> I have had an attack from the VirtuMonde nasttyware which I have managed
> to
> recover from - mostly.
You have much more work to do and you're going to need an expert's
assistance.
Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315
Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.
Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware
When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use (in
conjuction with some other utilities). HijackThis will NOT fix anything on
its own, but it will help you to both identify and remove any
hijackware/spyware with assistance from an expert. **Post your log to
http://aumha.net/viewforum.php?f=30,
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html, or other appropriate forums for review
by an expert in such matters, not here.**
If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA or Geek Squad) computer repair shop.

Signature
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/
> I have had an attack from the VirtuMonde nasttyware which I have managed
> to
[quoted text clipped - 4 lines]
>
> Any thoughts?
Jeff - 30 Aug 2008 08:39 GMT
Thank you for the very prompt reply to my post PABear.
I have already posted a HiJackThis log to Spybot Malware Forum, but haven't
had any reply for 4 days. Looking at the forum I can understand why - there
are simply hundreds of VirtuMonde associated posts going in there. I was
directed here on re-installing IE7 (I wanted to see if it was an IE7 specific
problem) and noticed this forum so thought I might just post here too.
I thought I'd done a fairly good job but obviously not.
I ran most of the common Spyware/AntiVirus programs including Malwarebytes,
Spybot, Spyware Doctor, AVG, Windows Malicious Software Removal Tool ... and
others in both ordinary and Safe Mode. Eventually, having found and removed
many objectionable files they all reported a clear system. I then checked the
running dll's and removed two and did a final registry search which seemed
clear. I was hoping that was it, ran most of the previously mentioned progs
once more with a clear report from each. This jump/redirect hijack is the
only symptom I'm left with (apparently).
I will wait on the people from SpyBot to get the time to look at my problem.
Anyways thanks for the help again ....
Jeff
PA Bear [MS MVP] - 30 Aug 2008 21:34 GMT
Did you "read & heed" http://forums.spybot.info/showthread.php?t=288 as well
as http://forums.spybot.info/showthread.php?t=16806 ?
If it's been 4 days and you've gotten no replies, have you posted here yet?
=> http://forums.spybot.info/forumdisplay.php?f=37
Can you give me a link to your thread?
PS: Don't forget it's a long holiday weekend in the USA. Most of the
"handlers" will be AWOL until Tuesday.

Signature
~PA Bear
> Thank you for the very prompt reply to my post PABear.
>
[quoted text clipped - 27 lines]
>
> Jeff
Jeff - 31 Aug 2008 13:41 GMT
Hi Pa Bear,
A busy couple of days with one of the experts has completely solved all my
problems. Excellent service and attention. I am very impressed.
All is well now and, after following all the final advice, I am hoping it
will remain that way.
Thanks for your attention too, its reassuring to know there are people out
there fighting back!
Jeff
> Did you "read & heed" http://forums.spybot.info/showthread.php?t=288 as well
> as http://forums.spybot.info/showthread.php?t=16806 ?
[quoted text clipped - 37 lines]
> >
> > Jeff
June - 31 Aug 2008 17:50 GMT
Jeff, I am experiencing the same problems you have stated -- clicking on a
link takes me to an unrelated site -- I cannot seem to download any
diagnostics because the links take me elsewhere.
I am not as computer literate as you and don't know how to changes settings
with DLLs and registries without specific detailed instructions.
I will follow the instructions as well as I can from PA Bear, but was hoping
you might tell me how you fixed your issue.
June
> Hi Pa Bear,
>
[quoted text clipped - 50 lines]
> > >
> > > Jeff
PA Bear [MS MVP] - 31 Aug 2008 23:07 GMT
Please being a new thread about YOUR problems, June. Thanks. Jeff's fix
will not apply to your machine.

Signature
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/
> Jeff, I am experiencing the same problems you have stated -- clicking on a
> link takes me to an unrelated site -- I cannot seem to download any
[quoted text clipped - 7 lines]
> hoping
> you might tell me how you fixed your issue.
Frank Saunders MS-MVP IE,OE/WM - 01 Sep 2008 03:05 GMT
> Jeff, I am experiencing the same problems you have stated -- clicking on a
> link takes me to an unrelated site -- I cannot seem to download any
[quoted text clipped - 7 lines]
> hoping
> you might tell me how you fixed your issue.
Do a thorough check for malware, following all of the steps at one of these
Web pages.
Help with malware:
All MS-MVP Sites.
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://www.elephantboycomputers.com/page2.html#Removing_Malware
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/darnit.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
Unexplained computer behavior may be caused by deceptive software.
http://support.microsoft.com/kb/827315
So How Did I Get Infected Anyway?
For quite a few people it's by installing programs like Messenger Plus,
whose ads for malware don't identify the malware as such and try to convince
you that you owe it to the author. See also:
http://www.wilderssecurity.com/showthread.php?t=27971
Don't ever do a "default" install of anything. Always choose Custom and see
what else is being carried along. Don't install any extras you're not sure
of.

Signature
Frank Saunders MS-MVP IE,OE/WM
Do not reply with email
puggioni renato umberto - 29 Nov 2008 15:56 GMT
> Jeff, I am experiencing the same problems you have stated -- clicking on a
> link takes me to an unrelated site -- I cannot seem to download any
[quoted text clipped - 73 lines]
>> > >
>> > > Jeff
PA Bear [MS MVP] - 31 Aug 2008 23:06 GMT
You're welcome & thanks for your feedback. I'd be interested in reading
your thread: Can you give me a link to it?
> Hi Pa Bear,
>
[quoted text clipped - 57 lines]
>>>
>>> Jeff