We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

I have a serious infection

Options
Hi Guys.. Picked up a prety agressive virus/malware from an email attachment.

The infection has shut down and isolated Windows Firewall and also done the same to Malwarebytes. Thinking i could outsmart the it, I downloaded installed and updated a new version of Mbam and then run a scan. About 20 seconds into the scan the virus shut it down completly and isolated it again.

As far as i can make out its an advertising infection within the two browsers, ie & FF. It has also added a toolbar that will not uninstall.

It looking more like a format but thought id ask here incase anyone has come across this nasty bit of Sht before.

Thank in advance for any tips..
«13456714

Comments

  • GunJack
    GunJack Posts: 11,834 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    can you try MBAM in Safe Mode ???
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • samdd
    samdd Posts: 1,344 Forumite
    GunJack wrote: »
    can you try MBAM in Safe Mode ???

    Hi. thanks for your reply. I thought the same thing and tried the safemode option. It appears that once the infection has isolated mbam then its totally isolated becase it give the same message in safemode and will not load.

    Its a pretty smart virus becasue when you type into Google any words to do with virus removal etc the browswer goes bannans and throws huge amounts of adds at you..

    Is there another way? id hate to start over agin on a fresh install..
  • GunJack
    GunJack Posts: 11,834 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    edited 26 September 2011 at 3:04PM
    either:-

    1. download and save to desktop Combofix (but in the download process rename the file qwerty) and see if it'll run.

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    2. download RKILL to desktop (as above, rename during download), run that, then mbam.

    3. http://www.avira.com/en/support-download-avira-antivir-rescue-system

    on another pc, download the .iso file from this page, and burn it to a disk using nero, imgburn, etc (a burning prog whch will burn .iso files) Reboot the infected pc from this disk, update and run a scan. Chances are it'll get enough of the infection for mbam to get the rest later :)

    any of these may work....
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • samdd
    samdd Posts: 1,344 Forumite
    GunJack wrote: »
    either:-

    1. download and save to desktop Combofix (but in the download process rename the file qwerty) and see if it'll run.

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    2. download RKILL to desktop (as above, rename during download), run that, then mbam.

    3. http://www.avira.com/en/support-download-avira-antivir-rescue-system

    on another pc, download the .iso file from this page, and burn it to a disk using nero, imgburn, etc (a burning prog whch will burn .iso files) Reboot the infected pc from this disk, update and run a scan. Chances are it'll get enough of the infection for mbam to get the rest later :)

    any of these may work....

    Combo fix and RKill will download but dont give the option to Save-as, they go directly into downloads. Should i cut them over to desktop and remane the source file?
  • Download to a clean computer and rename before transferring.
  • TakeThis
    TakeThis Posts: 2,909 Forumite
    System Restore no good?

    Windows 7?

    These instructions will assist you:

    Download and save this Windows 7 Recovery Disc Image to a working computer if Windows 7 32 bit or this image if Windows 7 64 bit.
    Next, download and install ImgBurn(No need to install the Google Toolbar. Remove the relevant tick). Burn the Image to Disc. Use this guide(skip step 2b)

    You can then use these instructions to assist you with a System Restore. Further to that we will have access to the Registry via Command Prompt.

    System File Checker
  • dacouch
    dacouch Posts: 21,636 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    GunJack wrote: »
    either:-

    1. download and save to desktop Combofix (but in the download process rename the file qwerty) and see if it'll run.

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    2. download RKILL to desktop (as above, rename during download), run that, then mbam.

    3. http://www.avira.com/en/support-download-avira-antivir-rescue-system

    on another pc, download the .iso file from this page, and burn it to a disk using nero, imgburn, etc (a burning prog whch will burn .iso files) Reboot the infected pc from this disk, update and run a scan. Chances are it'll get enough of the infection for mbam to get the rest later :)

    any of these may work....

    The mbeep is great and sorted me out when I had an agressive bug, one tip I found helpful is to open internet explorer or avira or mwarebytes etc etc as "Administrator" (In vista or windows) as this normally fools the bug and allows you to run the programs.
  • scotty1971
    scotty1971 Posts: 1,732 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    try the GUM clinic
  • samdd
    samdd Posts: 1,344 Forumite
    This infection a very smart malware program. Im having to work in Safe mode becasue windows is crashing (BSOD) If the malware even gets a sniff im trying to remove it then it throws a total wobbly and shuts the computer or BSOD. It's even reading what im typing into google and replaces the google webpage with simular finds.

    I only have one pc available to me so unable to dowload to a clean machine.

    I downloaded Combofix and RKill by changing the download options in FF but both were grabbed and uninstalled by the malware while running.

    I found a portable version of Mbam and downloaded to a mem stick and tried that but again, the malware grabs it and closes it down. Something ive noticed is that the malware is reproducing itself by grabbing folders and converting them into EXE's... if i double click to open the folder it runs a EXE infection..

    This isnt good and i feel ive got no other option but to format the Hdd and run a fresh install.
  • samdd
    samdd Posts: 1,344 Forumite
    dacouch wrote: »
    The mbeep is great and sorted me out when I had an agressive bug, one tip I found helpful is to open internet explorer or avira or mwarebytes etc etc as "Administrator" (In vista or windows) as this normally fools the bug and allows you to run the programs.

    What is Mbeep?
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.9K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.9K Work, Benefits & Business
  • 598.8K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.