We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help Please Laptop Infected

13

Comments

  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    should run Rkill in Normal mode

    yes, you should get that message if it works
    Ex forum ambassador

    Long term forum member
  • patman99
    patman99 Posts: 8,532 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    No, the whole process works only in safe mode. System Rescue/Tools copies itself into Windows System Restore folders. As these are locked-out to normal access (i.e. virus scans) when Windows is in 'normal' mode, Malwarebytes cannot access them to clean them of the infection. So the rogueware simply re-installs itself the next time you reboot.

    By booting into safe mode, the System Restore folders are not locked, so AV and Anti-malware programs can scan and clean them. This is why all the better AV programs after install, do a first-time scan before Windows loads-up.
    Never Knowingly Understood.

    Member #1 of £1,000 challenge - £13.74/ £1000 (that's 1.374%)

    3-6 month EF £0/£3600 (that's 0 days worth)

  • patman99
    patman99 Posts: 8,532 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    beachlou wrote: »
    I can't get onto the internet in safe mode so I can't download malwarebytes. I have downloaded it to my USB stick (have no disk drive on my alternative laptop) & have tried to run it but the virus is still there. ANy ideas on where to go from here? Thanks


    In 'Safe mode with Networking Support' only wired connections are supported. Wireless support is not built-in to Windows. To download stuff in SMWNS you will need to connect with a cable.

    Btw, I have been using 'ImmunetProject' alongside my regular AV program. It's a cloud-based AV, so adds a 2nd layer of protection without interfering with the regular AV.
    Never Knowingly Understood.

    Member #1 of £1,000 challenge - £13.74/ £1000 (that's 1.374%)

    3-6 month EF £0/£3600 (that's 0 days worth)

  • Al1x
    Al1x Posts: 1,653 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Just wondered where you think you got the virus from?


    We got it from ebay
  • patman99
    patman99 Posts: 8,532 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    As it is a data-miner, just make sure that when you have cleared-it off, you go to all the sites you regularly buy from and change your passwords. Also, keep a very close eye on your Bank statements and at the first sign of fraudulent activity, get your account details and any cards you have changed.
    Never Knowingly Understood.

    Member #1 of £1,000 challenge - £13.74/ £1000 (that's 1.374%)

    3-6 month EF £0/£3600 (that's 0 days worth)

  • patman99 wrote: »
    You should have a list of your Operating systems, above this should be a list something like this -

    Safe Mode
    Safe Mode with Network Support
    Command Line only

    Last Good boot

    Start Windows normally


    If your normally get a menu when you boot asking you to select your O/S, then you need to select your O/S, then hit 'F8'


    I definitely dont have any of those modes come up,(I know I have previously).

    I have been able to download malware and Rkill as suggested but on a Mac to a CD, and cannot get either of them to open. Both come up with messages that the files cannot be opened and have the .exe on the end
    Do you have any suggestions of other ways I can try. thanks
  • huggsy
    huggsy Posts: 59 Forumite
    Just a quick update my daughter in law has just been on the phone and friends of theirs have got it and they were on ebay
  • patman99
    patman99 Posts: 8,532 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker Photogenic
    edited 27 February 2011 at 9:28PM
    I must have been lucky, I have been on Ebay all week and so far no infection.
    Never Knowingly Understood.

    Member #1 of £1,000 challenge - £13.74/ £1000 (that's 1.374%)

    3-6 month EF £0/£3600 (that's 0 days worth)

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Can anyone please explain exactly which page they were on or what they were doing on ebay when it infected them?
    :idea:
  • huggsy
    huggsy Posts: 59 Forumite
    My son was looking through the listings for a new van and his friends were also looking at cars, I have been on ebay myself quite a bit last week and must have been very lucky.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.8K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.2K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.