BarryC
01-28-2008, 10:32 PM
This computer I'm borrowing right now is infected with something called virtumonde.dll. It's terrible, and nearly impossible to get rid of.
This computer has Spyware Blaster, and Spybot- Search & Destroy, which has some prevention, like Spyware Blaster. Very little that's bad ever gets through. But a couple weeks ago a whole bunch of stuff broke through the defenses, all at once, including a bunch of virtumonde stuff. One thing was called Malware Alarm and another I think was called OIC or something. I forget the full name. All of the stuff was easily removed, including all of the virtumonde stuff except one dll file. But with that one file running, all the other stuff kept coming back. (Although now it's all gone except for the one virtumonde file.)
It's called Virtumonde.dll, but the actual file name is different than that, and it renames itself from time to time. Last I checked it was rqonk.dll. It's located in C:\WINNT\system32.
I also have Adaware SE, Hijack This and Registry Mechanic, which really is not the same thing. Only Hijack This, and Spybot- Search & Destroy will find the dll file. The other programs won't find it. But it seems to be undeletable anyway. Besides that, Spybot- Search & Destroy takes 2 hrs., 50 min. to run on this computer! It's terrible.
Okay, now that you know all that, I've tried a few things to get rid of it. First I downloaded a program that's made specifically for getting rid of all virtumonde files. Unfortunately no matter how many times I ran it, it never even found any of the virtumonde files. One time I ran Adaware SE after running that other program (which told me there weren't any virtumonde files on this computer). Adaware found 17 files, although it didn't, and never did, find the virtumonde.dll file. Okay, so I deleted that program since it was useless. I also downloaded Spy Hunter, which purported to get rid of virtumonde infections, but it never found that one dll file. (But it did find other bad stuff that nothing else has found.)
Then I read this page: http://www.safer-networking.com/removeVirtuMonde.php , where I found that you can "un-register" the dll files. But every time I tried, I got an error message that said something about the unregister server is offline, or malfunctioning, or something. Then finally, I discovered that with Hijack This, you can order Windows to delete a file at startup, but even then it wouldn't delete that one file!
Right now the file seems to be doing nothing except slowing the system down. Right now while I've been typing this message everything has frozen a couple of times so far. But I can usually get things to free up again when that happens. When the file is more active I get re-directs, especially after clicking on search results, but sometimes other times too.
So I'm desparate to find a way to get rid of this file. It's driving me up a wall.
Please help.
Thanks,
Barry
This computer has Spyware Blaster, and Spybot- Search & Destroy, which has some prevention, like Spyware Blaster. Very little that's bad ever gets through. But a couple weeks ago a whole bunch of stuff broke through the defenses, all at once, including a bunch of virtumonde stuff. One thing was called Malware Alarm and another I think was called OIC or something. I forget the full name. All of the stuff was easily removed, including all of the virtumonde stuff except one dll file. But with that one file running, all the other stuff kept coming back. (Although now it's all gone except for the one virtumonde file.)
It's called Virtumonde.dll, but the actual file name is different than that, and it renames itself from time to time. Last I checked it was rqonk.dll. It's located in C:\WINNT\system32.
I also have Adaware SE, Hijack This and Registry Mechanic, which really is not the same thing. Only Hijack This, and Spybot- Search & Destroy will find the dll file. The other programs won't find it. But it seems to be undeletable anyway. Besides that, Spybot- Search & Destroy takes 2 hrs., 50 min. to run on this computer! It's terrible.
Okay, now that you know all that, I've tried a few things to get rid of it. First I downloaded a program that's made specifically for getting rid of all virtumonde files. Unfortunately no matter how many times I ran it, it never even found any of the virtumonde files. One time I ran Adaware SE after running that other program (which told me there weren't any virtumonde files on this computer). Adaware found 17 files, although it didn't, and never did, find the virtumonde.dll file. Okay, so I deleted that program since it was useless. I also downloaded Spy Hunter, which purported to get rid of virtumonde infections, but it never found that one dll file. (But it did find other bad stuff that nothing else has found.)
Then I read this page: http://www.safer-networking.com/removeVirtuMonde.php , where I found that you can "un-register" the dll files. But every time I tried, I got an error message that said something about the unregister server is offline, or malfunctioning, or something. Then finally, I discovered that with Hijack This, you can order Windows to delete a file at startup, but even then it wouldn't delete that one file!
Right now the file seems to be doing nothing except slowing the system down. Right now while I've been typing this message everything has frozen a couple of times so far. But I can usually get things to free up again when that happens. When the file is more active I get re-directs, especially after clicking on search results, but sometimes other times too.
So I'm desparate to find a way to get rid of this file. It's driving me up a wall.
Please help.
Thanks,
Barry