Virus Warning - linked from Wrecked Exotics

Virus Warning - linked from Wrecked Exotics

Author
Discussion

Rollcage

Original Poster:

11,327 posts

193 months

Monday 29th November 2010
quotequote all
I was looking through the latest WE email and clicked on a link to a story about the Geely/Rolls Royce situation earlier in the year and seem to have picked up a bloody virus that means that I cant seem to use my lappy for t'internet under my user profile. Everything I try and do anything it just either says the file is corrupted or , when trying to view web pages, just takes me to an Anti-virus site! Ironically, it seems the site has somehow originated the virus!

The other user accounts seem to work OK (hence this post) - I have run a virus scan, which has not detected anything.

Any ideas how to get my main (administrator) profile up and running again?

Cheers

FourWheelDrift

88,557 posts

285 months

Monday 29th November 2010
quotequote all
If it's the Anti-virus "virus" that stops you running your AV software and other things you have to do a few things.

You need Malwarebytes to remove it on that pc and rkill to kill the processes if it still stops you running Malwarebytes under safe mode and possibly TDSSKiller from Kaspersky Labs if you want to really make sure it's all gone.

Firstly reboot in safe mode - F8 at windows boot up.

Open Internet Explorer, go to internet options, then connections tab, then Lan settings and deselect the proxy settings. (There might be something there).

Then you need to run rkill to stop any nasty processes.

Run Malwarebytes. That should do it.


rkill - http://www.technibble.com/rkill-repair-tool-of-the...

Rollcage

Original Poster:

11,327 posts

193 months

Monday 29th November 2010
quotequote all
Cheers FWD thumbup

I will give it a go!

FourWheelDrift

88,557 posts

285 months

Monday 29th November 2010
quotequote all
Found the website I got that from, I had it on a PC a few months back I think it was delivered via a Flash advert. Which is why I always run Flash block and hate any websites that use it. They have to be very obviously non-malicious to have it allowed.

http://www.bleepingcomputer.com/virus-removal/remo...


Ps. I remember now the rogue Flash vid/advert was via on one of those Russia-English web pages that listed odd and crazy photos and news stories.

Edited by FourWheelDrift on Monday 29th November 19:35

Rollcage

Original Poster:

11,327 posts

193 months

Monday 29th November 2010
quotequote all
All sorted now, thanks very much for the help FWD, PH is such a great place! (Not that I needed reminding of course!)