annamc
Topic Starter
On December 29, while my husband was surfing the net (he swears he wasn't downloading anything whatsoever), he saw an installation window pop up which wouldn't cancel when he tried to (he says it was labeled as an update for my WalMart music downloader, which seems doubly odd). Popups started proliferating. He saw something called "Internet Speed Monitor" had been installed, and uninstalled it. The computer had slowed to a crawl, and Norton 360 was disabled – several of its system files had disappeared. At that point I came back home and he told me what was going on, and I took over, since I know a bit more about software. Ironically, the Norton 360 self-diagnostic said that everything was absolutely fine with the program, even as multiple error messages kept telling me that crucial operating files were missing.
I managed to connect with Symantec chat help, which recommended I use the Norton uninstaller to remove Norton 360 and then reinstall it. I did so, and it told me I had w32.Trats!inf and the Vundo/virtumonde viruses. I followed the removal instructions for w32.Trats!inf from the Symantec website as best I could (I couldn't understand the registry instructions), and used Vundofix to get rid of the Vundo infection. It took about five or six runs of Vundofix to make the files go away.
The computer was working pretty much normally then, but Norton 360 then told me I was still infected with w32.Trats!inf., so I started another chat session. They said I'd need to pay for premium support ($100) to get it removed, so I did – I figured I didn't have much choice. They then took remote control of the computer, ran a tool, deleted some things, and pronounced me clean.
A day later, Norton pops up a notice that w32.Trats!inf is back. I have 15 days of free support left with Norton on the virus cleanup, so I have another support chat. They check and lo! it's back. They delete it again and assure me it's really gone this time, and make broad hints that perhaps I had just reinfected myself by clicking on evil attachments, etc. I was skeptical, but accepted this.
Yesterday, Norton 360 tells me that vundo is back! I ran the Norton fix, and it said everything was now fine. I ran vundofix, and it found nothing, but when I poked around in the registry, there were still references to pmnnm.dll and pmnnm.exe, which I know from my many hours of reading about these viruses are evil files. At that point it was very late, so I shut the thing off and started again early this morning. I read online that having old versions of Java will make you vulnerable, so I uninstalled all my old versions of Java and just installed the new one, hoping this might help keep me from being so vulnerable. Then I logged on for another chat with Norton/Symantec premium support. They checked my system 32 folder, and saw that I was indeed infected: ctfmon.exe.tmp; mnnmp.ini; mcrh.tmp; and ctfmon.exe are apparently the offending files (they explained something to the effect that ctfmon.exe is a legit file, but there's apparently a virus clone). Interestingly, the last modified date on all these files was December 30 – these *were never deleted correctly in the first place* during the first two tech support sessions (which I paid $100 for, lest we forget). This guy tells me not to worry (that was exactly what the last two guys told me), and deletes the files, and says it's fixed – just as I notice ctfmon.exe has come back up on the reboot. He confirms that oops, yes, it's back, and has me go into safemode, in which he says he at last deleted every last virus trace. I point out that the registry entries for pmnnm.dll and pmnnm.exe are still there, so he deletes those. At this point my Microsoft Office begins freaking out and asking for an install; apparently the fix to the ctfmon.exe file (which is an Office file) damaged that. So I had to use the CD to reinstall bits of that. Then, when he ended the chat session, I realized he'd forgotten to reenable system restore (they disable it when they start fixing your system to avoid reinfection). I called Symantec (I had no patience to wait a half hour for another chat) and asked if I should reenable it, or if he was leaving it off deliberately to avoid reinfecting my system; they told me to reenable it. So, apparently he forgot to reactivate a crucial system process. It just gets better and better!
At any rate, the guy from Symantec swears (again) that this time my system is really, really, clean, this time they mean it, cross their hearts and hope to die. At this point, my faith in their competence is somewhere between diddly and squat. They've been very nice (at $100, they should be!), but for professionals to miss these files repeatedly leaves me very, very worried.
How can I make sure that all traces of this virus are really, truly gone from my system, and the ctfmon.exe file now in my system32 folder is the innocent file, not the evil spawn of doom file? Neither Norton 360 or Vundofix are detecting anything untoward, but they weren't detecting the infections half the time. Also, how can I make sure this doesn't happen again? My husband swears he was just browsing a sports message board, and hadn't downloaded anything, or clicked on any attachments.
I've been online since the mid 90s, and my husband has been online almost that long; neither of us have ever seen anything remotely like this. I do use Netscape 7.2 for email and some browsing – as an older browser, is that exposing us to problems?
I installed the new version of HijackThis, and can post a log if that would be useful. Any help would be tremendously appreciated. It's been a wretched start to the new year.
Thank you,
Anna M.C.