We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

HELP! Virus...

swebb
swebb Posts: 1,042 Forumite
I have a virus that keeps displaying messages on the bottom right of the screen, telling me I have security warnings - virus etc. It puts a pop up that is scanning my PC and telling me I have viruses and no doubt I'll need to pay to get rid (obviously I cancel).

My own AV is now disabled (Virgin) and pretty much most exe's won't work.

I have tried to download and run the first file referenced in the Malware/Spyware Removal Guide thread. But... the exe won't execute. I'm trying to work my way downwards on the thread for a solution.

In the meantime any help anyone please?

cheers
«13

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Reboot and keep pressing F8 to get into SAFE MODE WITH NETWORKING

    Download MALWAREBYTES (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_malwarebytes_anti_malware/
    Open malwarebytes and goto UPDATE and click 'check for updates'. After its updated goto SCANNER and click PERFORM QUICK SCAN then click SCAN
    Remove everything thats found (needs to be ticked)
    Post the COMPLETE log here AFTER youve deleted everything it finds
    If anything was found then do the exact same but run a FULL scan

    if it still wont work then run FixExe.reg (to allow malwarebytes etc to run). After clicking YES it will be fixed (Nothing will visually happen)
    http://download.bleepingcomputer.com/reg/antivirus-vista-2010/FixExe.reg

    And attempt malwarebytes again

    assuming it works -
    reboot into NORMAL mode

    Download HIJACK THIS (Make sure you click 'DOWNLOAD LATEST VERSION')
    http://www.filehippo.com/download_hijackthis/
    Click MAIN MENU then DO A SYSTEM SCAN AND SAVE A LOGFILE(Takes seconds) then post the log so we can see whats running
    (do NOT do anything else with Hijack but scan and post the FULL log)
    If you get a message that you cant write to the hosts file then Press the SHIFT key, and whilst holding it RIGHT CLICK and select RUN AS (admin)
    :idea:
  • swebb
    swebb Posts: 1,042 Forumite
    In progress now...
  • swebb
    swebb Posts: 1,042 Forumite
    I get a pop up saying:

    Windows cannot completet the installation in safe mode. To continue installing windows, restart the computer.

    Then it's a restart as usual.

    how about if I download the files and boot in normal safe mode after i.e. put the downloaded files in a folder, boot into safe mode and run them from there?
  • swebb
    swebb Posts: 1,042 Forumite
    As I guessed... I can't get into safe mode either.

    I've downloaded the files. Can they be run in another mode?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Have you run the 'fixexe' file?
    :idea:
  • swebb
    swebb Posts: 1,042 Forumite
    aliEnRIK wrote: »
    Have you run the 'fixexe' file?

    can I do that in 'normal' mode?
  • hannoja
    hannoja Posts: 2,015 Forumite
    Part of the Furniture Combo Breaker
    Would an online virus scanner/cleaner help..? (if you can get online okay)

    BitDefender might be worth a shot, though it hasn't found any 'nasties' on my machine, so I can't vouch for it's 'cleaning' techniques..
  • http://www.f-secure.com/en_UK/

    a very good online scanner
    "If you no longer go for a gap, you are no longer a racing driver" - Ayrton Senna
  • swebb
    swebb Posts: 1,042 Forumite
    I'm running an online scan now which is taking ages... 12 hours to go.

    I have also run fixexe BUT!!! it won't run. Message "File regedit.exe is infected by W32/Blaster.worm. Please activate spyware protection to protect your computer" i.e. the same sort of message for pretty much any exe.

    HELP!!
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Everything your dowloading must be getting infected (or its a false message)

    Your going to need to use another (none infected) computer

    Download the FREE version of DR WEB
    http://www.freedrweb.com/download+cureit/gr/
    Burn it to a cheap cd or put ona uSB stick tha has a PROTECTION switch on it (so that when its inserted, your computer cant infect it) and run the program
    Turn your anti virus OFF
    Click CANCEL to the 'Would you like to read purchase terms now?' message
    Click START click OK
    It will auto QUICK scan
    After that set to scan the WHOLE computer and press the 'play' icon
    ***DO NOT UPGRADE TO FULL VERSION***

    If you cant run it in either mode then your going to have to create an actual bootable disc (we can get to that later if this fails)

    If you cant get onto another computer just now then press CTRL ALT and DEL to bring up TASK MANAGER and try to determine what the nasty is and END THE PROCESS to try to continue with malwarebytes etc
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.7K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.