VirtuMundo manual removal:
Kill processes:
sysupd.exe, windowsupd1.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\SysUpd
HKEY_CURRENT_USER\Software\Microsoft\WindowsUpd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\SysUpd
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\WindowsUpd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysUpd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\WindowsUpd
Delete files:sysupd.exe, windowsupd1.exe
Post Comment:
Attention: Use this form only if you have additional information about VirtuMundo parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Comments from visitors:
1. by Guest. 2006-09-03 11:09:15
janbillb2@aol.com
Thanks in advance
HKLMsoftwarewindowscurrentversion
should actually read:
HKLMsoftwaremicrosoftwindowscurrentversion
Sorry for any confusion there.
P.S. It took me the better part of a day to find out how to get rid of this thing. I should never have needed to but my AV company Computer Associates (e-trust) refuses to call this a virus. They bought an anti-spyware comapny in August '04 and now want you to buy that product to get rid of it.
Go figure!
HKEY_LOCAL_MACHINE
SOFTWARE
But no registry file under those two simply called "windows". I have "windows 3.1 migration status" but that's not it. No other files called or starting with windows under HKLM/SOFTWARE.
Any thoughts? Thanks!
I've been bothered by VirtuMonde for some time, tried many things, Norton can't delete it, Ad-Aware can't delete it, almost going to reinstall my PC. Luckily I found this post, and followed the instruction here, and it works.
Even though the files were not listed here, but i want to say "Thank You Very Much" to you, number 4 post.
I read a comment made by another user that the files name was not windowsupd or the variations listed.
It may or may not be Virtumonde but it is a nasty bugger to get rid of.
Do the following exactly or it will come back to haunt you.
Open regetit and backup the registry (just in case)
Go to HKLMsoftwarewindowscurrent versionrunonce
There will be an entry starting with an asterisk *
The data section will point to a file on your system.
Find that file, right click, Properties, security.
Remove all access to the file. The users list needs to be blank or it won't work. If you have inherited permissions uncheck that and when you are asked to copy or remove just click remove.
Now save these changes by clicking OK all the way out.
Reboot.
Ok the virus is now inactive so you have to do the cleanup.
Open regedit go back to HKLMsoftwarewindowscurrent version and look under all the RUN keys (run, runonce, runex, etc) delete all entries that start with an *.
Now go back to the original file you removed access to and add yourself to the access list with full control.
Save changes and then delete file and empty recycle bin.
You should now be clean of the virus.
certified pc technician