I'm having the same problem as many others getting rid of virtumonde. I've used AVG virus scan, Malwarebytes and Spybot, all of which detect and 'fix' the problem but it immediately reappears. Ad-aware started crashing during scans about the same time this problem started. I run Windows XP x64 and apparently ComboFix is incompatible. The problem started when AVG detected a virus and I started getting hijack pop-ups in Firefox. I immediately used my tools and haven't had any problems. The only symptom now is is a RunDLL error on startup. I ran Malwarebytes in safe mode and the next bootup was fine, however the bad command line was immediately found in the registry.
I'll post any log files on request but here are the error findings:
Hijack this:
O4 - HKLM\..\Run: [tozenedumu] Rundll32.exe "C:\WINDOWS\system32\mepawadi.dll",s
Malwarebytes:
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tozenedumu (Trojan.Vundo.H) -> Quarantined and deleted successfully
Spybot:
Virtumonde.prx: [SBI $3F5CA9DA] Autorun settings (tozenedumu) (Registry value, fixed) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tozenedumu
Thanks.