Threat Database Adware VirtuMonde.prx

VirtuMonde.prx

By SpideyMan in Adware

VirtuMonde.prx is playing hide-and-seek with victims who spot VirtuMonde.prx on scan reports, quarantine and remove Trojan.VirtuMonde.prx, only to see Trojan.VirtuMonde.prx rear its ugly head and again and again.

VirtuMonde.prx is a spy and a pirate. Trojan.VirtuMonde.prx spies on your surfing habits and hijacks your browser, so Trojan.VirtuMonde.prx can forcibly route you to malicious websites and keep you from downloading helpful programs that can detect or remove VirtuMonde.prx.

Other than subtle signs of intrusion such as slowed system or inhibited browser performance, you may never know Trojan.VirtuMonde.prx or its malicious friends (other malware) are hiding out in your system; it’s only until you run a PC checkup with an anti-malware scanner that you learn VirtuMonde.prx is the Trojan from hell that simply will not go away.

According to the frantic reports of its victims, VirtuMonde.prx most likely has rootkit technology helping bury its malicious files deep in your system's kernel and away from prying eyes or scans that want to remove Trojan.VirtuMonde.prx. Unless you are skilled in editing registry, system, or .dll directory files, you will need an aggressive and reputable anti-malware tool using an anti-rootkit component, to both find and remove Trojan.VirtuMonde.prx. Otherwise, you might be in for one hellish ride, while hackers fight for control of your PC and continuously monitor and steal vital data stored on your PC or off of web-based forms.

Trojans such as VirtuMonde.prx take advantage of vulnerabilities in software and hardware. Often Trojans and other malicious programs come bundled or cloaked in legitimate downloads of freeware, shareware, or a deceptive codec component you may need to view a movie or video. P2P files are a haven for malware and often times include an ambiguous user-end license agreement (EULA) that carries infectious adware tools.

Once infected with Trojan.VirtuMonde.prx, you can expect your registry to be modified so that VirtuMonde.prx runs its infectious executable at every Windows boot. Trojan.VirtuMonde.prx will perform steps to disarm or disable your security measures, including adding its malicious program to your approved programs listing to bypass your firewall. Trojan.VirtuMonde.prx will set itself as a proxy, so VirtuMonde.prx can control your browser and web traffic and keep you from downloading any helpful programs, such as a stealth anti-malware tool, to detect and remove VirtuMonde.prx, but do not be discouraged, there is a way you can restore order to your system and actually 'remove' all traces of Trojan.VirtuMonde.prx off your system.

Not every anti-virus or anti-spyware program is capable of restoring your registry, programs, .dll directory or general files. Therefore, you need to be careful when selecting online scanners and Internet security tools lest you be fooled by a rogue security program, known to mislead you and leave your PC open to malicious attacks. You should seek anti-malware tools known to combat Trojan.VirtuMonde.prx and have anti-rootkit capabilities to battle even the stealthiest of viruses. Shutting down or turning off your system will not make VirtuMonde.prx go away! As soon as you restart your system, the madness will repeat.

Malware makers are seeking new ways each and every day to steal money or data from PC users. Therefore, protecting your valuable data and PC is going to take both the efforts of a stealth anti-malware tool and persistent PC user.

Malicious programs use a lot of resources and can easily cause a system crash. Equally, deleting the wrong system, program, or .dll directory file could cause irreparable damage to your hard drive and thus corrupt your files. Why take the risks? Use a reputable anti-malware tool containing an anti-rootkit component to clean your system, so you can use it worry free.

File System Details

VirtuMonde.prx may create the following file(s):
# File Name Detections
1. winhost.exe
2. quicken.exe
3. regsvr32 /u lspak.dll
4. regsvr32 /u winupd.dll
5. System\winhost32.exe
6. editpad.exe
7. regsvr32 /u Local Settings\Temp\wincore.dll
8. regsvr32 /u Local Settings\Temp\cidrules.dll
9. regsvr32 /u virtumonde.dll
10. windowsupd2.exe
11. regsvr32 /u cidrules.dll
12. regsvr32 /u wincore.dll

Registry Details

VirtuMonde.prx may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}scan
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEpl.IEPl.1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}
HKEY_USERS\S-1-5-21-1887652994-1477516851-2064603551-500\Software\Microsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEpl.IEpl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}
HKEY_LOCAL_MACHINE\SOFTWARE\TargetSoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tdev
HKEY_CLASSES_ROOT\DosSpecFolder.DosSpecFolder.1
HKEY_CLASSES_ROOT\CLSID\{FDA4DFFB-2C3D-4730-8D7E-28523C7F2F67}\Windows\CurrentVersion\Ext\Stats\{CA21E6FA-41D9-4F05-9650-8B3FBE72124D}

Trending

Most Viewed

Loading...