From: David Kaye on 4 Mar 2010 14:01 sfdavidkaye2(a)yahoo.com (David Kaye) wrote: >That's now what *I* do. Typo. I meant to say that this is NOT what I do. Windows seldom needs to be reinstalled.
From: Rebecca Chung on 4 Mar 2010 14:04 "Jordon" wrote: > Rebecca Chung wrote: > > For future reference, I found this link useful: > > http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft > > > > It looks like I have to do a bunch of other stuff before I can use the > > Malwarebytes software, so I'll try this once I have access to another > > computer and I'll report back. :) > > Have you tried running Malwarebytes with Windows in Safe > Mode? > > BTW, it would be beneficial if you'd quote the post you're > responding to. Or at least the relevant parts of it. > > -- > Jordon > . > That's what I'm going to do (but Safe Mode with Networking). However, Antivirus Soft is not letting me download anything onto my infected computer, or run any programs I have, so I'm going to have to download rkill and Malwarebytes on a friend's computer later and transfer it with a flash drive to my computer... Sorry for not quoting properly! -Rebecca
From: ~BD~ on 4 Mar 2010 17:48 Rebecca Chung wrote: > For future reference, I found this link useful: > http://www.bleepingcomputer.com/virus-removal/remove-antivirus-soft > > It looks like I have to do a bunch of other stuff before I can use the > Malwarebytes software, so I'll try this once I have access to another > computer and I'll report back. :) I'll wish you the best of luck Rebecca! Have a 'play' by all means, but as someone else has mentioned you'll be better off flattening your machine and re-installing Windows from scratch. It doesn't take long and is good experience! :) -- Dave
From: Leythos on 4 Mar 2010 19:48 In article <hmovp2$oob$1(a)news.eternal-september.org>, sfdavidkaye2 @yahoo.com says... > > =?Utf-8?B?UmViZWNjYSBDaHVuZw==?= <RebeccaChung(a)discussions.microsoft.com> wrote: > > >At this point, I'm pretty much resigned to shelling out the money to have > >someone repair it, as this malware is specifically preventing me from using > >software to remove it... > >But thanks for the suggestion. :) > > If you want to do it yourself, download Malwarebytes on another computer and > copy it to a CD or memory stick or something and then install it on your > computer while in safe mode. If it's the infection I think it is, safe mode > is not affected. Then run Malwarebytes (without the update first) and clean > things out. Then go back to regular mode, run Malwarebytes again and update > it before scanning a second time. It might not work - from a USB drive or other. I ran across a AV 2010 infected computer today, nothing would run (MBAM, SBS&D, SAS, TRJ6.8.1).... Strange thing what that it only infected domain user profiles, not the local admin/user profile - booted as local admin in safe mode, edited registry, rebooted in safe mode + networking, ran MBAM, it cleaned up some, rebooted - still hacked, could not open Task Manager, anti-malware tools... Uninstalled Symantec Corp 10 AV. Safe mode + networking again, installed Avira Antivir, set to highest detection modes, did a full scan, removed several trojans, rebooted, ran a full scan in normal mode, MBAM reinstall, update, run, removed about a dozen thigns... Loaded and ran SBS&D, no signs of anything now... 3 Hours to clean a PC that could have been wiped and rebuilt in 2 hours. -- You can't trust your best friends, your five senses, only the little voice inside you that most civilians don't even hear -- Listen to that. Trust yourself. spam999free(a)rrohio.com (remove 999 for proper email address)
From: David Kaye on 7 Mar 2010 03:32
"Phyllis" <someone(a)microsoft.com> wrote: >I have the same thing on my computer and I just completed the steps from >Bleeping Computer website. No joy, when I went back into normal mode, here >came the Antivirus Soft and all its warnings. You can't run any of >antivirus, malware, spyware programs you have. It won't even let me update >my TrendMicro antivirus. MalwareBytes will install in Safe mode and get the current database if you invoke Safe mode with networking. Forget Trend. Trash it. Install Avast when you're done. Run MalwareBytes at least twice to be sure it got everything. Dunno why it happens; maybe MB uncovers some kind of layers of malware or something, but sometimes you have to run it twice. But in most cases MB will operate just fine in Safe mode no matter what the malware says. The other day, "System Security" malware tried to tell me that it couldn't launch MB, but MB was running right under the warning box! It helps if you can roll back the registry MANUALLY (using an external boot disk) back to at least a week before the infection. Remember to get all 5 files: system, security, software, sam, and default. |