win32/adware.virtumonde.fp

Discussion in 'NOD32 version 2 Forum' started by gidon, Aug 16, 2007.

Thread Status:
Not open for further replies.
  1. gidon

    gidon Registered Member

    Joined:
    Aug 16, 2007
    Posts:
    2
    Hello,

    I have a virus in my operating memory in c/windows/system32/vtsqr.dll

    I don't know what to do, i cannot erase this file and it is making havoc on my computer many other .dll files in system32 are also being infected.

    What should I do??
     
  2. flyrfan111

    flyrfan111 Registered Member

    Joined:
    Jun 1, 2004
    Posts:
    1,229
    Run a scan in safe mode.
     
  3. gidon

    gidon Registered Member

    Joined:
    Aug 16, 2007
    Posts:
    2
    How do I change the settings to safe mode?
    Should I delete the .dll if I am asked to?
     
  4. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Hi there, welcome to Wilders.

    Please complete the instructions located HERE

    Cheers :D
     
  5. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Basicly all you need to do is download, extract and run this Undll tool. Then browse for the dll found by NOD32 and eventually restart the computer.
     
  6. sparx

    sparx Registered Member

    Joined:
    Jan 10, 2007
    Posts:
    60
    VundoFix is also a really great utility for clearing out Virtumonde infections.
     
  7. ASpace

    ASpace Guest

    Yes , running Vundofix is part of Blackspear's instructions (they are even Sticky) . See post #4 :)
     
  8. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Vundofix is a 3rd party tool not made by Eset. We (Eset) recommend that you use Undll.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.