I tried everything you suggested,
tried to remove suspisios programs from startup and with task manager in my
account and in safemode,
In Safe Mode my spybot v1.6 found the virtumonde.dll and deleted it. After
each restart it found it again and again. All online scanners didn't find
anything.
Also I found some interesting file in my windows folder called
BM3b6d974d.txt with the following context:
< .... Date ... > Process attached explorer - 0 - 0
< .... Date ... > Start thread connector, thread id: - 2588 - 0
< .... Date ... > Start thread protector, thread id: - 2132 - 0
*** BEGIN EXEPTION REPORT ***
EXE C:\WINDOWS\EXPLORER.EXE
Module C:\WINDOWS\System32\fwfltkxd.dll
...
...
I deleted this file...
Also found wininit.ini in my Windows folder (also deleted it):
[rename]
C:\tempjunk3267.tmp = C:\WINDOWS\system32\rqRIaAqn.dll
nul=C:\tempjunk3267.tmp
The file rqRIaAqn.dll is reported by spybot as the virtumonde.dll virus but
I'm unable to delete it. The DLL attached itself to explorer.exe and
winlogon.exe,
If I try to remove it from memory (with unlocker.exe), windows automatically
crashes (in safe mode too) and the standart delete does not work (file in use
error).
I don't see other option then formatting my PC.
Thanks.
Alex Levi said:
Can anyone tell me what is the following line that I found in my registry
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Key: BM3b6d974d
Value: Rundll32.exe "C:\WINDOWS\system32\xqfulqgt.dll",s
When using Registry monitor I found that my Explorer.exe is writing this key
(almost every second)
Is this normal?
I tried to scan my PC with NAV, Spybot, online scanners and found nothing.
Thanks.