I have been running Ad-Aware and Spybot and have eliminated 90% of spyware. However, I continually get Virtumundo in two Register Keys and Values according to Ad-Aware. In the log it says:HKey_Classes_Root:atlevents.atlevents.1\ There are 2 register keys and 2 values. I quarantine them and at the next re-boot it appears again. According to Ad-Aware the threat level is low, however it also says "no uninstaller.Bundled install that is undisclosed, may cause system instability. opens unsolicited websites. " This has not happened. How to get rid of these things or do I just ignore it? I understand very little about computers. Thank you. On Spybot I did get something called Atlevents. Also DSO exploits constantly appears.
click on the link "Essential spyware removal steps and other hijackthis help forums" below and follow all the instructions (Step 1-5) and post the hijackthis log after reading (Instructions a/b/c) and downloading/running all the programs mentioned there alongwith the Online anti-virus scans .Update all the programs ie spybot,adaware before logging into safe more to run it .
What you have on your PC is VirtuMonde Adware.
Symantec has just produced a removal tool, so follow these instructions to run it, you may find it helpful to print them out.
*Sometimes this will fix the problem, and sometimes not, but it is worth a try.
Follow these steps to download and run the tool:
1. Download the FixVundo.exe file from: http://securityresponse.symantec.com/avcenter/FixVundo.exe
2. Save the file to a convenient location, such as your Windows desktop.
3. Optional: To check the authenticity of the digital signature, refer to the "Digital signature" section later in this writeup.(No need for this step, I've authenticated it already)
4. Close all the running programs.
5. If you are on a network or if you have a full-time connection to the Internet, disconnect the computer from the network and the Internet.
6. If you are running Windows Me or XP, turn off System Restore. Do Start->Control Panel->System, System restore. Check "Turn off System Restore" and reboot.
7. Locate the file that you just downloaded.
8. Double-click the FixVundo.exe file to start the removal tool.
9. Click Start to begin the process, and then allow the tool to run.
Important: Do not launch any new applications while the tool is running.
10. Restart the computer.
11. Run the removal tool again to ensure that the system is clean.
12. If you are running Windows Me/XP, then re-enable System Restore.(Check the box)
13. If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection.
Regarding Spybot's finding those 5 DSO Exploits, there is a bug in the program.
The DSO Exploit is a security gap in IE. Microsoft did already repair this, so if you have all Windows updates and patches installed, it will not be dangerous for your system. Spybot S&D will still find it, because it contains an invalid value. Spybot S&D just has to reset that value. Unfortunately, in the current version, it sets again an incorrect value, so it is found in the next scan. Please update your main program.
For download please use one of the mirrors nearest you from major geeks.
http://www.majorgeeks.com/download4392.html
SpyBot-Search & Destroy 1.3 Final MUST be installed before this update will work properly.
When Spybot opens after the update, it will be version 1.3.1TX.
Don't forget to post an updated HJT log as instructed by jamez kann above.
thank you to all who have helped regarding the Virtumunde in HKey. I have finally gotten rid of it! I also have installed ZoneAlarm and AVG and have them running. All viruses are gone as of today. However, I followed directions as best as I could because I really didn't understand them. Now if my dial-up would just stop disconnecting! I think I will have to go to broadband because I was disconnected more than five or six times when I was downloading the virus scan program and the firewall. If only Microsoft would have well spoken representatives without accents, it would be much better for all to understand.
jamez kann
2 Intern
•
860 Posts
150
0
Posted November 25th, 2004 13:00
click on the link "Essential spyware removal steps and other hijackthis help forums" below and follow all the instructions (Step 1-5) and post the hijackthis log after reading (Instructions a/b/c) and downloading/running all the programs mentioned there alongwith the Online anti-virus scans .Update all the programs ie spybot,adaware before logging into safe more to run it .