Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
12/11/2011 9:46:15 AM EDT
My daughter just called me and said she can't do anything with her lap top.

She says it won't let her go on the Internet saying it's too risky. (virus pop up) Wants her
to buy a download first, which I know is a scam. (did it before)

We bought a year subscription to Norton about five months ago, but I guess it didn't catch this.

How can she get around this thing? Sounds like she's stuck.

Thank you for your help in advance.

kz
12/11/2011 9:49:29 AM EDT
[#1]
Download malwarebytes on another machine, start laptop in safe mode with networking, install and update malwarebytes, run it.




12/11/2011 9:54:43 AM EDT
[#2]
Run Malwarebytes Anti Malware, Lavasoft AdAware, Spybot S&D and antivirus software in succession several times, preferably in safe mode.

May have to download them onto a USB drive from another PC and then put them on the laptop.
12/11/2011 9:56:01 AM EDT
[#3]
I have used Microsoft Security Essentials with great success.  Got rid of a couple Trojans one of my dipshit friends got on this machine.  Granted, I had to restore it from the day before, before Windows would let me do anything.  But MSE is all I use, it got rid of the Trojans after I restored the entire PC.
12/11/2011 10:04:01 AM EDT
[#4]
Download rkill from bleeping computer  and superantispyware or malwarebytes. Read the instructions.
12/11/2011 10:10:31 AM EDT
[#5]
Quoted:
Download rkill from bleeping computer  and superantispyware or malwarebytes. Read the instructions.


Aren't rkill, Hitman and things like that best used under specific direction by someone who knows what they're doing?


OP, if your kid can get online on another PC, bleeping computer is a good site to go to.  start a thread on there describing the problem and someone will be along to personally help out.
12/11/2011 10:14:44 AM EDT
[#6]
Just dealt with this a few days ago, it evaded most of my attempts to get rid of it including most of what has already been mentioned.  What finally got it was Avast antivirus, which has a "boot time scan" option.
12/11/2011 10:16:44 AM EDT
[#7]
Quoted:
Quoted:
Download rkill from bleeping computer  and superantispyware or malwarebytes. Read the instructions.


Aren't rkill, Hitman and things like that best used under specific direction by someone who knows what they're doing?


OP, if your kid can get online on another PC, bleeping computer is a good site to go to.  start a thread on there describing the problem and someone will be along to personally help out.


Na it's easy
http://www.bleepingcomputer.com/forums/topic308364.html
12/11/2011 10:20:59 AM EDT
[#8]
Get the exact text on the message.  Google the text.  It will tell you the virus, or malware.  Deal with the specific infection.  Don't wast time running random shit.  It might work but you need a targeted approach.
12/11/2011 10:39:45 AM EDT
[#9]

Do the following:









1. Restart your computer, while restarting, press and hold
down the F8 key.  If you hear a clicking
sound, release the key, hit the enter ky then and immediately press F8 down again.  Repeat until you get to a screen that lists a
number of options.









2. Select start in Safe Mode with networking,









3. Select the account named administrator if possible.









4. After startup, go online and download the following
programs to your desktop:  RKILL
http://download.bleepingcomputer.com/grinler/rkill.exe”









COMBOFIX
http://www.google.com/url?sa=t&source=web&ct=res&cd=2&ved=0CA0QFjAB&url=http%3A%2F%2Fwww.combofix.org%2Fdownload.php&ei=DaTIS52dNJW09gS-3qSZCw&usg=AFQjCNHZOzvWVDVokuL0QVCBJjBrFheaCQ&sig2=r8HfGs5f-SLl62p-qREPfg”









MALWAREBYTES: http://www.malwarebytes.org/mbam.php









5. Run RKILL it will stop the processes









6. Run Combofix, it will install the recovery console and
update itself, and then run a full scan – let it complete.









7 After that install and run Malwarebytes in quickscan.  That should remove the problem and fix the
registry.









8.  That evening run a
complete scan with Malwarebytes









If you can't get into the administrator account, download
these files from another computer and copy them to the desktop.  If you can, start in safe mode, log in to the
computer and as soon as you can, run rkill, continue to try running it as soon
as you see your desktop.  It will kill
the process and you can proceed from there.



12/11/2011 10:44:51 AM EDT
[#10]
Quoted:
Get the exact text on the message.  Google the text.  It will tell you the virus, or malware.  Deal with the specific infection.  Don't wast time running random shit.  It might work but you need a targeted approach.



This.  Broad-spectrum sweeps don't always catch everything.  

Also, check out something called The Cleaner.  It's at moosoft.com.  Best trojan cleaner I've ever used.

If anyone is so inclined, my advice is to get familiar with Task Manager.  Once you get a feel for what should be running, go to process->view->select columns and check "PID."   After, hit windows-R and type "cmd" and then type "netstat -aon" and it will list all connections from your computer.  From there, you can look at the PID in the command window, and identify the process in task manager.  You can hunt-and-sniff out things you think might be on your machine and dialing out, etc.  Handy stuff to snoop out what's going on.
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.