Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

malware infection!

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 23-Mar-2008, 09:52 AM
twizzle's Avatar
twizzle twizzle is offline
Lifetime Member
Posts: 1,046
Points: 617 twizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 points
Power: 21
None
Join Date: 16 Jan 2006
Location: norfolk
Age: 34
Certifications: Comptia A+, N+
WIP: Being a BILB
malware infection!

hey fellas need some help.

Turns out my pc has no become infected with some malware.Unsure where it came from, and even how it managed to get on my pc considering that i have Spybot s&D, Ad-Aware and NOD32 running. Anyway its called Vitumonde.dll and i'm having problems removing it.
I'v run all 3 above, Trends Housecall, Ewido AVG, Kaperskys online checker, stinger and i've done what i can in safe mode (deleted the infected iles and removed some registry entries etc) every check says reved or fixed, until i reboot the pc and it becomes re-infected.
I have tried to google this one nd just cannot seem to find a good bit f advice on how to get rid of this apart from what i have done. So any suggestions? have i missed something??

Its getting really annoying as it runs another instance of IE when i run IE, sending me to pages of Ads. I want tmake sure i have tried everything before the last resort of reformatting and re-installing all (wont use system restore as i know this gets infected too)


LOVELY SPAM, LOVELY SPAM,
LOVELY SPAM, LOVELY SPAM.
SPAM, SPAM, SPAM, SPAM
 
Reply With Quote
  #2  
Old 23-Mar-2008, 10:16 AM
MrNerdy's Avatar
MrNerdy MrNerdy is offline
Valued Member
Posts: 327
Points: 164 MrNerdy has over 100 pointsMrNerdy has over 100 points
Power: 7
None
Join Date: 17 May 2007
Location: London
Certifications: ECDL, CiscoIT1 & A+
WIP: Girlfriend & Network+
By googling your problem i found THIS
Or try THIS
It may just be a case of working through the list until you find something that works!


I'm not a complete idiot, some parts are missing!
 
Reply With Quote
  #3  
Old 23-Mar-2008, 12:29 PM
Sparky's Avatar
Sparky Sparky is online now
Premium Member
Posts: 4,997
Points: 2419 Sparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 points
Power: 78
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCTS N+ A+
WIP: Server 2008 upgrade & 70-284
Actually system restore should be the first you try in safe mode. I know many people say this wont work but if you can pick a restore point from a point in time before the machine got infected then that might be all you need to do. It is possible that some of the restore points may have the malware included though.

When you reboot is your PC connected to the internet? Either the malware is downloading itself again or being recreated from a start-up process.

Few things you can try:
*System restore in safe mode
*Run all the spyware checks in safe mode again
*Log on as a different user account
*Run Filemon as this will tell you exactly what is running in the background. Delete the malware files as needed.
http://technet.microsoft.com/en-us/s.../bb896642.aspx
*Icesword is useful as well, also deletes files that are in use.
http://www.softpedia.com/get/System/...IceSword.shtml


Me: You need to buy a couple of servers.
Customer: Whats wrong with the servers I have?
Me: Well, you dont have *any* servers just now.
Customer: WTF! I thought I did!

 
Reply With Quote
  #4  
Old 23-Mar-2008, 01:01 PM
derkit's Avatar
derkit derkit is offline
Premium Member
Posts: 803
Points: 1065 derkit has over 1000 pointsderkit has over 1000 pointsderkit has over 1000 pointsderkit has over 1000 pointsderkit has over 1000 pointsderkit has over 1000 pointsderkit has over 1000 pointsderkit has over 1000 points
Power: 22
None
Join Date: 04 Sep 2006
Location: Northwood, London
Age: 27
Certifications: BSc (Hons), A+, MCP, MCDST
WIP: Net+, ITIL v3
ComboFix may be worth a look also - I haven't researched your particular problem, but I've used it on a few computers and it always does well.

Linky


It's the journey that matters, not the destination.

Aims:
70-271: Dec 2007 PASSED!
70-272: March 2008 PASSED!
ITIL v3 Foundation: June 2008
Net+: July 2008
70-270: Nov 2008
 
Reply With Quote
  #5  
Old 23-Mar-2008, 06:31 PM
Mitzs's Avatar
Mitzs Mitzs is offline CertForums News Posting Member
Lifetime Member
Posts: 2,958
Points: 1995 Mitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 pointsMitzs has over 1500 points
Power: 54
None
Join Date: 11 Apr 2005
Location: Tenneesse USA
Certifications: Microcomputers and network specialist.
Twizzle, you can try counterspy and see if it works it is what mary and I use. They have a 15 day free trial. Adware, counter spy, just don't keep their stuff up todate well enough anymore.


Don't walk in front of me, I may not follow. Don't walk behind me, I may not lead. Walk beside me and just be my friend. (Old Irish Proverb)
 
Reply With Quote
  #6  
Old 23-Mar-2008, 08:07 PM
twizzle's Avatar
twizzle twizzle is offline
Lifetime Member
Posts: 1,046
Points: 617 twizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 points
Power: 21
None
Join Date: 16 Jan 2006
Location: norfolk
Age: 34
Certifications: Comptia A+, N+
WIP: Being a BILB
Mr Nerdy, thanks for the googles but i've already tried the first one and that didnt work. Hijackthis listed some processes that i removed but to no avail.
Derkit, tired Combofix but now my pc wont boot either to safe mode or normal windows, and at the mo i cant even find my xp disk!!

Bugger it all, will have to formt and start again! ( well there goes the bathroom tilling this weekend and i was so looking forward to doing that!!! ;) )


LOVELY SPAM, LOVELY SPAM,
LOVELY SPAM, LOVELY SPAM.
SPAM, SPAM, SPAM, SPAM
 
Reply With Quote
  #7  
Old 23-Mar-2008, 08:36 PM
Theprof's Avatar
Theprof Theprof is offline
Lifetime Member
Posts: 2,050
Points: 673 Theprof has over 500 pointsTheprof has over 500 pointsTheprof has over 500 pointsTheprof has over 500 pointsTheprof has over 500 pointsTheprof has over 500 points
Power: 30
None
Join Date: 20 May 2006
Location: Canada
Age: 21
Certifications: 270, A+, MCDST, Network+
WIP: Bachelors in Business, MCSA
I've had some pretty bad malware last week called virusheat and no anti-spyware/malware helped except for this app.


My best memories go out to nights that turned into mornings and the friends that turned into family.

Whatever the mind can conceive and believe, the mind can achieve. Dr. Napoleon Hill

Do just once what others say you can't do, and you will never pay attention to their limitations again. James R. Cook


 
Reply With Quote
  #8  
Old 23-Mar-2008, 10:46 PM
twizzle's Avatar
twizzle twizzle is offline
Lifetime Member
Posts: 1,046
Points: 617 twizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 pointstwizzle has over 500 points
Power: 21
None
Join Date: 16 Jan 2006
Location: norfolk
Age: 34
Certifications: Comptia A+, N+
WIP: Being a BILB
Well just spent the last hour or so re-installing windows. Had to wipe the exisiting install but fortunatley not teh whole drive. Now i'm just running the Profs app to see if that finds anything.
What surprises me is that NOD didnt remove it and thats sposed to be one of the best, neither did Trend or AVG.
malware and Viruses are just getting too good these days!


LOVELY SPAM, LOVELY SPAM,
LOVELY SPAM, LOVELY SPAM.
SPAM, SPAM, SPAM, SPAM
 
Reply With Quote
  #9  
Old 23-Mar-2008, 11:07 PM
Bluerinse's Avatar
Bluerinse Bluerinse is online now
Senior Moderator
Posts: 7,370
Points: 2479 Bluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 points
Power: 107
None
Join Date: 29 Jun 2003
Location: The Gold Coast, QLD Australia
Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)
WIP: None but considering SBS
Quote:
Originally Posted by twizzle View Post
Well just spent the last hour or so re-installing windows. Had to wipe the exisiting install but fortunatley not teh whole drive. Now i'm just running the Profs app to see if that finds anything.
What surprises me is that NOD didnt remove it and thats sposed to be one of the best, neither did Trend or AVG.
malware and Viruses are just getting too good these days!
The reason that NOD and AVG and other similar programs didnt remove it is that it's not a virus as such. it is addware, something that you have infected your computer with by using Internet Explorer and have most likely inadvertantly, agreed to the installation thereof.

Foor goodly sake, now your PC is clean again, the best protection against these nasties is to not use IE.. Use Fx or Opera for your usual day to day browsing. It is the Active X controls built into IE, mainly for the purposes of Windows update that these malware writers exploit in order to get their crap into your system. Only use IE on sites you need to and *trust*, ie some banks and Microsoft etc.


"A child of five could understand this. Fetch me a child of five." <Groucho Marx>
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Inside a Modern Malware Distribution System Mitzs Security & Viruses 0 06-Jan-2008 04:52 AM
DRM software being exploited by malware authors ffreeloader Security & Viruses 0 09-Nov-2007 02:05 PM
More malware coming for Macs tripwire45 News 7 08-Nov-2007 09:40 AM
Now nhl.com serving up malware through banner ads zebulebu Security & Viruses 1 06-Nov-2007 08:52 PM
Building malware defenses: From rootkits to bootkits Mitzs Security & Viruses 0 22-Oct-2007 12:45 AM


All times are GMT. The time now is 10:30 PM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages