832 bytesMD5: c7ed881353a0e902de96aaaef4b08cf1
65iowrrqbs.dll70208 bytesMD5: cef13d112246a02b01fdf20a5bbb7ec8
66urstr.dll228960 bytesMD5: fead1b9c31e22cd68fcce42ce891722a
67ssqpq.dll336384 bytesMD5: 2535658e4f1a5103ef18676d8d791694
68byxxy.dll335968 bytesMD5: ca4b16645b62f767a183a2a848d9706d
69rqrssro.dll44054 bytes
70awtqqnl.dll26694 bytesMD5: a235f52ad905ec89f9c9632f9a94dbe8
71EliStarA 20.20.exe679947 bytesMD5: 66b5f0d0a9af1c9b39dbf14ffa378f16
72Nero_Burning_Rom_Ultra_Edition_6.6.0.6_serial_number.txt[1].exe168589 bytesMD5: 0c0cecac345a6e41309e6d65489753dc
73vtuspmn.dll26637 bytesMD5: 59aef3b861b7a2a74ae97454628cfee9
74SbCIe02b.dll208896 bytesMD5: 908388713dc2e96068e2591ac67c54b7
75iifcyab.dll38912 bytes
76efcbbcc.dll38912 bytes
77hrj6051se.dll233555 bytes
78jtr0079me.dll233652 bytes
79dsnltn.dll120960 bytes
80awtqomn.dll36352 bytesMD5: 00e6269b8a8de5276c67230c96b29a3e
81mljijhi.dll41472 bytesMD5: 5f40045792cd83b671e054a42404dd36
82sstrs.dll266336 bytesMD5: 0c053e21700e83a163b50c18108268e1
83pmkjj.dll298080 bytesMD5: 8bed6e305b017adb1a662f2abed6d503
84ssqqomk.dll31254 bytes
85keycpl.dll92730 bytesMD5: 4e2054ae08dced53e3f493afba8212b8
86byxurqq.dll44054 bytesMD5: 275cbcbe24a20a1b5f89c16b3cad8907
87jkhfe.dll328704 bytesMD5: 7134e38e457520099c36e1b073481f95
88sstur.dll231520 bytesMD5: a8806fbb9a26110e9e67f7160f573c70
89opnkjjg.dll39424 bytes
90iifddby.dll, yaywttq.dll26694 bytesMD5: 2f287e9392c950158148779c9364e6a0
91bunwhhmo.dll69184 bytesMD5: 40ed74ae9ec8a6c305f4fddd43a888bb
92iifddby.dll26694 bytes
93urqrpqp.dll35328 bytesMD5: 3c353965b47f91219f44014ef5938a22
94ssqpn.dll326752 bytesMD5: 30b62459049d5309673058f14b971ecb
95cmutils.dll120576 bytes
96nnlmn.dll321120 bytesMD5: ba23772716a35953cceb8d5534253f47
97qwmehqhv.dll70208 bytesMD5: 2cd528092aca61315c6fe75e3da88ac4
98pmnlj.dll308832 bytesMD5: 305f95d475d271f59f97a61fca20309b
99gebyxuu.dll36352 bytes
100cbkllosv.dll70208 bytesMD5: 75f86a0ccd4845cfa74b3ea9183278b5
101EliStarA.exe645131 bytesMD5: 6ddcb20704d7be4fa40e50a3e5625244
102khfcdba.dll43542 bytes
103efcdaab.dll36352 bytes
104opnnopq.dll38400 bytes
105pmnnn.dll263168 bytes
106EliStarA 20 dic 2009.exe639499 bytesMD5: 084eeafec5e366eb4e7b7d9acf35e57e
107ssqqn.dll319584 bytesMD5: 80301c9557dfdbd74485762e052e59ea
108winsrc.dll311816 bytesMD5: 6dc59cd4a45f96cc27b2a9d710f7abc2
109rldmmyyb.dll69184 bytesMD5: 4eb00dbd11d001b635ec0d4a2ac50bec
110ddcaaxu.dll38912 bytesMD5: 569d8140191d5a454ff665140ea6e30d
111nnnmmlk.dll31254 bytesMD5: cbe9e81aa9d4ff26dde8c35839c55fd0
112gebya.dll331360 bytesMD5: 0bc9b5120a80483f868572632a6810fa
113iiffgfd.dll39424 bytes
114mllkk.dll266336 bytesMD5: 0b04c48ec47c70bba5d173bcaa61f58c
115drvkuk.dll103936 bytesMD5: 32bea5969a6e057042aa40a849478ded
116hggfged.dll34304 bytesMD5: 60a1e02a5ec8707405bd07d0f244de83
117ddaya.dll340480 bytesMD5: 46fb3acceb4c34d1d13a89f821505c7c
118tmpidamd.dll70208 bytesMD5: efaf3e853f800d5897d2cda807c423b3
119tuvvsrp.dll36352 bytesMD5: 68bfcc5833616bcccdb4e6d3bfdb0c4f
120khfcdba.dll, ljjgedc.dll, rqrppon.dll, wvursqn.dll, xxyxwxv.dll43542 bytesMD5: 02fb66ff2648fb497a3a1998f4d0b844
121rulesak.dll110592 bytes
122awtqo.dll320096 bytesMD5: 3e65d4d37199f6eb1ff5bfe64e455218
123ljjhgee.dll40960 bytes
124cbxussr.dll44054 bytes
125pmnno.dll262708 bytesMD5: fe192ced601812e3f46825b3a094e729
126fccdbab.dll40448 bytes
127ljiijj.dll90112 bytesMD5: 71a371a6c8e9f3cca00da9f0cc41830f
128keygen.exe53773 bytesMD5: b29d7eec069ad3bb874a99d3737e5b60
129urqollm.dll24336 bytesMD5: 0fe566a5beaa37bdb39dff82299d4913
130opnlifg.dll40448 bytes
131geebc.dll263220 bytesMD5: a78dcf34c93869b46d13f1abb7e1ca09
132uynltcou.dll77376 bytesMD5: b024c806349071b38e47254e81f87abe
133vtsts.dll298080 bytesMD5: c61a58b9b88999f40550bf6efd3a9a91
134lspak.dll196608 bytes
135opnlm.dll321120 bytesMD5: fda553a5a55f9b2315761ff37f446dcc
136jiinhuyb.dll77376 bytesMD5: 48513f985265cf515be1fafdb46f4158
137sstqq.dll266336 bytesMD5: 7d745eb8c24ebd05f8357b452e095d28
138nnx22011.exe116351 bytes
139pmnnm.dll298080 bytesMD5: 1a622cba5a89518cf4a511492db9d4f7
140ddayy.dll332288 bytes
141cbxxywx.dll29206 bytesMD5: 274007e7c2fef02eafd67c49f5f6bb56
142wvursqn.dll43542 bytes
143awtqopm.dll36352 bytesMD5: 2b262799cd238f8e99101470f172d8c1
144Windows_XP_SP2_Professional_Edition_Corporate_serial_number.txt[2].exe168657 bytesMD5: b8e0cf17674dc0d38320ce4d3dbe7c46
145ksljdsle.dll70208 bytesMD5: 2b08afb83e8ae77050b063ef9c2ef0a3
146ddcawvv.dll37888 bytes
147byxvs.dll316512 bytesMD5: 79b321ef5702201cda904a9a4e48bcf9

Memory Processes Created:

# Process Name Process Filename Main module size
1castlecops[1].execastlecops[1].exe151174 bytes
2ces005dr.execes005dr.exe30737 bytes
3EliStarA 1965.exeEliStarA 1965.exe629771 bytes
4EliStarA 20.20.exeEliStarA 20.20.exe679947 bytes
5Nero_Burning_Rom_Ultra_Edition_6.6.0.6_serial_number.txt[1].exeNero_Burning_Rom_Ultra_Edition_6.6.0.6_serial_number.txt[1].exe168589 bytes
6EliStarA.exeEliStarA.exe645131 bytes
7EliStarA 20 dic 2009.exeEliStarA 20 dic 2009.exe639499 bytes
8keygen.exekeygen.exe53773 bytes
9nnx22011.exennx22011.exe116351 bytes
10Windows_XP_SP2_Professional_Edition_Corporate_serial_number.txt[2].exeWindows_XP_SP2_Professional_Edition_Corporate_serial_number.txt[2].exe168657 bytes

Registry Modifications:

The following Registry Keys were created:

  • 904598c7
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {EEC73EA5-1367-49D1-93F4-CA1D8C22E9F9}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {135B4804-7728-4137-B6D8-5CC590110C9D}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AFFCBA64-651F-43DD-97BC-684C179618A5}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {57D6708C-88E2-4CAB-9FA4-78BB8CA3A3C4}
  • kopCFEWV.exe
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {D0DC2547-DF58-4CF2-8FA2-25DEE29426F6}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {837B45D6-BF85-457D-AABF-6D2E7815F791}
  • Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler {037C7B8A-151A-49E6-BAED-CC05FCB50328}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad dtseqrxk
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {AD72687B-CF83-4463-8E95-2CB3198CA5F6}
  • Microsoft\Windows NT\CurrentVersion\Winlogon\Notify khfDtUno
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {E7683750-B89A-402F-8F22-EBF3DA3F70C2}
  • 2chkdsk
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {A05DA7E0-383C-4E99-A72A-742050A152A2}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {5FCD13AC-B899-4EF7-BD3E-C959EFBFB753}
  • gf1.0.0.2
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {6148028B-D532-4417-8C0B-5A4A0B745393}
  • cbgzgdqt
  • Software\Microsoft\Internet Explorer\Explorer Bars {83B28A74-640D-48F4-9F51-E80EED7CC7E0}
  • SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks {60EDCEE2-B6AF-4F2E-BB15-14F101364B47}

Reply

Your email address will not be published.

Name
Website
Comment

Enter the numbers in the box to the right *