We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

computer has a bad trojan

2

Comments

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Do you remember the name of the trojan MSE detected at all? Did it mention Alureon?
  • spaceboy
    spaceboy Posts: 1,933 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Honestly cant remember, I was expecting MSE to remove it, so wasnt paying much attention. I remember it was classed as "severe" though. All I remember is win32 something...
  • Boot in safe mode with networking by pressing either f8 or f12 just before the windows logo appears, if safe mode with networking appears on the startup repair screen choose it and press enter. This should boot windows from here you can either backup your data and wipe or get rid of the virus and carry on as normal.

    Next download this Rkill from bleepingcomputer (I cant post links due to being new but google rkill.exe download) should be from bleepingcomputer.com

    Next download malwarebytes anti-malware and install it.

    Run Rkill.exe that will stop all unknown processes in windows and in most cases stop the virus from running. Wait until the command window closes and then run Malwarebytes, if it asks you to update do so it's very important.

    Perform a full scan on your computer and once its completed show results and remove the viruses it has found. This should definately get rid of the virus at least.

    Restart the computer and it should boot into windows. If it still goes to startup repair and can't fix the error boot into windows using safe mode with networking and perform a system restore. If for some reason you can't boot with safe mode then get back to me by pm.

    Hope this helps!
  • lee20010
    lee20010 Posts: 153 Forumite
    Funny you say that David, I always remove in safe mode without internet access, as most trojans, adware etc often re-download on removal...annoying as hell
    Debt in June 2011: Debt amount £1248
    Credit score: 406:mad:
    Debt in Jan:Debt amount £0
    Credit score: 715:T

    Got my first credit card in December 2011 :D
  • ah but you cant update the antivirus without internet access and its important its updated because if its a new virus then it won't remove it. Rkill.exe stops all viruses processes allowing the antivirus software to do its job. I suppose you could restart after updating the software though good point.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    If for some reason you can't boot with safe mode then get back to me by pm.

    Why not keep the advice in this thread?
  • fair enough just thought pm might be easier to work with. So far he tried to boot with safe mode and it still fails. I shall get back to this thread very soon.
  • spaceboy
    spaceboy Posts: 1,933 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    I've currently running the avira rescue disc, will report back findings soon...
  • spaceboy
    spaceboy Posts: 1,933 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    First detection - signature of java script virus JS/Redirector.QB

    in Firefox profiles setup.
  • spaceboy
    spaceboy Posts: 1,933 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    TR/FakeAV.AH - Trojan Horse
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.4K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.4K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.3K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.