How to Detect & Remove VirtuMonde
What's VirtuMonde?
VirtuMonde is adware that launches annoying popup ads on your PC. VirtuMonde popups pimp fake anti-spyware like SysDefender, WinFixer, and ErrorSafe. VirtuMonde can also act as a keylogger, and record every keystroke you type, save this information as a DLL file (virtumonde.DLL, perhaps?), and send it to a parent site, putting your personal and financial information at risk.
VirtuMonde is also known as Virtumonde.C, and “major rip-off.”
» Comment supprimer VirtuMonde, en Français
Do I Have VirtuMonde?
You can search your computer manually, but it might take hours to find VirtuMonde’s hidden files. To save time, I recommend you automatically scan your PC for VirtuMonde and other spyware. Why not? It’s free.
Free VirtuMonde Scan, with SpyHunter
You can easily detect VirtuMonde with SpyHunter’s FREE spyware scanner. And if you’re really infected with VirtuMonde, you can buy the full version of SpyHunter to remove VirtuMonde and other spyware. Or you can use my instructions below and remove VirtuMonde for free.
I’m a big fan of SpyHunter. Here’s why: SpyHunter offers live support on the phone, and if SpyHunter doesn’t automatically remove VirtuMonde, you can get a custom fix for your computer.
How to Remove VirtuMonde
Your best protection against VirtuMonde is to remove VirtuMonde processes, registry keys, DLLs, and other files ASAP.
Get Rid of VirtuMonde Manually
Manual removal of any spyware can be difficult. When you manually remove VirtuMonde, you have to fiddle with your registry and risk destroying your PC. It’s highly recommended you use an automatic spyware scanner to make sure you’re infected with VirtuMonde. Also, I recommend you backup your system any time before editing your registry.
To remove VirtuMonde manually, you need to delete VirtuMonde files. Not sure how to delete VirtuMonde files? Click here, and I’ll tell you. Otherwise, go ahead and…
Remove VirtuMonde processes:
winhost.exe
quicken.exe
editpad.exe
%System%\winhost32.exe
Remove VirtuMonde registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\TargetSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEpl.IEpl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEpl.IEPl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tdev
HKEY_USERS\S-1-5-21-1887652994-1477516851-2064603551-500\Software\Microsoft
HKEY_CLASSES_ROOT\CLSID\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
\Windows\CurrentVersion\Ext\Stats\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder.1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats
\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
Detect and Remove these VirtuMonde DLLs:
lspak.dll
%System%\wincore.dll
%System%\cidrules.dll
%UserProfile%\Local Settings\Temp\wincore.dll
%System%\winupd.dll
%UserProfile%\Local Settings\Temp\cidrules.dll
Note: In any files I mention above, “%System%” is a variable referring to your PC’s System folder. Maybe you renamed it, but by default your System folder is “C:\Windows\System32″ on Windows XP, “C:\Winnt\System32″ on Windows NT/2000,” or “C:\Windows\System” on Windows 95/98/Me.
“%Program_Files%”, “%ProgramFiles%”, or “%Profile%” is a variable referring to a folder in your PC where applications that aren’t a part of your PC’s operating system are installed by default. You may have changed this folder’s name or moved it, but if you didn’t touch it, find the folder as “C:\Program Files”. If you’re having trouble finding this folder, you can locate it by looking up registry value “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir”.
Also, “%UserProfile%” is a variable referring to your current user’s profile folder. If you’re using Windows NT/2000/XP, by default this is “C:\Documents and Settings\[CURRENT USER]” (e.g., “C:\Documents and Settings\JoeSmith”).
VirtuMonde changed your homepage?
Click Windows Start menu > Control Panel > Internet Options. Next, under Home Page, select the General > Use Default. Type in the URL you want as your home page (e.g., “http://www.homepage.com”). Then select Apply > OK. You’ll want to open a fresh web page and make sure that your new default home page pops up.
Recommendation:
To save time and avoid risking destroying your computer, I highly recommend you use a spyware scanner, such as SpyHunter, to detect VirtuMonde and other spyware, adware, trojans, viruses, keyloggers, and more that can be hidden in your PC. It’s also recommended before you manually remove VirtuMonde you backup your system.
Free VirtuMonde Scan, with SpyHunter
Automatically detect VirtuMonde and other spyware on your PC with SpyHunter’s FREE spyware scan.
How Do I Remove VirtuMonde Files?
Need help figuring out how to delete files, DLLs, and registry keys? While there’s some risk involved, and you should only manually remove VirtuMonde files if you’re comfortable and confident editing your system, you’ll find it’s fairly easy to delete VirtuMonde files in Windows.
How to delete VirtuMonde files in Windows XP and Vista:
- Click your Windows Start menu, and from “Search,” click “For Files and Folders…“
- A speech bubble will pop up asking you, “What do you want to search for?” Click “All files and folders.”
- Type any file name in the search box, and select “Local Hard Drives.”
- Click “Search.” Once the file is found, delete it.
How to stop VirtuMonde processes:
- Click the Start menu, select Run.
- Type taskmgr.exe into the the Run command box, and click “OK.” You can also launch the Task Manager by pressing keys ALT + CTRL + DELETE or CTRL + Shift + ESC.
- Click Processes tab, and find VirtuMonde processes.
- Once you’ve found the VirtuMonde processes, right-click them and select “End Process” to kill VirtuMonde.
How to remove VirtuMonde registry keys:
Your Windows registry is the core of your Windows operating system, storing information about user settings, system preferences, and software, including which applications automatically launch at start up. Because of this, spyware, malware, and adware will often bury their own files into your Windows registry so that they automatically launch every time your start up your PC.
Because your registry is such a key piece of your Windows system, you should always backup your registry before you make any changes to it. Editing your registry can be intimidating if you’re not a computer expert, and when you change or a delete a critical registry key or registry value, there’s a chance you may need to reinstall your entire Windows operating system. Make sure your backup your registry before editing it.
- Select your Windows menu “Start,” and click “Run.” An “Open” field will appear. Type “regedit” and click “OK” to open up your Registry Editor.
- Registry Editor will open as a window with two panes. The left side Registry Editor’s window lets you select various registry keys, and the right side displays the registry values of the registry key you select.
- To find a registry key, such as any VirtuMonde registry keys, select “Edit,” then select “Find,” and in the search bar type any of VirtuMonde’s registry keys.
- As soon as VirtuMonde registry key appears, you can delete the VirtuMonde registry key by right-clicking it and selecting “Modify,” then clicking “Delete.”
Computer acting funny after you’ve edited your registry and deleted VirtuMonde registry keys? Just restore your registry with your backup.
How to remove VirtuMonde DLL files:
Like most any software, spyware, adware, and malware may also use DLL files. DLL is short for “dynamically linked library,” and VirtuMonde DLL files, like other DLLs, carryout predetermined tasks. To manually delete VirtuMonde DLL files, you’ll use Regsver32, a Windows tool designed to help you remove DLL and other files.
- First you’ll locate VirtuMonde DLL files you want to delete. Open your Windows Start menu, then click “Run.” Type “cmd” in Run, and click “OK.”
- To change your current directory, type “cd” in the command box, press your “Space” key, and enter the full directory where the VirtuMonde DLL file is located. If you’re not sure if the VirtuMonde DLL file is located in a particular directory, enter “dir” in the command box to display a directory’s contents. To go one directory back, enter “cd ..” in the command box and press “Enter.”
- When you’ve located the VirtuMonde DLL file you want to remove, type “regsvr32 /u SampleDLLName.dll” (e.g., “regsvr32 /u jl27script.dll”) and press your “Enter” key.
That’s it. If you want to restore VirtuMonde DLL file you removed, enter “regsvr32 DLLJustDeleted.dll” (e.g., “regsvr32 jl27script.dll”) into your command box, and press your “Enter” key.
How Did I Get VirtuMonde?
You may be wondering how VirtuMonde ended up on your PC. If you’re infected with VirtuMonde or other spyware, your system’s and web browser’s security settings may be set too low, you may not follow safe web browsing and email habits, and you may need to regularly use a good anti-spyware application. Unsafe computer behavior that may lead to your PC having VirtuMonde includes:
Freeware or Shareware:
Did you download and install shareware or freeware? These low-cost or free software applications may come bundled with spyware, adware, or programs like VirtuMonde. Sometimes adware is attached to the free software to “pay” developers for the cost of creating the software, and more often spyware is secretly and maliciously attached to free software to harm your computer and steal your personal and financial information.
Peer-to-Peer Software:
Do you use a peer-to-peer (P2P) program or other application with a shared network? When you use these applications, you put your system at risk for unknowingly downloading an infected file, including applications like VirtuMonde.
Questionable Websites: Did you visit a website that’s of questionable nature? When you visit malicious sites that are fishy and phishy, Trojans, spyware, and adware may be automatically downloaded and installed onto your computer, sometimes including applications like VirtuMonde.
It’s important to practice safer online habits to prevent being infected with VirtuMonde . You may want to scan your computer for the latest version of VirtuMonde and other security threats.
Detect VirtuMonde & Other Malware
Is your computer infected with malware?
When you’re infected with malware, whether it’s VirtuMonde, spyware, adware, trojans, rogue anti-spyware, keyloggers, worms, or viruses, there are a few key symptoms you may experience. If you notice one or more of the symptoms listed below, your PC may be infected with VirtuMonde or other malware. Continue reading below, or click here for a free malware scan.
Slow computer performance: It only takes one or two spyware parasites like VirtuMonde to cause your computer to slow dramatically. If your PC takes longer than usual to reboot or if your Internet connection is unusually slow, your computer may be infected with malware.
New desktop shortcuts or switched homepage: Malware like VirtuMonde may change your Internet settings or redirect your default homepage to another web site. Malware may even add new desktop shortcuts on your PC.
Annoying popups on your PC: Malware may bombard your computer with popup ads, even when you’re not online. Malware may stop your regular Internet activity and track your surfing habits and gather personal information about you, putting your financial and personal information at risk.
Understanding VirtuMonde & Spyware
If you’re infected with VirtuMonde and spyware, you should know what you’re fighting. I’ll explain some spyware definitions related to VirtuMonde.
VirtuMonde May Be Adware
What’s Adware?
Adware is software designed to promote advertisements. Adware may act without your authorization or knowledge. Often, free utilities may install hidden adware, sometimes to earn money for the author to recover development costs. While adware is not always malicious, it can track your Internet activity and send this and other personal information from your computer to advertisers. When advertisers get this information, you may be a target for pop-up/pop-under advertisements, web browser toolbars, and spam.
Some adware may also fall under the category of spyware. Spyware is any software or malware (”malicious software”) used to spy or track your computer activity. While some spyware is legitimately and intentionally installed by parents or employers to monitor Internet activity on a computer, spyware may be installed maliciously. Often spyware may come bundled with downloads of free software or come in the form of a cookie via a website, and this spyware may track your Internet activity or may steal secret account usernames and passwords, credit card numbers, and other personal and financial information.
To protect yourself specifically against adware, there is software designed to detect and remove adware from your PC with a few clicks of your mouse, such as Adware Remover.
VirtuMonde May Be a Key Logger
What’s a Key Logger?
Key loggers - or “keyloggers” or “keystroke loggers” - are software or spyware that record every keystroke you make typing on your PC. Some keyloggers are installed in order to capture your usernames and passwords, bank account numbers, credit card numbers, etc. Some keyloggers can take screen shots of your computer monitor and your activity, watch emails and your online chats, and more. Keyloggers are sometimes legitimately installed to monitor an employee’s or child’s computer activity. But even when keyloggers are installed without malicious reasons, keyloggers work secretly, without your knowledge.
Because of keyloggers stealth methods, keyloggers, even when installed without malicious reasons, may put your personal and financial information at risk. It may be a good idea to remove VirtuMonde and other keyloggers.
Some keyloggers may also fall under the category of spyware. Spyware is any software or malware (”malicious software”) used to spy or track your computer activity. While some spyware is legitimately and intentionally installed by parents or employers to monitor Internet activity on a computer, spyware may be installed maliciously. Often spyware may come bundled with downloads of free software or come in the form of a cookie via a website, and this spyware may track your Internet activity or may steal secret account usernames and passwords, credit card numbers, and other personal and financial information.
Keylogger Prevention
There are no easy ways to prevent keylogging from your computer. The best way to prevent being spied on through a keylogger is to use your common sense and some of the keylogger prevention methods below.
» Use Anti-Spyware Software: Most anti-spyware software is able to detect and remove keyloggers, whether the keylogger is commercial or not. It’s always a good idea to use anti-spyware software to regularly monitor your system for keyloggers and other spyware.
» Use a Firewall: Using a firewall can protect you and your computer from keyloggers that are spread maliciously through worms, viruses, and Trojans
» Monitor the Programs Your Computer Runs: Whether or not motivated by keylogger prevention, you should always watch which programs are installed on your PC and which are running regularly. If your computer is located in an area easily accessed by other people, watch for devices connected to your USB ports. Keyloggers may easily be installed this way.
» Use a Network Monitor: A network monitor will alert you whenever an application on your PC attempts to make a connection to the Internet. This can help you prevent the keylogger from contacting the anonymous attacker and sending him or her your personal information
» Automatic Form Fillers: Automatic form fillers, including those intergrated into your browser, can help prevent the damages of keylogging as the programs let you access sensitive accounts without typing your user information. In order for this to work, you’ll need to create passwords in a way that is invisible to keystroke logging and screenshots.
» Web-Based or On-Screen Keyboards: On screen keyboards, mostly used for financial websites, can help protect you from keyloggers stealing your username and passwords. In these web-based keyboards, you typically use your mouse clicks to “type” a password on an on-screen keyboard. It is still possible for a keylogger with a fast screenshot feature to capture this information.
Using the above methods can help protect you from keyloggers, but keyloggers can be almost impossible to detect. You may want to scan your PC for keyloggers regularly, especially if you share your computer with anyone or if it is in an area that may be accessed by other people.
VirtuMonde-Related Posts
VirtuMonde's Threat Level Explained
VirtuMonde Is a Minor Pest 
The parasite isn't a real threat, but VirtuMonde may track your Internet activities. VirtuMonde may be easily removed with your Windows system "Add/Remove" function.
VirtuMonde Is a Pest 
The parasite might profile you web activities and may have installed itself onto your PC via a drive-by download. You can probably manually remove VirtuMonde yourself.
VirtuMonde Is a Minor Threat 
The parasite might profile you and other users of your PC, and VirtuMonde may send this data back to its parent server.
VirtuMonde Is a Medium Threat 
The parasite might profile you and other users of your PC, and VirtuMonde may send this data back to its parent server. VirtuMonde may be impossible to manually remove.
VirtuMonde Is a Threat 
The parasite might profile you and other users of your PC, and VirtuMonde may send this data back to its parent server. VirtuMonde may download and install more malware onto your PC, and VirtuMonde may be impossible to manually remove.
VirtuMonde Is a Minor Danger 
The parasite may profile you, log every keystroke you make, and take snopshots of your computer activity. VirtuMonde may also be difficult to manually remove.
VirtuMonde Is a Medium Danger 
The parasite may profile you, log every keystroke you make, and take snopshots of your computer activity. VirtuMonde may download more malware and also be very difficult to manually remove.
VirtuMonde Is a Danger 
The parasite may profile you, log every keystroke you make, and take snopshots of your computer activity. These logs may be sent to anonymous attacker, and VirtuMonde may download more malware. VirtuMonde may be very difficult to manually remove.
VirtuMonde Is a Major Danger 
The parasite may track all of your computer activity, and VirtuMonde may allow a hacker to access your PC. VirtuMonde may pipe more malware into your computer, and may disable your anti-spyware or anti-virus software. VirtuMonde may be very difficult to manually remove.
VirtuMonde Is an Extreme Danger 
The parasite may track all of your computer activity, and VirtuMonde may allow a hacker to control your computer. VirtuMonde may pipe more malware into your computer, and may disable your anti-spyware or anti-virus software and firewall, and block your access to anti-spyware sites. VirtuMonde may be very difficult to manually remove.




July 14th, 2007 at 11:45 pm
I’ve been using Norton, Ad-Aware, and Spybot, and the only one that actually catches VirtuMonde is Spybot. But the problem is, after I remove it using spybot, when I run a scan, it still says it’s there. Am I just getting re-infected with it between when I remove it and when I scan for it? If so it’s strange that I’m so vulnerable even though I have firewall and Norton Auto-Protect on, and I’m wondering if there’s a way to prevent myself from getting infected again?
February 8th, 2008 at 7:13 pm
Ha ! I did a full format and somehow virtumonde survived. But I did not clean some of the old files. Maybe I should try it again.
February 9th, 2008 at 10:48 am
I have Virtumonde. I run Spybot daily. It finds Virtumonde and I tell it to remove it. If I rerun the scan immediately it is not there, but if I do anything else it comes back. I have also run the Symantec Virtumonde removal tool (before removing it with Spybot) and it says that my computer is not infected. I also run Adaware, but I’m not sure it finds it. My symptom is excessive popups, which have made Netscape Navigator unusable. I’ve switched to Firefox, which is much better, but still has occasional problems. My problems seem to be the same as Nick in the previous response.
April 18th, 2008 at 3:39 pm
despite running adware and spybot several times i could not get rid of virtumond dll,third time lucky but kept coming back so looked in my computer then in programme files found that it had created a filein programmes deleted it and no more trouble
June 1st, 2008 at 2:26 pm
I went for the manual removal after having Spybot do a search. I found a virtumonde .dll file but when I type in - regsvr32/u byXOijih.dll I get the message “byXOijih.dll was loaded, but the DllUnregisterServer entry point was not found. This file can not be registered”. And so it lingers
June 3rd, 2008 at 3:57 pm
I work with virutmonde every day and many different varieties of it. Everything from the easy to remove kind with removal programs, some that associate with installed programs(xpAntivirus, winfixer, etc) , and the worst that recreate them selves into personal settings, system rundll files and, chkdsk check sum. Every time I think I’ve got it figured out it comes back. The latest and most difficult is the check sum and I am currently working on it. I have yet to find one solid guarantee technique to work on all versions. I will repost after I try this technique on all versions I run accross.
August 11th, 2008 at 1:08 pm
Thanks for the tutorial!!! Time will tell, but if these fixes work I would like to donate to whoever posted this. I prefer not to invest in software, as it continually changes and I end up with multiple outdated tools fighting for the same resources–I’d rather run a tight system and fix issues as they arise. If you could supply me with a paypal address for donations, I’d appreciate it. Again, thanks for all the good work!
August 29th, 2008 at 5:40 pm
HEy, lets put up a price on the criminal’s heads who make Virtumonde (the legal way). Some techi geeks may turn them in or hunt them down. Also, some of them may decide to stop writing them if it gets too dangerous. Maybe they go back to video games. Nothin’ wrong with video games! How about $5,000? I think we’d hv to talk to some police about the whole process. If 1 hundred of us put up $50 we can do it. It would hv to be placed in n escrow account for group control. I’ll check on the details like how much time they would get, etc. Time by the way, AWAY from their computer. They’d go mad. THey wouldn’t know WHAT to do. That and the prison food, attitude, and the views may not be so inviting.
October 2nd, 2008 at 12:41 am
I FINALLY got rid of virtumonde with Spysweeper. Finally killed Virtumonde!! and removed it, no more annoying IE pages opening randomly. (I’ll give it a few days to make sure) This creepy thing disabled Spybot search and destroy’s ability to remove it as well as AVG. they could identify it , quarantine it , and then it was BAAAAck. I couln’t install Mcaffee either, and norton didn’t detect it. So I am now using AVG in combo with Spy Sweeper by Webroot, and I am going toB Beta demo their virus software as well. I have used Norton for years, and was disappointed that Virtu managed to disable it, which let other viruses in as well. Thanks for this site. I found it on google, just to see how others were doing with this thing, once I had identified it.
November 17th, 2008 at 1:33 pm
the guys who made this program were so you buy their product, personnally i think they should be shot…If i knew who it was and they lived in my town I would personally take care of them!! because they cause us alot of grief for profit…bastards