<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: VirtuMonde</title>
	<atom:link href="http://www.411-spyware.com/remove-virtumonde/feed" rel="self" type="application/rss+xml" />
	<link>http://www.411-spyware.com/remove-virtumonde</link>
	<description>411-Spyware.com</description>
	<lastBuildDate>Mon, 23 Nov 2009 03:04:02 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: spybot - virtumonde - Comunidad GX</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-35661</link>
		<dc:creator>spybot - virtumonde - Comunidad GX</dc:creator>
		<pubDate>Sat, 22 Aug 2009 22:13:23 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-35661</guid>
		<description>[...] que no estas detectando y que la sigue corriendo..  ..lei que es un troyano mira esta pagina Remove VirtuMonde (Removal Instructions) &#124; 411 on Spyware tiene muchos process asociados, como era de imaginar [...]</description>
		<content:encoded><![CDATA[<p>[...] que no estas detectando y que la sigue corriendo..  ..lei que es un troyano mira esta pagina Remove VirtuMonde (Removal Instructions) | 411 on Spyware tiene muchos process asociados, como era de imaginar [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yvonne</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-35276</link>
		<dc:creator>Yvonne</dc:creator>
		<pubDate>Sat, 04 Jul 2009 02:06:47 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-35276</guid>
		<description>Just to let everyone know that people are getting it back because there is a process in task manager call msa.exe that i think is part of the virtumonde thing and if not stopped and deleted off hard drive (search for msa.exe) it keeps reloading They think there clever making these programs to steal things but there just another type of criminal. BORING</description>
		<content:encoded><![CDATA[<p>Just to let everyone know that people are getting it back because there is a process in task manager call msa.exe that i think is part of the virtumonde thing and if not stopped and deleted off hard drive (search for msa.exe) it keeps reloading They think there clever making these programs to steal things but there just another type of criminal. BORING</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-34724</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Wed, 06 May 2009 15:59:16 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-34724</guid>
		<description>I was experiencing the same symptoms as listed by virtu...ces above - the thing was reloading processes faster than I could scan and fix them with HijackThis, or anything else.  Even in Task Manager, if you killed a process it would reappear in a few seconds.  There was one particular BHO in Internet Explorer that was the culprit.  Once I deleted that BHO, then HijackThis and the anti-virus program could really delete the virus (I use Zone Alarm).  It made no difference if Internet Explorer was open or not.  In Internet Explorer, go to Tools - Internet Options - select the Programs tab - click on the Manage Add-Ons button.  The one on my machine had a weird name like {nnn....}.  While there you might want to disable a bunch of the other junk you find.  I hope this helps - the next step was to totally rebuild....</description>
		<content:encoded><![CDATA[<p>I was experiencing the same symptoms as listed by virtu&#8230;ces above &#8211; the thing was reloading processes faster than I could scan and fix them with HijackThis, or anything else.  Even in Task Manager, if you killed a process it would reappear in a few seconds.  There was one particular BHO in Internet Explorer that was the culprit.  Once I deleted that BHO, then HijackThis and the anti-virus program could really delete the virus (I use Zone Alarm).  It made no difference if Internet Explorer was open or not.  In Internet Explorer, go to Tools &#8211; Internet Options &#8211; select the Programs tab &#8211; click on the Manage Add-Ons button.  The one on my machine had a weird name like {nnn&#8230;.}.  While there you might want to disable a bunch of the other junk you find.  I hope this helps &#8211; the next step was to totally rebuild&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raymond</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-33137</link>
		<dc:creator>Raymond</dc:creator>
		<pubDate>Sat, 10 Jan 2009 15:20:48 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-33137</guid>
		<description>Remove the hatd drive from the infected computer, attach it to another that has autorun diabled. Scan the computer with Malwarebytes, Spybot, and Webroot or what ever virus scanner you have. Scanning the drive while it is attached to another computer will prevent any of the files from being loaded into memory or locked, preventing them from being removed.</description>
		<content:encoded><![CDATA[<p>Remove the hatd drive from the infected computer, attach it to another that has autorun diabled. Scan the computer with <span class='bm_keywordlink'><a href="http://shop.malwarebytes.org/lpa/342/1/4909/en/" rel="nofollow">Malwarebytes</a></span>, <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span>, and Webroot or what ever virus scanner you have. Scanning the drive while it is attached to another computer will prevent any of the files from being loaded into memory or locked, preventing them from being removed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: virtumondemakersarefeces</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-33018</link>
		<dc:creator>virtumondemakersarefeces</dc:creator>
		<pubDate>Mon, 05 Jan 2009 03:26:00 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-33018</guid>
		<description>I rarely use Microsoft Internet-Explorer but I did so to find a radio website that needed ActiveX.  After opening IE, I started getting pop up ads.  I activated task manager and saw that there were several processes running that should not have been there.  I opened Process Explorer and identified several processes acting out of the Windows sys32 file.  I killed a few files I was pretty certain were viral/spyware/crap by delete or rename-n-delete or process kill.  I also used Hijack this to remove some BHO.  AVG noted that my boot sector had been changed.  I noticed that processes and files were appearing as I was killing them.  I went to Internet Options and turned off ALL activeX garbage.  This help to stop 75% of the new processes but there was a single .dll file I could not remove.  I downloaded Malwarebytes from a cache page of a Google search because the Virtumonde was blocking primary access to certain webpages.  After running Malwarebytes, my computer appears free of Virtumonde and I was able to remove the last BHO for a deleted dll using HijackThis.</description>
		<content:encoded><![CDATA[<p>I rarely use Microsoft Internet-Explorer but I did so to find a radio website that needed ActiveX.  After opening IE, I started getting pop up ads.  I activated task manager and saw that there were several processes running that should not have been there.  I opened Process Explorer and identified several processes acting out of the Windows sys32 file.  I killed a few files I was pretty certain were viral/spyware/crap by delete or rename-n-delete or process kill.  I also used Hijack this to remove some BHO.  <span class='bm_keywordlink_affiliate'><a href="http://www.jdoqocy.com/k0108mu2-u1HLLLMOQPHJIOLROIK" rel="nofollow">AVG</a></span> noted that my boot sector had been changed.  I noticed that processes and files were appearing as I was killing them.  I went to Internet Options and turned off ALL activeX garbage.  This help to stop 75% of the new processes but there was a single .dll file I could not remove.  I downloaded <span class='bm_keywordlink'><a href="http://shop.malwarebytes.org/lpa/342/1/4909/en/" rel="nofollow">Malwarebytes</a></span> from a cache page of a Google search because the Virtumonde was blocking primary access to certain webpages.  After running <span class='bm_keywordlink'><a href="http://shop.malwarebytes.org/lpa/342/1/4909/en/" rel="nofollow">Malwarebytes</a></span>, my computer appears free of Virtumonde and I was able to remove the last BHO for a deleted dll using HijackThis.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wizboss59</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-32972</link>
		<dc:creator>wizboss59</dc:creator>
		<pubDate>Fri, 02 Jan 2009 19:21:20 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-32972</guid>
		<description>My Lenovo laptop running XP pro was infected with malware &quot;virtumonde&quot; which randomly opens browser windows, pop-ups, installs trojans and displays warning messages.
Also, it seem to have turned off the firewall, automatic windows updates and Norton. I was able to turn on the firewall but not the automatic updates and I believe that Norton was corrupted as it can&#039;t be updated and/or turned on.
Reboot was problematic, it failed several time but finally rebooted okay. The performance however was very poor. Since Norton was disabled, I have downloaded and ran the AVG free version. It detected and cleaned 2 trojans but other trojans kept appearing. I ran Spybot and it detected three entries of virtumonde (virtumonde.generic, virtumonde.dll and virtumonde.sci). I selected them, clicked fix and it checked them as removed but it didn&#039;t as in the next scan they showed up again. I also downloaded and ran a Symantec &quot;FxVmonde&quot; removal tool which didn&#039;t find anything. I ran Ad-Aware which detected a couple of Trojans and removed them but it didn&#039;t solve the problem. My next step was to do it manually. I searcehd for the processes and key registries that are mentioned here and didn&#039;t find them. I then uninstalled AVG, Spybot and Ad_Aware. I didn&#039;t uninstall Norton as I don&#039;t have the key to run the tool. I downloaded Windows Defender from MS&#039;s site. It took a couple of validations before it was downloaded. I ran windows defender which detected  the Trojan files: Vundo.gen!J, ZangoShoppi...., Vundo.gen!Y, Conhook.D. and asked to reboot the PC.
After the reboot the malware was gone and my laptop is back to life again. It took me tree days of trials and errors to solve this and I hope that this will help a lot of people that are struggling with this menace. Good luck!</description>
		<content:encoded><![CDATA[<p>My Lenovo laptop running XP pro was infected with malware &#8220;virtumonde&#8221; which randomly opens browser windows, pop-ups, installs trojans and displays warning messages.<br />
Also, it seem to have turned off the firewall, automatic windows updates and <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Norton</a></span>. I was able to turn on the firewall but not the automatic updates and I believe that <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Norton</a></span> was corrupted as it can&#8217;t be updated and/or turned on.<br />
Reboot was problematic, it failed several time but finally rebooted okay. The performance however was very poor. Since <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Norton</a></span> was disabled, I have downloaded and ran the <span class='bm_keywordlink_affiliate'><a href="http://www.jdoqocy.com/k0108mu2-u1HLLLMOQPHJIOLROIK" rel="nofollow">AVG</a></span> free version. It detected and cleaned 2 trojans but other trojans kept appearing. I ran <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> and it detected three entries of virtumonde (virtumonde.generic, virtumonde.dll and virtumonde.sci). I selected them, clicked fix and it checked them as removed but it didn&#8217;t as in the next scan they showed up again. I also downloaded and ran a <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Symantec</a></span> &#8220;FxVmonde&#8221; removal tool which didn&#8217;t find anything. I ran Ad-Aware which detected a couple of Trojans and removed them but it didn&#8217;t solve the problem. My next step was to do it manually. I searcehd for the processes and key registries that are mentioned here and didn&#8217;t find them. I then uninstalled <span class='bm_keywordlink_affiliate'><a href="http://www.jdoqocy.com/k0108mu2-u1HLLLMOQPHJIOLROIK" rel="nofollow">AVG</a></span>, <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> and Ad_Aware. I didn&#8217;t uninstall <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Norton</a></span> as I don&#8217;t have the key to run the tool. I downloaded Windows Defender from MS&#8217;s site. It took a couple of validations before it was downloaded. I ran windows defender which detected  the Trojan files: Vundo.gen!J, ZangoShoppi&#8230;., Vundo.gen!Y, Conhook.D. and asked to reboot the PC.<br />
After the reboot the malware was gone and my laptop is back to life again. It took me tree days of trials and errors to solve this and I hope that this will help a lot of people that are struggling with this menace. Good luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Virtumonde</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-32726</link>
		<dc:creator>Virtumonde</dc:creator>
		<pubDate>Wed, 17 Dec 2008 18:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-32726</guid>
		<description>[...] you might wanna look at this webpage Remove VirtuMonde (Removal Instructions) » 411-Spyware.com  spybot can do pretty well, use it to delete the virus, restart computer, then use spybot again to [...]</description>
		<content:encoded><![CDATA[<p>[...] you might wanna look at this webpage Remove VirtuMonde (Removal Instructions) » 411-Spyware.com  <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> can do pretty well, use it to delete the virus, restart computer, then use <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> again to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Keller</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-32382</link>
		<dc:creator>Robert Keller</dc:creator>
		<pubDate>Mon, 24 Nov 2008 21:16:51 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-32382</guid>
		<description>I&#039;ve had this virus before, and now I have it again. I got rid of it before by running Spybot search and destroy, deleting the found files, and then immediately 
running a system restore to a point before infection. I then was able to delete the remaining dll file and any other lingering files. Next, I created a &quot;dummy&#039; dll
file in the system32 folder and gave it the same name as the deleted, malicious dll (don&#039;t ask me why--I didn&#039;t really know what I was doing but I thought
I&#039;d give it a try).  I ran spybot again after that and it detected nothing. The virus stayed off my computer for months before I got re-infected online.
So, that&#039;s my strategy this time around, and hopefully it will work. By the way, to those who created this virus--you should rot in a 
Siberian dungeon, eating rats for survival. You&#039;re worthless, and I wish extreme bad karma on you!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve had this virus before, and now I have it again. I got rid of it before by running <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> search and destroy, deleting the found files, and then immediately<br />
running a system restore to a point before infection. I then was able to delete the remaining dll file and any other lingering files. Next, I created a &#8220;dummy&#8217; dll<br />
file in the system32 folder and gave it the same name as the deleted, malicious dll (don&#8217;t ask me why&#8211;I didn&#8217;t really know what I was doing but I thought<br />
I&#8217;d give it a try).  I ran <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> again after that and it detected nothing. The virus stayed off my computer for months before I got re-infected online.<br />
So, that&#8217;s my strategy this time around, and hopefully it will work. By the way, to those who created this virus&#8211;you should rot in a<br />
Siberian dungeon, eating rats for survival. You&#8217;re worthless, and I wish extreme bad karma on you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: markthegreat</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-32273</link>
		<dc:creator>markthegreat</dc:creator>
		<pubDate>Mon, 17 Nov 2008 20:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-32273</guid>
		<description>the guys who made this program were so you buy their product, personnally i think they should be shot...If i knew who it was and they lived in my town I would personally take care of them!! because they cause us alot of grief for profit...bastards</description>
		<content:encoded><![CDATA[<p>the guys who made this program were so you buy their product, personnally i think they should be shot&#8230;If i knew who it was and they lived in my town I would personally take care of them!! because they cause us alot of grief for profit&#8230;bastards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mersi</title>
		<link>http://www.411-spyware.com/remove-virtumonde/comment-page-1#comment-31672</link>
		<dc:creator>Mersi</dc:creator>
		<pubDate>Thu, 02 Oct 2008 07:41:03 +0000</pubDate>
		<guid isPermaLink="false">http://411-spyware.com/remove-virtumonde#comment-31672</guid>
		<description>I FINALLY got rid of virtumonde with Spysweeper. Finally killed Virtumonde!!  and removed it, no more annoying IE pages opening randomly.  (I&#039;ll give it a few days to make sure)   This creepy thing disabled Spybot search and destroy&#039;s ability to remove it as well as AVG.  they could identify it , quarantine it , and then it was BAAAAck.  I couln&#039;t install Mcaffee either, and norton didn&#039;t detect it.  So I am now using AVG in combo with Spy Sweeper by Webroot, and I am going toB Beta demo  their virus software as well.  I have used Norton for years, and was disappointed that Virtu managed to disable it, which let other viruses in as well.  Thanks for this site.  I found it on google, just to see how others were doing with this thing, once I had identified it.</description>
		<content:encoded><![CDATA[<p>I FINALLY got rid of virtumonde with Spysweeper. Finally killed Virtumonde!!  and removed it, no more annoying IE pages opening randomly.  (I&#8217;ll give it a few days to make sure)   This creepy thing disabled <span class='bm_keywordlink'><a href="http://www.safer-networking.org/en/spybotsd/index.html" rel="nofollow">Spybot</a></span> search and destroy&#8217;s ability to remove it as well as <span class='bm_keywordlink_affiliate'><a href="http://www.jdoqocy.com/k0108mu2-u1HLLLMOQPHJIOLROIK" rel="nofollow">AVG</a></span>.  they could identify it , quarantine it , and then it was BAAAAck.  I couln&#8217;t install Mcaffee either, and <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Norton</a></span> didn&#8217;t detect it.  So I am now using <span class='bm_keywordlink_affiliate'><a href="http://www.jdoqocy.com/k0108mu2-u1HLLLMOQPHJIOLROIK" rel="nofollow">AVG</a></span> in combo with Spy Sweeper by Webroot, and I am going toB Beta demo  their virus software as well.  I have used <span class='bm_keywordlink_affiliate'><a href="http://www.anrdoezrs.net/1g81p-85-7NRRRSUWVNPOTUSOXS" rel="nofollow">Norton</a></span> for years, and was disappointed that Virtu managed to disable it, which let other viruses in as well.  Thanks for this site.  I found it on google, just to see how others were doing with this thing, once I had identified it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
