1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved more Virtumonde trouble

Discussion in 'Malware and Virus Removal Archive' started by Blitzkrieg, 2008/10/10.

  1. 2008/10/27
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi
    Ok good. How are things running.

    Now lets clean up.

    Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    Now close all windows other than HiJackThis, then click Fix Checked.

    Close HJT.


    Click Start > Run in the run box copy and paste or type ComboFix /u then hit Enter to uninstall ComboFix and remove the files/folders it created. This action will also reset the System Restore points, removing any infected files there as well.
    Please check and verify that C:\Qoobox and C:\ComboFix folders were removed, as well as the C:\ComboFix.txt file.

    You can Delete RSIT.exe and this folder. C:\rsit.

    Let me know how things are running.

    Thanks
    Geri
     
  2. 2008/11/06
    Blitzkrieg

    Blitzkrieg Inactive Thread Starter

    Joined:
    2008/07/22
    Messages:
    16
    Likes Received:
    0
    Just completed the last tasks.

    Things are running great, thanks so much for your help Geri! :D
     

  3. to hide this advert.

  4. 2008/11/08
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi
    OK that's great to hear.

    Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Now close all windows other than HiJackThis, then click Fix Checked.

    Close HJT.


    Please look at this link for some preventive recommendations, It could keep you from ending up back here to the Malware and Virus Removal Forums.
    http://www.windowsbbs.com/showthread.php?t=67958

    I'll mark this one resolved.

    Surf Safely.
    Geri
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.