We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Vista virus/trojan help please

2

Comments

  • stilltheone
    stilltheone Posts: 2,131 Forumite
    He's just Trolling.....:whistle: Perhaps one of the kids got a hold of his sign-in details.
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    Hello I'm back! Have just downloaded via one of RussJK's links and am in the process of carrying out the full scan.

    Once it is done will the pc be back to how it was or do I have to do something to revive it? Sorry if it is a silly question!
  • RussJK
    RussJK Posts: 2,359 Forumite
    Not a silly question, although the info is in the bleepingcomputer link :) Malwarebytes will just remove (most) of the malware responsible for hiding all the files. Afterwards you'll have to run something like unhide to make the files visible:

    http://download.bleepingcomputer.com/grinler/unhide.exe

    There may be things also there that Malwarebytes can't get at, but can deal with that later. Better to do a quick scan initially, as an infected system will cause the full scan to run even slower, and full scan rarely finds more than the quick scan.
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    RussJK wrote: »
    Not a silly question, although the info is in the bleepingcomputer link :) Malwarebytes will just remove (most) of the malware responsible for hiding all the files. Afterwards you'll have to run something like unhide to make the files visible:

    http://download.bleepingcomputer.com/grinler/unhide.exe

    There may be things also there that Malwarebytes can't get at, but can deal with that later. Better to do a quick scan initially, as an infected system will cause the full scan to run even slower, and full scan rarely finds more than the quick scan.

    Thanks, have been running the full scan for about 10 mins now, do you think I would do better to abort it and choose quick scan?
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    edited 14 June 2011 at 2:39PM
    RussJK wrote: »
    May as well keep going by this point :)

    While you are waiting, you may as well set your folder options to view hidden files just for the sake of seeing that everything is still there:
    http://www.bleepingcomputer.com/tutorials/tutorial130.html

    Done it and icons are back on screen. :):):)

    Once scan has finished and its all sorted should I restore the settings back as they were?
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    edited 14 June 2011 at 3:17PM
    I have a threat detected - trojan horse generic23.A.AU
    detected on open

    Do I heal it or move it to vault?

    Actually just realised the threat has shown up on an AVG resident shield alert.

    the process name is C:\ProgramFiles\Malwarebytes' Anti-Malware\mbam.exe
    process id: 5980
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    RussJK wrote: »
    Move it to vault. What program found it? What file, folder, etc.

    File name: C;\ProgramData\22535952.exe

    as I said this is showing on an AVG alert, but the malware scan is showing it has found 3 objects infected so far.
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    RussJK wrote: »
    Well you edited your post with that extra info after I'd already replied ;)

    I wouldn't put Malwarebytes into the quarantine! Just ignore AVG or turn AVG off.

    I know, sorry, I hadn't put it into the vault yet anyway as I knew I was editing! So does it still need to go there or heal it?
  • busiscoming2
    busiscoming2 Posts: 4,461 Forumite
    Part of the Furniture 1,000 Posts
    Or push the ignore button :o
  • RussJK
    RussJK Posts: 2,359 Forumite
    I know, sorry, I hadn't put it into the vault yet anyway as I knew I was editing! So does it still need to go there or heal it?

    Neither, just turn AVG off completely. Who knows what it'll do if it "heals" malwarebytes.

    Uninstall AVG and then run the removal tool:
    http://www.avg.com/gb-en/download-tools

    Malwarebytes is likely to be fine.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.5K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.5K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.5K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.