VirtuMonde Removal Guide
Do you know what VirtuMonde is?
DESCRIPTION
VirtuMonde (also referred to as Vundo, Vundo Trojan and VirtuMundo) is a spyware program that creates a Dynamic Link Library, which is reported to record your keystrokes and randomly displays advertisements. By doing this, it stays memory resident, checking if VirtuMonde is being ran, if not, it launches it again. Additionally, it harvests users’ information about their connection, pages viewed and applications installed. VirtuMonde also writes cookies to track browsing behavior and may visit various Internet sites.
VirtuMonde also downloads other software from various remote servers with or without your knowledge and consent.
While having the VirtuMonde you will notice a slight or large amount of memory being used randomly throughout the day. VirtuMonde will make false pop-ups appear informing you that the system is infected and that your performance is deteriorating. In order to solve this, you are supposed to download the program.
In some cases VirtuMonde has altered Administrative rights of machine Owners, and prevented them from downloading effective anti-spyware programs.
Non-Techie terms: Spyware makers create programs like VirtuMonde to extort money from you. VirtuMonde does not detect spyware. VirtuMonde is the spyware you should avoid and not give out any personal information.
VIRTUMONDE OVERVIEW
Name: VirtuMonde
Type: Rogue Anti-spyware program
VirtuMonde Automatic Removal Instructions
VirtuMonde Manual Removal Instructions
This manual removal method is for techie computer users. VirtuMonde manual removal may be difficult and time consuming to remove. There’s no guarantee that VirtuMonde will be removed completely. So read the VirtuMonde removal steps carefully and good luck.
Before you start: Close all programs and Internet browsers. Also back up your computer in case you make a mistake and your computer stops working.
- Uninstall VirtuMonde Program
Click on Start > Settings > Control Panel > Double-click on Add/Remove Programs. Search for and uninstall VirtuMonde v.3.8 if found.
- To stop VirtuMonde processes (view process removal steps)
Go to Start > Run > type taskmgr. The click the Processes tab and you’ll see a list of running processes.
Search and stop these VirtuMonde processes:
Nero_Burning_Rom_Ultra_Edition_6.6.0.6_serial_number.txt[1].exe
Windows_XP_SP2_Professional_Edition_Corporate_serial_number.txt[2].exe
ces005dr.exe
nnx22011.exe
kopCFEWV.exe
castlecops[1].exe
unknown.exe
svci.exe
psdrv.exe
rasrun.exe
nwonknu.exe
editpad.exe
quicken.exe
winhost.exe
editpad.exewindowsupd2.exe
quicken.exe
winhost.exe
windowsupd2.exeFor each unwanted process, right-click on it and then select “End task”.
- To Unregister VirtuMonde DLLs (view DLL removal steps)
Search and unregister these VirtuMonde DLLs:
awtttqr.dll
mljjk.dll
bndsrsqo.dll
awtqopm.dll
geeby.dll
jiinhuyb.dllTo locate the VirtuMonde DLL path, go to Start > Search > All Files or Folders. Type VirtuMonde and in the Look in: select either My Computer or Local Hard Drives. Click the Search button.
Once you have the VirtuMonde DLL path, go to Start and then click on Run. In the Run command box, type cmd, and then click on OK.
To locate the exact DLL path, type cd in order to change the current directory. To display the contents of the directory, use the dir command. To remove the DLL file type regsvr32 /u FILENAME.dll (FILENAME is the name of the file that you want to unregister).
- To unregister VirtuMonde registry keys (view registry keys removal steps)
Go to Start > Run > type regedit > press OK.
Edit the value (on the right pane) by right-clicking on it and selecting the Modify option. Select the Delete option.
Search and delete these VirtuMonde registry keys:
- If your homepage has been changed, go to Start > Control Panel > Internet Options > click on the General > click Use Default under Home Page. Add the your desired default homepage, then click Apply > click OK. Open a new web browser to check that you have your desired default homepage.
- Remove VirtuMonde Directories.
To find VirtuMonde directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.
Search and delete the following AntiVirGear directories:
awtttqr.dll
mljjk.dll
bndsrsqo.dll
awtqopm.dll
geeby.dll
jiinhuyb.dllRight-click on the AntiVirGear folder and select Delete.
A message will appear saying ‘Are you sure you want to remove the folder [NAME OF FOLDER] and move all its contents to the Recycle Bin?’, click Yes.
Another message will appear saying ‘Renaming, moving or deleting [FOLDERNAME] could make some programs not work. Are you sure you want to do this?’, click Yes.
- To remove VirtuMonde icons on your Desktop, drag and drop them to the Recycle Bin.
You’ve completed the VirtuMonde manual removal instructions!
I hope this article has helped you solve your VirtuMonde problems. If you want to contribute to this article, post your comment below.
Disclaimer: This article is for educational purposes. By using this information you agree to be bound by the disclaimer. There’s no guarantee that VirtuMonde will be completely removed from your computer. Seek professional help if your computer continues to experience problems.
VirtuMonde Removal Guide Automatic Removal Instructions
VirtuMonde Manual Removal Instructions
This manual removal method is for techie computer users. VirtuMonde manual removal may be difficult and time consuming to remove. There’s no guarantee that the infection will be removed completely. So read the removal steps carefully and good luck.
Before you start: Close all programs and Internet browsers. Also back up your computer in case you make a mistake and your computer stops working.
- Uninstall VirtuMonde Program
Click on Start > Settings > Control Panel > Double-click on Add/Remove Programs. Search for and uninstall the infection if found. - To stop VirtuMonde processes (view process removal steps)
Go to Start > Run > type taskmgr. The click the Processes tab and you’ll see a list of running processes.
Search and stop these processes:
1014[1].exe
is[1].exe
psdrv.exe
svci.exe
asd0.exe
winhost.exe
FreeApp[1].exe
rasrun.exe
nwonknu.exe
castlecops[1].exe
For each unwanted process, right-click on it and then select “End task”. - To Unregister VirtuMonde DLLs (view DLL removal steps)
Search and unregister these DLLs:
vhsttu.dll
bkcosq.dll
inlvolhc.dll
geebc.dll
flojedot.dll
xkhcunoe.dll
eynrdxpd.dll
jtrwal.dll
temlxopqgdk.dll
jdpfjwgb.dll
To locate the DLL path, go to Start > Search > All Files or Folders. Type VirtuMonde and in the Look in: select either My Computer or Local Hard Drives. Click the Search button.
Once you have the DLL path, go to Start and then click on Run. In the Run command box, type cmd, and then click on OK.
To locate the exact DLL path, type cd in order to change the current directory. To display the contents of the directory, use the dir command. To remove the DLL file type regsvr32 /u FILENAME.dll (FILENAME is the name of the file that you want to unregister). - To unregister VirtuMonde registry keys (view registry keys removal steps)
Go to Start > Run > type regedit > press OK.
Edit the value (on the right pane) by right-clicking on it and selecting the Modify option. Select the Delete option.
Search and delete these registry keys: - If your homepage has been changed, go to Start > Control Panel > Internet Options > click on the General > click Use Default under Home Page. Add the your desired default homepage, then click Apply > click OK. Open a new web browser to check that you have your desired default homepage.
- Remove VirtuMonde Directories.
To find infection directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.
Search and delete the following directories:
There are no directories.
Right-click on the named folder and select Delete.A message will appear saying ‘Are you sure you want to remove the selected folder and move all its contents to the Recycle Bin?’, click Yes.
Another message will appear saying ‘Renaming, moving or deleting a folder could make some programs not work. Are you sure you want to do this?’, click Yes. - To remove VirtuMonde icons on your Desktop, drag and drop them to the Recycle Bin.
You’ve completed the manual removal instructions!
I hope this article has helped you solve your problems. If you want to contribute to this article, post your comment below.
Read Other Related Posts
Did You Find this Article Helpful?
Or get latest articles to your via email:

Hi there i tried the automatic removal technique but it seems that the virus is still on my computer as when i restart the compter, the privacy tab in internet exporer properties always sets the cookies to zero. I have removed the virtumonde trojan about five times with windows defender but it seems to come back every time i reboot, i am no computer wizz so can’t follow the manual removal guide. Can someone tell me what i should do as i’ve tried the automatic removal four times now but no hope. Also when it says that wininet.dll will be checked for infection on the guide, well when i tried, it didnt check for infection. Heres is the rapprt.txt:
SmitFraudFix v2.257
Scan done at 16:42:33.54, 03/12/2007
Run from C:\Documents and Settings\my name\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] – Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler’s .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri’s WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» DNS
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
“System”=”"
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler’s .dll
»»»»»»»»»»»»»»»»»»»»»»»» End