Spybot said it got rid of it but kept coming back after reboot. I ran Combofix as described in the tutorial provided by bleepingcomputer.
I got rid of a lot more things than spybot did. lots more dll's and ini's ect. But trojan was still there when I ran spybot.
I had to manually delete additional dll's in my windows\system32 folder in recovery mode due to access denied issues.
The file names i deleted were ...
There are probably a few people in the world that can appreciate clever coding and I am one of them. Whoever came up with this virtumode trojan definitely knew there stuff. very impressive trojan it just would not go away. Though I would like to kick that person in the jaw for writing the thing it was impressive nonetheless.
I ran spybot one more time to clear out any remaining registry entries and misc files it found pertaining to virtumonde.
Rebooted and ran spybot oncemore for good measure and it appears to be finally gone.
Also congrats to whoever wrote combofix (just as impressive as virtumode itself) it did well minus the few deletions i made manually and some help from spybot. But that can prolly be tweaked in time. This things seems to mutate everyday.
i'll post my combofix log for anyones reference.
Thanks bleepingcomputer and combofix
Edited by samino_the_basenji, 22 July 2008 - 11:17 AM.