Help! Virus and Malware infestation...

Status
Not open for further replies.
Joined
Apr 11, 2003
Messages
3,198
Location
USA
My Toshiba laptop allegedly has a virus and malware on it.

It was working fine as of 8 p.m. on Saturday. When I came back to it at 10 p.m., there was a Windows alert that my PC was infected. It would not allow me to connect to the 'net via Explorer 7.

It said the "wuaudt.exe" file was infected. Strangely enough, it recommended I fix the problem by clicking on a button, which immediately took me to a "purchase" screen for Antivirstat.

I ran a deep scan using my I/S suite, ESET 4, and it found nothing. I'm running it again and it has yet to find any infected files.

I can shutdown and restart and sign onto the laptop with no problems. It's just trying to access I/E 7 or Outlook that shuts me down.

I thought I had downloaded MBAM onto the Toshiba, but it may be the ASUS I loaded that on.

Any advice?
 
Try dowloading Malwarebytes and Spy bot search and destroy from another computer and install it on your computer.
 
As in "download it to a CD from my ASUS and run it on the Toshiba?"

I was trying to download MBAM onto the Toshiba but it won't let me onto I/E7.
 
This thing has been going around for awhile now. It tricks you to install it.

Download Malwarebytes free version and copy it to a thumb drive or a CD if you don't have one.

Link To Web Site

Install it on the infected computer then boot into the Safe mode by tapping key F8 on startup and and run Malwarebytes in the safe mode.

I am a Linux user and it was kind of funny, got the same message you Windows computer is infected, click here.

It is a ploy to get your credit card info.

Another way I have removed it for friends is to make a Windows Recovery Disk and boot off it then use the go back feature to set the system to a day or so before it got infected. Then install Malwarebytes and do a full scan to clean the system.

Here is a link to where you can create a boot disk for this purpose.

Link To Windows Recovery Disk Site

I found that making the recovery disk and using go back was and then scanning is the quickest way.

Post for others how you made out.

Hope this helps.
 
Try ComboFix. Combo Fix site. download it to a thumb drive. Boot up the affected PC in Safe Mode and run it.

Just ran it on my daughter's laptop, she had a similar bug. ComboFix kills the Hijack/Redirect processes, so MBAM or other programs can run.

Dave
 
Thanks Deltona and SrDriver.

And simple_: I expected that as the very FIRST response to my question!
 
Quote:

Any advice?


Seriously, try using a less targeted browser, especially one without MS proprietary extensions. If a webserver detects IE it "knows" exactly they type of exploits to try. Regardless of the current security marketing that is done re: IE. It has a very poor track record and since development at MS cost $$ for something they can't sell (as its part of the OS lol) attention to secure coding techniques is probably very small.

You could also try to sandbox the browser in the future; someone else can provide the link as I do not know what it is.
 
Last edited:
Update:

I "cleaned" the problem from my laptop, but now I cannot connect to the internet or Outlook.

I downloaded both ComboFix and MBAM to a USB drive. I rebooted in safe mode, but I forgot to shut down ESET, so ComboFix was not wanting to run simultaneously with ESET.

I simply ran MBAM in safe mode and two hours later, it revealed 23 problems, including three infected files and twenty registry related problems.

Once those were cleaned out, I re-booted in "normal" mode. My laptop is showing a wireless connection to my router and I checked the M/S security settings and ESET security settings. I can find nothing that would prevent connectivity.

I re-booted again, but alas, still no connectivity.

Once I get connectivy, I think I'll ditch ESET.
 
Go to E-Set . com and do an online scan to remove viruses etc. Then go to download.com and download spy-bot.

If you need help, PM me and I can connect to your remotely and assist.

Cheers,

Steve
thumbsup2.gif
 
What version of Windows are you running? Also, is it the 32 bit or 64 bit version?

Sounds like ESET is not allowing you access? Did you try to shut it off then see if you can use your browser?
 
check and make sure the virus didn't change the the IE settings to go to some proxy. open it up, tools, internet options, connection and then LAN settings. Make sure nothing under the proxy options are set (unless you set them yourself).

One program to run is rkill.com. It will kill any active processes and then run MBAM full scan to catch any additional items. MSE is good at finding hard to find malware too.
 
+1. Try unloading Eset and trying to connect. Can your machine ping the router? Also agree with checking the Internet proxy settings in IE. Some malware will change the proxy settings, and Outlook settings too.

Dave
 
Last edited:
My wife had the same problem, here is a site with step by step instruction on how to be rid of it:

http://www.spywareremove.com/removeAVSecuritySuite.html

Main thing is to make the deletions in the registry, exception to instructions though, do not delete:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" ="1"

just change the value from "1" to "0"

Good luck - Bill
 
To enable access again to the internet with IE explorer, open it, go to "tools", open "internet options", go to "connections"
tab, click on "lan settings" at bottom, then unclick box for "Use a proxy server for your LAN", click "OK" and you should now have access again. This is what did it for me.

Good luck - Bil
 
Originally Posted By: BillW
To enable access again to the internet with IE explorer, open it, go to "tools", open "internet options", go to "connections"
tab, click on "lan settings" at bottom, then unclick box for "Use a proxy server for your LAN", click "OK" and you should now have access again. This is what did it for me.

Good luck - Bil


Welcome, BillW, and you win the case of beer!

I followed the above advice and, voila!, connectivity via I/E 7.

Thanks to all of you for your invaluable advice. Running MBAM (and ComboFix) in safe mode via a USB drive solved the problem.

What concerns me is ESET 4 I/S was run twice after the laptop was infected and never detected anything! Worse yet, it never prevented the infection.

It's late (11:50 p.m.) and I need some sleep. Tomorrow I'll remove ESET 4 I/S and load NIS 2010. Should I just stay with the basic (free) MBAM software or pay for the "full monty?"

I'd set up NIS to run continuously, with MBAM scheduled to run once per week minimum, or I could manually run a "deep scan."
 
Originally Posted By: dkryan
Originally Posted By: BillW
To enable access again to the internet with IE explorer, open it, go to "tools", open "internet options", go to "connections"
tab, click on "lan settings" at bottom, then unclick box for "Use a proxy server for your LAN", click "OK" and you should now have access again. This is what did it for me.

Good luck - Bil


Welcome, BillW, and you win the case of beer!

I followed the above advice and, voila!, connectivity via I/E 7.

Thanks to all of you for your invaluable advice. Running MBAM (and ComboFix) in safe mode via a USB drive solved the problem.

What concerns me is ESET 4 I/S was run twice after the laptop was infected and never detected anything! Worse yet, it never prevented the infection.

It's late (11:50 p.m.) and I need some sleep. Tomorrow I'll remove ESET 4 I/S and load NIS 2010. Should I just stay with the basic (free) MBAM software or pay for the "full monty?"

I'd set up NIS to run continuously, with MBAM scheduled to run once per week minimum, or I could manually run a "deep scan."


That's the thing about Malware, there is no single product on the market that can protect you from it. That is why it is wise to:

A). Use a browser that isn't Internet Explorer (as mentioned numerous times in this thread)

B). Run a good antivirus/antimalware program (which you are already doing)

C). Back that up with good passive antimalware protection like Malwarebytes, A-Squared...etc. Do frequent scans with these.

I've had EVERY scanner miss something. Sometimes MANY things. Something MWB doesn't pick-up, A-Squared does. Something A-Squared doesn't pick-up, ESET does. Something ESET doesn't pick-up, MWB does. Something MWB doesn't pick-up, Norton does....etc. It is very frustrating at times. And it is even MORE frustrating when it is an OBVIOUS infection like the one you have, that is staring you in the face and your protection software is telling you everything is hunky dorey and you know full well it isn't!
 
I haven't seen anything since NIS 2009 was installed and I was dbl checking with every product known to man. Now NIS 2010 with MBAM scan daily and Sophos/GMER root kit scans weekly but still nothing after 10 months. It doesn't get any easier than that.
 
Status
Not open for further replies.
Back
Top Bottom