Urgent Help Please

Pasty
Pasty Posts: 33 Forumite
This might be the wrong place to post this message, but hopefully someone on here can help.

My laptop has been infected with a virus that i have got from a site called Win24.

I had no idea it had been infected (virus protection did not stop it) until i turned my laptop on yesterday. I was able to put my password in and see my desktop, but as it loaded up it froze. I was unable to do anythiny with it other than switching the power off.

Anyway, i started the laptop in safemode and was able to run a virus scan which picked up an infected file from Win24 (i think). After playing around and following some instructions from windows help i am now able to use my laptop. However, the performance is slower and i'm sure it is still infected. Evertime i load it up and run a virus scan it picks up the same virus and deletes it, but then then next time i re-start the laptop and scan the virus is there again. Also, a "thing" keeps trying to add itself to the start up programme: c:\windows\system32\drivers\ctfmun.exe which of course i block.

Can someone in the know give me some advise please. I really don't want to spend my matched betting profit on a new laptop!

Edit - it may be Win32 and not Win24
«1

Comments

  • dipsomaniac
    dipsomaniac Posts: 6,739 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    format drive and re-install operating system - it is the only way in my opinion.

    second best is to restore to factory setting if you have the option

    third choice use system restore to a known good setting
    "The Holy Writ of Gloucester Rugby Club demands: first, that the forwards shall win the ball; second, that the forwards shall keep the ball; and third, the backs shall buy the beer." - Doug Ibbotson
  • cooldudecol
    cooldudecol Posts: 784 Forumite
    Surely, this question would be better placed in Techie Stuff ???

    ctfmun.exe - if you type this into google, there are several sites to explain how to remove this.
  • bioboybill
    bioboybill Posts: 3,474 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    One of the best sights to ask these sort of questions is TekTips (do a Google). Tbh the advice a couple of posts above is OTT. I'm no IT expert, but a lot of viruses hide in system restore. In fact it's generally accepted that system restore should be turned off before doing a virus scan and removal. This does remove all your system restore settings when you switch it back on again and I know this seems a bit scary, but unless you do that viruses can just hide in there and come back to bite you.

    Try turning off system restore and then run your virus scan and try to remove or quarantine it. Then turn system restore back on and re-boot. If that doesn't work ask your question at TekTips

    By the way the real ctfmon.exe is a file used by windows office, but this might be a virus pretending to be that.

    Bill
  • dipsomaniac
    dipsomaniac Posts: 6,739 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    nothing OTT about formatting and re-installing operating system. it can be done in a couple of hours, clears out all the rubbish and laptop will run like new again. should be done at least once a year IMO
    "The Holy Writ of Gloucester Rugby Club demands: first, that the forwards shall win the ball; second, that the forwards shall keep the ball; and third, the backs shall buy the beer." - Doug Ibbotson
  • Pasty
    Pasty Posts: 33 Forumite
    Thanks for your replies - looks like the thread has been moved to the right place now.

    Some more info on the virus:

    Original file name: droute.dll
    Original folder: C:\WINDOWS\System32
    Size of file: 23364
    Description: Win32:Goldun-MA(Spy)
  • espresso
    espresso Posts: 16,448 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    Follow the instructions in posts 1 - 4 in the Malware/Spyware removal guide here. Format and re-install is OTT but I don't trust financial advisors.
    :doh: Blue text on this forum usually signifies hyperlinks, so click on them!..:wall:
  • John2g
    John2g Posts: 38 Forumite
    It is a trojan. This FREEWARE will remove it for you. http://www.comodo.com/boclean/boclean.html
  • TonyLisaP
    TonyLisaP Posts: 505 Forumite
    format drive and re-install operating system - it is the only way in my opinion and I am an expert.

    second best is to restore to factory setting if you have the option if you don't then don't do it.

    third choice use system restore to a known good setting or not

    Great advice! :T
  • DatabaseError
    DatabaseError Posts: 4,161 Forumite
    bioboybill wrote: »
    By the way the real ctfmon.exe is a file used by windows office, but this might be a virus pretending to be that.

    Bill
    c:\windows\system32\drivers\ctfmun.exe


    craftily disguised (nearly) ...mun.exe rather than ...mon.exe

    just to add, download and run ccleaner, run it, also run the 'issues' module and fix all errors, you should notice an instant, free, speed boost

    .
    Utinam logica falsa tuam philosophiam totam suffodiant.
  • John2g
    John2g Posts: 38 Forumite
    "craftily disguised (nearly) ...mun.exe rather than ...mon.exe"... and protected by a rootkit.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 349.8K Banking & Borrowing
  • 252.6K Reduce Debt & Boost Income
  • 453K Spending & Discounts
  • 242.8K Work, Benefits & Business
  • 619.6K Mortgages, Homes & Bills
  • 176.4K Life & Family
  • 255.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 15.1K Coronavirus Support Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.