PDA

View Full Version : Norton - Sacked!



Tokamak
2008-06-23, 09:53
Firstly, I hopes that this is the correct forum for this question....

I've been a happy user of Norton IS on a couple of windows PCs for the last couple of years, have been using it in tandem with spybot.

However, due to my own stupidity, and despite the best efforts of teatimer, I managed to infect my main pc with Virtumonde. Thankfully, spybot went apesh*t, and I was able to contain the virus(?)/rootkit before any rebooting was done.

Now, to achieve this I first ran a norton full file scan, thinking that the software that I pay for would find all of the bits of this root kit and kill it for me. Erm, no.

What I ended up using was a combo of Spybot and a free virus / mallware app recomended in your mallware section. Im fairly confident that Virtumonde has gone now (after I've backed up my sisters photos, Ill reformat to be sure) but because Norton was completely useless it is now sacked.

Could anyone recomend a virus/malware program that I can use in combo with Spybot (and firefox / no script) that wont just sit there and be completely useless should anything like this happen again? Looking on the internets at work this morning and BitDefender / Kaspersky might be the way to go :)

Thanks in advance!

spybotsandra
2008-06-23, 11:19
Many people are asking for recommendations regarding firewall and antivirus software they should use.
Our recommendation regarding firewalls is Outpost from Agnitum.
http://www.agnitum.com/products/outpost/
Even the free version - Outpost Free - will fit most users' needs.
http://www.agnitum.com/products/outpost/download.php
For a free anti-virus software for personal use, take a look at H+BEDV AntiVir:
http://www.free-av.com/

Our complete overview:
http://www.spybot.info/en/articles/recommendations.html

Best regards
Sandra
Team Spybot

Tokamak
2008-06-23, 11:48
So, not only do I click 'yes' to a BHO registry addition (doh!), but I can't search the articles properly....

Thanks Sandra :)

tazdotnet
2008-06-29, 19:52
i had Virtumonde and it went down without a fight... didn't even need BartPE, just Spybot and my knowledge of windows xp pro security... denied all permissions to the files that it installed for startup (used Spybot) that were part of Virtumonde... then i restarted and removed the restrictions from the files and deleted them...

is there anything i might have overlooked that could revive Virtumonde?...
like does it hook a module into a common windows proccess like Nail does?..
or any other tricky things you can think of...

KillahSam
2008-06-29, 20:07
Kaspersky is awesome =]

Low cpu usage, and gets everything off.