Annoying virus - Please help !

Author
Discussion

Egg Chaser

Original Poster:

4,954 posts

169 months

Friday 27th August 2010
quotequote all
I've managed to pick up an annoying virus that pops up loads of blatantly fake anti-virus programs telling me that my computer is infected, won't let me open some programs, and won't let me go on any website when using internet explorer.

I've had a very similar virus(es) before and last time I used an anti-malware program to remove it/them. Last night I ran the same anti-malware program but it didn't cure it, although I only used a quick scan. I'm running a full scan now, but any ideas what to do if that doesn't cure it either?

So far its only affected one user account on my computer. I know I'll probably get replies saying that I was downloading porn, but I wasn't and thats why its so annoying banghead

So, any ideas how to cure it before I go and get a hammer from the shed?

ETA - I tried using system restore too, but that didn't work either

Edited by Egg Chaser on Friday 27th August 22:33

philthy

4,689 posts

242 months

Friday 27th August 2010
quotequote all
www.malwarebytes.org

Try that,and let us know how you get on.

Egg Chaser

Original Poster:

4,954 posts

169 months

Friday 27th August 2010
quotequote all
philthy said:
www.malwarebytes.org

Try that,and let us know how you get on.
Thats what I'm using at the moment. Like I said I've tried a quick scan, and that didn't work, so I'm running a full can now.

Although it is a slightly older version that I'm using, so I might try updating it and trying again if it doesn't work.

FourWheelDrift

88,820 posts

286 months

Friday 27th August 2010
quotequote all
Is it trying to get you to install Anti Vir Pro?

If so you need to reboot your PC in safe mode before removing it with MalwareBytes.

Ps. When done go to your appdata\local\temp folder and delete everything in it. It might say a txt file is in use that's fine it's JavaScript and exe files you must get rid of in there.

Edited by FourWheelDrift on Friday 27th August 23:30

Sheets Tabuer

19,167 posts

217 months

Friday 27th August 2010
quotequote all
If it is the same one I got a few days ago from looking at chilli plants on a gardening forum of all things (all the crap I have seen over the years and I get it off a chilli plant picture ffs)

Anyhow, it was called security tool and it was a pain in the arse.

I downloaded rkill to kill the process as it wouldn't let me use taskmanager then downloaded the latest malwarebytes and ran a full scan, it didn't get rid of it so I looked for a program called 123456678.exe in my appdata folder (would be documents and setting on xp) but obviously the numbers were random, once found I deleted it.

Ran malwarebytes again and that clean other parts of it out.

After that I ran hitmanpro which is a cloud av using several scanners and it showed no trace.

I run MSE and ad-aware ad watch live which both picked it up and said they stopped it from running but they didn't, I now run IE if I have to use it in a programme called sandibox, that isolates the IE process and won't let things that run in IE run on your PC.

Fort Jefferson

8,237 posts

224 months

Friday 27th August 2010
quotequote all
Egg Chaser said:
philthy said:
www.malwarebytes.org

Try that,and let us know how you get on.
Thats what I'm using at the moment. Like I said I've tried a quick scan, and that didn't work, so I'm running a full can now.
I had this problem last week,(Security Centre virus) update to the latest version, and it works a treat.

Egg Chaser

Original Poster:

4,954 posts

169 months

Friday 27th August 2010
quotequote all
FourWheelDrift said:
Is it trying to get you to install Anti Vir Pro?

If so you need to reboot your PC in safe mode before removing it with MalwareBytes.
No, but I think thats the one I had before. The one I've got now is called 'Antivirus software alert', and has a message that says:


Virus said:
INFILTRATION ALERT

Your computer is being attacked by an internet virus. It could be a password-stealing attack, a trojan - dropper or similar.

Do you want to block this attack?
|Yes| |No|.
I've also got a popup in the bottom right that says "Windows Security Alert: Application cannot be executed. The file wlcomm.exe is infected. Do you want to activate your antivirus software now?". I also get this as an error message when I try to open nearly any program.

When I try to open any website in internet explorer I get the message "Internet Explorer Warning - visiting ths web site may harm your computer!". It even says that when trying to open my homepage, which is google.

I would post screenshots, but I can't even open paint!

Thanks for the tips everyone, will try them once the scan has finished.

banghead

Who me ?

7,455 posts

214 months

Friday 27th August 2010
quotequote all
If Anti virus Pro -go looking for SUPER ANTISPYWARE, on the net .

va1o

16,038 posts

209 months

Friday 27th August 2010
quotequote all
Had quite a few like these to fix now, seems to be really spreading.

Malware Bytes seems to be the most effective way to remove. Quite a few guides about to help you e.g. http://www.bleepingcomputer.com/virus-removal/remo...

va1o

16,038 posts

209 months

Friday 27th August 2010
quotequote all
Oh and there are now several versions of the rouge anti-virus software under many different names, but they all have the same basic removal procedure which is to kill the processes, restore proxy settings in your browser and run anti-malware bytes.

Fort Jefferson

8,237 posts

224 months

Friday 27th August 2010
quotequote all
Fort Jefferson said:
Egg Chaser said:
philthy said:
www.malwarebytes.org

Try that,and let us know how you get on.
Thats what I'm using at the moment. Like I said I've tried a quick scan, and that didn't work, so I'm running a full can now.
I had this problem last week,(Security Centre virus) update to the latest version, and it works a treat.
PS, You need to boot in safe mode [F5] to download and run the Malwarebytes program.

Egg Chaser

Original Poster:

4,954 posts

169 months

Friday 27th August 2010
quotequote all
va1o said:
Had quite a few like these to fix now, seems to be really spreading.

Malware Bytes seems to be the most effective way to remove. Quite a few guides about to help you e.g. http://www.bleepingcomputer.com/virus-removal/remo...
Thanks for that, will try it now thumbup

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
New problem - I can't open safe mode. Or am I just doing it wrong? (pressing F8 at startup)

Matt Black

420 posts

172 months

Saturday 28th August 2010
quotequote all
I got this st a while back or similar, I restored to a date before the crap, you got to be quick though, restart pc as soon as you can click start then system restore, it should work well it did for me thumbup

Sheets Tabuer

19,167 posts

217 months

Saturday 28th August 2010
quotequote all
Be quick, press f8 a few times when your screen goes black, before the starting windows logo comes up.

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
Sheets Tabuer said:
Be quick, press f8 a few times when your screen goes black, before the starting windows logo comes up.
Thats what I've been doing but still no luck. Tried at least 10 times confused

Sheets Tabuer

19,167 posts

217 months

Saturday 28th August 2010
quotequote all
Which version of windows do you have?

how old is your pc, is it a usb keyboard?

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
Sheets Tabuer said:
Which version of windows do you have?

how old is your pc, is it a usb keyboard?
Windows XP and a wireless usb keyboard

Sheets Tabuer

19,167 posts

217 months

Saturday 28th August 2010
quotequote all
That may be your problem, your keyboard may not be showing up in the OS till it has booted on xp anyhow, can you press delete to get in to the bios?.

Anyhow did you kill the process before you ran the malwarebytes scan?

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
Sheets Tabuer said:
That may be your problem, your keyboard may not be showing up in the OS till it has booted on xp anyhow, can you press delete to get in to the bios?.

Anyhow did you kill the process before you ran the malwarebytes scan?
Yeh I can get into the bios, thats why its confusing me

I've not tried to kill the process yet because I havn't been able to get into safe mode yet