Virtumonde VIRUS.. More than a Pop-Up

xguntherc

I Click Home To Much
Vista Guru
Hey Guys. My brothers computer has this... Not sure what the crap he does wrong. but this is the second Virus he's got in the last 6 months. It's probably myspace's fault.

Anyways. I looked up all the info about the Virtumonde virus/trojan and everywhere I read said it's a virus that's more of a popup.. it's an ad crapper.. sends you hundreds of ad's and stuff of that sort. and that it can attach to IE and record your keystrokes and all that. but my brother doesn't have this problem.

My brothers problem with this Virtumonde virus. It's starting WITH Windows and completely locks him out of the system.

During Boot, it's all fine, enters password. and see's background picture. then it covers the screen saying Virus detected and says what it is. and can't do ANYTHING. nothing works from there. I've tried cntl, alt, del. I've started in Safe Mode. only for it to stop with safe mode written in all 4 corners and do nothing.

I'm not the smartest person on virus's and stuff of this sort. I'm a gamer, and a builder, and Overclocker. not a Tech that can fix viruses.

Any help or idea's would be great.. Preferably for free.. if I have to I'll just reinstall windows on his system. (XP) He doesn't have anything really he'd miss on that hard drive. just a few programs, Ventrillo and such.

Let me know what you all think. Thanks!
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics Card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Keyboard
    Logitech G11
    Mouse
    Logitech MX-518
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB.

    Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
Save yourself the time and effort and just reformat, this time making sure he has adequate antivirus and malware protection ;)
 

My Computers

System One System Two

  • Operating System
    Windows 11 Workstation
    Manufacturer/Model
    doofenshmirtz evil incorporated
    CPU
    Ryzen 9 5950X
    Motherboard
    Asus ROG Crosshair VIII Formula
    Memory
    Corsair Vengeance RGB PRO Black 64GB (4x16GB) 3600MHz AMD Ryzen Tuned DDR4
    Graphics Card(s)
    ASUS AMD Radeon RX 6900 XT 16GB ROG Strix LC OC
    Sound Card
    Creative
    Monitor(s) Displays
    3 x27" Dell U2724D & 1 x 34" Dell U3415W
    Hard Drives
    Samsung 980 Pro 1TB M.2 2280 PCI-e 4.0 x4 NVMe Solid State
    Drive
    PSU
    1500W ThermalTake Toughpower
    Case
    ThermalTake Level 10 GT
    Cooling
    Enermax Liqtech 240
    Keyboard
    Surface Ergonomic.
    Mouse
    Logitech Performance MX
    Internet Speed
    350 Mb/s
    Other Info
    WinTV NovaTD
    HP CP1515n Color Laser
    Sony BD-5300S-0B Blu-ray Writer
    Microsoft LifeCam Cinema
    APC 750i Smart UPS
  • Operating System
    windows 10
    Manufacturer/Model
    Surface Pro 3
    CPU
    1.9GHz Intel Core i5-4300U (dual-core, 3MB cache, up to 2.9GHz with Turbo Boost)
    Memory
    4GB
    Graphics card(s)
    Intel HD Graphics 4400
    Monitor(s) Displays
    12" Multi Touch
    Screen Resolution
    2160 x 144
    Hard Drives
    128GB
    Mouse
    Logitech
    Keyboard
    yes
    Internet Speed
    350 Mb/s
The symptoms you describe gives me a sense of Deju Vu of a virus I had to deal with several months ago. It's one of those "fake" antivirus trojans that integrate themselves into everything, and try to bait you into buying it, and causes havoc if you do nothing.
I agree with z3r010 on this one. Reformat the system.
 

My Computer

System One

  • Manufacturer/Model
    Custom Build
    CPU
    AMD Phenom 9600 Quad
    Motherboard
    ASUS MB-M3A32-MVP Deluxe/WiFi
    Memory
    2 x A-Data 2GB DDR2-800
    Graphics Card(s)
    ASUS ATI Radeon HD 2400PRO
    Monitor(s) Displays
    SAHARA 21"
    Screen Resolution
    1600x1200
    Hard Drives
    2 x 80GB Seagate (I)
    2 x 120GB Seagate (I/S)
    2 x 200GB Seagate (I/S)
    2 x 250GB Seagate (I/S)
    PSU
    800W
    Case
    Thermaltake Tai-Chi
    Cooling
    Tai-Chi Water Cooler
    Keyboard
    Genius
    Mouse
    Logitech
    Internet Speed
    384kbps
    Other Info
    Currently dual booting between Vista x64 Ultimate Windows 7 BETA x64
Ya thats what I think I'll do. Simple and just a startover.

Nice and easy..

Also he uses what I use.. and think is one of the BEST.. Eset NOD32.. I love it. We have the best they have to offer. but he said his wife turned it off because she said she closed the Icon down by the "Time" as she didn't know what the "EYE" was.. thats there Icon.. haha

Thats a VERY VERY Big no-no. and I'll make sure I tell him and his wife to leave that SHIZZZ alone!

Big mistake on her part. as I think thats what caused this. I love my NOD32.

thanks for the thought guys. I'll just reformat!
 

My Computer

System One

  • CPU
    Q9650 E0 4.0 GHz @1.304v
    Motherboard
    eVGA 750i FTW
    Memory
    2x2GB Corsair Dominator PC2-8500C5D
    Graphics Card(s)
    eVGA/MSI GTX 260 SLI
    Sound Card
    X-Fi XtremeGamer
    Monitor(s) Displays
    Samsung T240 & 226BW
    Screen Resolution
    1920x1200 & 1680x1050
    Hard Drives
    Seagate Cuda 500GB 32mb Cache SATA 7200.(11) + 500GB Seagate Cuda External eSATA, USB, FW400
    PSU
    PC P&C 750w Silencer PSU
    Case
    CoolerMaster HAF 932 (Water-Cooled)
    Cooling
    Plenty of Fans, and a few 230mm Fans
    Keyboard
    Logitech G11
    Mouse
    Logitech MX-518
    Other Info
    ASUS 20x Optical, Bose Companion 3, ATH-AD500 Cans :), Patriot Xporter 16GB Flash Drive (Very Fast), & Sandisk Micro 8GB.

    Nikon D40 DSLR with 18-105mm VR & 55-200mm VR
Ya thats what I think I'll do. Simple and just a startover.

Nice and easy..

Also he uses what I use.. and think is one of the BEST.. Eset NOD32.. I love it. We have the best they have to offer. but he said his wife turned it off because she said she closed the Icon down by the "Time" as she didn't know what the "EYE" was.. thats there Icon.. haha

Thats a VERY VERY Big no-no. and I'll make sure I tell him and his wife to leave that SHIZZZ alone!

Big mistake on her part. as I think thats what caused this. I love my NOD32.

thanks for the thought guys. I'll just reformat!

Believe me when I say this, but I don't usually recommend a reformat as my first advice. If you just blindly reformat, you rob yourself of the opportunity to learn something new. Reformatting is always the absolute LAST resort.

But I'm familiar with this particular virus (or something similar to it, anyway), and even if you somehow do manage to get rid of it and "stabilize" the system, you're going to end up reformatting anyway, because you whould not have fully gotten rid of the virus and it'll just keep coming back, no matter what you do. It's a tenacious bugger.
 

My Computer

System One

  • Manufacturer/Model
    Custom Build
    CPU
    AMD Phenom 9600 Quad
    Motherboard
    ASUS MB-M3A32-MVP Deluxe/WiFi
    Memory
    2 x A-Data 2GB DDR2-800
    Graphics Card(s)
    ASUS ATI Radeon HD 2400PRO
    Monitor(s) Displays
    SAHARA 21"
    Screen Resolution
    1600x1200
    Hard Drives
    2 x 80GB Seagate (I)
    2 x 120GB Seagate (I/S)
    2 x 200GB Seagate (I/S)
    2 x 250GB Seagate (I/S)
    PSU
    800W
    Case
    Thermaltake Tai-Chi
    Cooling
    Tai-Chi Water Cooler
    Keyboard
    Genius
    Mouse
    Logitech
    Internet Speed
    384kbps
    Other Info
    Currently dual booting between Vista x64 Ultimate Windows 7 BETA x64
Thanks for the heads up on this guntherc and Dzomlija. Not that I've come across it, touch wood, but it helps to know what to do!
 

My Computer

System One

  • Manufacturer/Model
    Scratch Built
    CPU
    Intel Quad Core 6600
    Motherboard
    Asus P5B
    Memory
    4096 MB Xtreme-Dark 800mhz
    Graphics Card(s)
    Zotac Amp Edition 8800GT - 512MB DDR3, O/C 700mhz
    Monitor(s) Displays
    Samsung 206BW
    Screen Resolution
    1680 X 1024
    Hard Drives
    4 X Samsung 500GB 7200rpm Serial ATA-II HDD w. 16MB Cache .
    PSU
    550 w
    Case
    Thermaltake
    Cooling
    3 x octua NF-S12-1200 - 120mm 1200RPM Sound Optimised Fans
    Keyboard
    Microsoft
    Mouse
    Targus
    Internet Speed
    1500kbs
    Other Info
    Self built.
I would take out the HDD, put it in another computer and boot from a different HDD and then do a virus scan of the infected HDD. It wont necessarily fix your problem but you will be able to see how many files are infected.

More of a learning thing because in the end you will have to format anyway.
 
Last edited:

My Computer

System One

  • Manufacturer/Model
    Custom Build
    CPU
    E6750 @ 3.6GHz
    Motherboard
    Gigabyte P35 DS3
    Memory
    4GB 8500C5D
    Graphics Card(s)
    POV GTX285
    Sound Card
    Onboard
    Monitor(s) Displays
    19" Widescreen LG
    Screen Resolution
    1400x900
    Hard Drives
    2 x WD 500G
    PSU
    Coolermaster Silent Pro 700M
    Case
    Antec 900
    Cooling
    Tuniq Tower 120 LFB
    Keyboard
    Logitech EX110
    Mouse
    Logitech MX400
    Other Info
    Graphics Driver - 190.38
I had it. After a week of fighting with it. I backed up my data and reinstalled. I used 10 different programs. It could not remove every component of Virtumonde. It was easier to backup the data and reinstall.
 

My Computer

System One

  • CPU
    pair of Intel E5430 quad core 2.66 GHz Xeons
    Motherboard
    Supermicro X7DWA-N server board
    Memory
    16GB DDR667
    Graphics Card(s)
    eVGA 8800 GTS 640 MB video card
    Hard Drives
    SAS RAID
Yeah good choice. On my old computer i got the ad version of Virtumonde however i did not have the internet so every 15-30 minutes a message would come up asking me whether or not i would like to go into Offline Mode (yes in those days i didn't know Firefox existed.) Spybot fixed my problem but in the end (several weeks later) the stupid software DEP locked me out (wouldn't let me get to the login screen) so i had to format anway.
 

My Computer

System One

  • Manufacturer/Model
    Custom Build
    CPU
    E6750 @ 3.6GHz
    Motherboard
    Gigabyte P35 DS3
    Memory
    4GB 8500C5D
    Graphics Card(s)
    POV GTX285
    Sound Card
    Onboard
    Monitor(s) Displays
    19" Widescreen LG
    Screen Resolution
    1400x900
    Hard Drives
    2 x WD 500G
    PSU
    Coolermaster Silent Pro 700M
    Case
    Antec 900
    Cooling
    Tuniq Tower 120 LFB
    Keyboard
    Logitech EX110
    Mouse
    Logitech MX400
    Other Info
    Graphics Driver - 190.38
Back
Top