Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Tech Advice Needed - Malware Problem

  1. #1
    Join Date
    24th Nov 2009
    Location
    1984
    Posts
    8,244

    Default Tech Advice Needed - Malware Problem

    Last night while browsing the internet, my anti-virus program (Avast) detected a Malware virus. Windows Security Centre then popped-up alerting me to a viral attack with over 30 possible infections detected. Windows Security Centre also informed me that my firewall had been disabled and when trying to remove the viruses stated that my subscription had expired and to purchase the upgrade.

    Thinking that it was a bit ‘off’ that Windows Security Centre would tell me that my credit card details have been compromised and then to purchase the upgrade just didn’t add up. I obviously did not take this action.

    Avast would not launch in order for me to run a scan so I logged into my partners profile (partitioned) and was able to run a scan on the whole computer. The results turned up nothing.

    Logging back into my profile (and even restarting the PC) just displayed the pop-ups and Windows Security Centre alerts again.

    I performed a system restore from the day before and this seems to have removed / prevented the pop-ups from reoccurring however I am a bit worried that any viruses present may not have been removed completely. Of course, that might just be me being overly cautious.

    A Google search today (on another PC) showed that this was obviously a virus that tells you that you have one and to purchase an update which is a virus in itself.

    Just wondering if anyone else has encountered this and what steps did you take to remove the threat / nuisance. Did a system restore only work for you? Did you run Malware detection s/w?

    My knowledge of accessing the registry is very limited therefore I am hesitant to do this if it can be avoided. Like I said, it appears to have been removed after the system restore, but I have also read that perhaps this is not the preferred way of removing malicious programs.

    Any assistance / help would be appreciated.
    New Acquisitions:
    TR Astrotrain, Skullsmasher, & Hardhead
    Scouting For:
    G1 Boxes & Cardbacks
    - - - - - - - - - - - - - - -
    [COLLECTION] [CREATIVE] [MK COLLECTION]



  2. #2
    Join Date
    2nd Jan 2008
    Location
    NSW (southwest metro)
    Posts
    3,760

    Default

    Ben, make sure you download and run Anti-Malware from Malwarebytes. Here's a direct link to the program -> http://majorgeeks.com/downloadget.ph...d909666f809b26

    You do not need to purchase this program to remove the virus. And the only diff between this and the full version is scheduling scans.

  3. #3
    Join Date
    24th Nov 2009
    Location
    1984
    Posts
    8,244

    Default

    Thanks mate. I'm guessing that it's best to download it to an external HD or USB device instead of the PC that may be infected?

    Also, (noob question here) should I run it in 'safe mode'? I didn't do the system restore in safe mode and it seemed to work.

    EDIT: I've also read that some variations of this virus won't allow you to run a system restore. I'm assuming that since I was able to, it should be fixed
    Last edited by 5FDP; 21st April 2010 at 12:23 PM.
    New Acquisitions:
    TR Astrotrain, Skullsmasher, & Hardhead
    Scouting For:
    G1 Boxes & Cardbacks
    - - - - - - - - - - - - - - -
    [COLLECTION] [CREATIVE] [MK COLLECTION]



  4. #4
    MV75's Avatar
    MV75 is offline Rank 6 - Dedicated Member
    Join Date
    27th Dec 2007
    Location
    Brisbane, QLD
    Posts
    2,879

    Default

    Everyone get this:

    http://www.microsoft.com/security_essentials/

    DO IT DO IT DO IT.

    I've had it with 3rd party anti virus. The only version of this one is free, there is no $ motive.

    As for the ops problem, what was it exactly? Wasn't that vista defender virus was it? My nieghbour had that nightmare a while ago.

    Quote Originally Posted by 5FDP View Post
    Thanks mate. I'm guessing that it's best to download it to an external HD or USB device instead of the PC that may be infected?

    Also, (noob question here) should I run it in 'safe mode'? I didn't do the system restore in safe mode and it seemed to work.

    EDIT: I've also read that some variations of this virus won't allow you to run a system restore. I'm assuming that since I was able to, it should be fixed
    Gotta get to know what exactly has hijacked your system first. You'll find they wipe out being able to system restore and to go to anti virus websites, so it's hard to fix the problem after the fact.
    Code:
    O o 
      _
     / --------------------------------
    |      IMMA FIRIN MA LAZAR!!!
     \_--------------------------------

  5. #5
    Join Date
    24th Nov 2009
    Location
    1984
    Posts
    8,244

    Default

    Quote Originally Posted by MV75 View Post
    Can I run this in conjuction with my other anti-virus s/w?

    Quote Originally Posted by MV75 View Post
    As for the ops problem, what was it exactly? Wasn't that vista defender virus was it? My nieghbour had that nightmare a while ago.
    It's looks something like this (amongst a million and one other pop-ups)...



    When you click on the 'remove' button, it asks for your details to upgrade to the newest version.

    This is what I think I have (or a variation of) >
    http://www.microsoft.com/security/po...ernetAntivirus
    New Acquisitions:
    TR Astrotrain, Skullsmasher, & Hardhead
    Scouting For:
    G1 Boxes & Cardbacks
    - - - - - - - - - - - - - - -
    [COLLECTION] [CREATIVE] [MK COLLECTION]



  6. #6
    MV75's Avatar
    MV75 is offline Rank 6 - Dedicated Member
    Join Date
    27th Dec 2007
    Location
    Brisbane, QLD
    Posts
    2,879

    Default

    Quote Originally Posted by 5FDP View Post
    Can I run this in conjuction with my other anti-virus s/w?
    No, uninstall your other stuff. Dunno. The MSE does anti vir, firewall, malware, etc. It does it all.

    Besides, why would you want to?


    It's looks something like this (amongst a million and one other pop-ups)...

    [IMG]http://img.photobucket.com/albums/v374/vishaal_here/Antivirus_1.jpg

    When you click on the 'remove' button, it asks for your details to upgrade to the newest version.

    This is what I think I have (or a variation of) >
    http://www.microsoft.com/security/po...ernetAntivirus
    Yea, looks like a hijack. You don't get that shit accidently.

    http://www.bleepingcomputer.com/viru...irus-1-removal

    Personally, I'd just nuke the site from orbit, (reinstall windows), to be sure. But I assume you have a crapton of photos and other crap you've never backed up, so you can't.
    Code:
    O o 
      _
     / --------------------------------
    |      IMMA FIRIN MA LAZAR!!!
     \_--------------------------------

  7. #7
    Join Date
    2nd Jan 2008
    Location
    NSW (southwest metro)
    Posts
    3,760

    Default

    Follow the link provided by MV75, which eventuates to Malwarebytes Anti-Malware anyway~

    You can download that from the link I gave in the first post from the infected computer and it doesn't need to be in safe mode to run. Just make sure you follow the instruction to restart after running a FULL SCAN

  8. #8
    Join Date
    24th Nov 2009
    Location
    1984
    Posts
    8,244

    Default

    Cheers guys! You're both awesome

    One last question - so considering all of the above suggestions you've given me, I take it that the system restore that I ran didn't do jack?
    New Acquisitions:
    TR Astrotrain, Skullsmasher, & Hardhead
    Scouting For:
    G1 Boxes & Cardbacks
    - - - - - - - - - - - - - - -
    [COLLECTION] [CREATIVE] [MK COLLECTION]



  9. #9
    MV75's Avatar
    MV75 is offline Rank 6 - Dedicated Member
    Join Date
    27th Dec 2007
    Location
    Brisbane, QLD
    Posts
    2,879

    Default

    Well, it's still popping up, right? My question should answer your last question.
    Code:
    O o 
      _
     / --------------------------------
    |      IMMA FIRIN MA LAZAR!!!
     \_--------------------------------

  10. #10
    Join Date
    24th Nov 2009
    Location
    1984
    Posts
    8,244

    Default

    Nope, it's not popping up anymore. From what I have read elsewhere, a system restore doesn't necessarily remove the infected files but rather they are just 'dormant' and can still cause issues at a later stage.

    I guess I just want to make sure they are removed altogether avoiding having to do a complete re-install.
    New Acquisitions:
    TR Astrotrain, Skullsmasher, & Hardhead
    Scouting For:
    G1 Boxes & Cardbacks
    - - - - - - - - - - - - - - -
    [COLLECTION] [CREATIVE] [MK COLLECTION]



Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •