Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
1/5/2012 9:40:57 AM EDT
some of you might remember that i posted a couple weeks ago about my e-mail having been hacked, and spam mail having been sent from my account.  well, it gets worse!  i believe i've got some very bad trojan on my laptop

-on two occasions, my laptop started playing music while sitting closed and idle.  i pick it up and open it, and the damn thing for sure apears idle.  ctl/alt/del causes it to stop.
-sometimes, when i google for something, and click the resulting link, i get redirected to some kind of ad website.  and then it wont let my get back to my gooogle results by hitting back.
-i ran a malware bytes scan, found 3 trojans, and erased them.  the problems still persisted
-i ran an ad-aware scan, found nothing.  i realized that i hadn't updated my ad-aware, now whenever i attempted it, its like the trojan knows what i'm trying to do, and it hi-jacks ad-aware and shuts it down before it can update.
-cpu usage shows 100% and my laptop sound slike its just going all the time.
-it appears to be blocking windows updater

so, what do i do about the trojan that blocks the scanning software from running properly??????  help!!!! i want my laptop back!!!!

1/5/2012 10:16:28 AM EDT
[#1]
update malware bytes, install and update avast anti virus, turn computer completely off and then turn it back on. Immediately after clicking the power button to turn it on start hitting the F8 key at the top of your keyboard. Select safe mode from the list and run avast and malware bytes until both come back clean.
1/5/2012 10:16:46 AM EDT
[#2]
tdsskiller  is pretty good at finding things that are running right now, that you do not want to have running.

http://kaspersky-tdsskiller.en.softonic.com/

1/5/2012 11:19:53 AM EDT
[#3]
hook your HDD up to another machine and transfer documents, then format and reinstall windows. I have a 64bit 7pro cd you can use if you want with volume licensing
1/5/2012 11:38:21 AM EDT
[#4]
Quoted:
hook your HDD up to another machine and transfer documents, then format and reinstall windows. I have a 64bit 7pro cd you can use if you want with volume licensing


^ this. Once infected, it is impossible to guarantee it is clean. And since I imagine you do your online banking, etc, on this computer - I would suggest reformatting and starting from scratch. Copy over documents and pictures, etc (after you have new and updated AV/antimalware software loaded).

Change your passwords to online sites too - and do it from a different system.

Dan
1/5/2012 11:51:26 AM EDT
[#5]
the above suggestions are good too. I am 100% dependant on having a computer for work so I always keep preloaded HDDs as spares. One gets compromised and it gets dropped in the range bag and a spare gets swapped in.
1/5/2012 12:48:45 PM EDT
[#6]
just reformat that bad boy and start over, you will never get it clean enough for it to be 100% secure again.

And this is what i tell all my end users

1. DO NOT open emails if you do not know who sent them (even if they have shiny flashing boxes telling you congrats you are now a billionaire)
2. Don't go to those free game website they will hose you PC real fast, seriously porn is safer to download than games
3. It is always user error when you get a virus you did do something your PC doesn't contract viruses all on its own

And as far as passwords go you have two choices make it easy to remember and have your identity stolen OR make a secure password at least 9 digits long (i have a 9 digit and a 14 digit that gets changed at random intervals). just pick out random letter and numbers, please do not use SS numbers, birthdays, pets, or anything familiar. Create a 9 digit password with a few uppercase and lower case letters with some numbers mixed in, for sites that allow it i use a 14 digit password with upper case, lower case, and special characters both password i made up out of thin air much safer that way.

Do not write it down either thats cheating i have to get rid of passwords taped under keyboards and stuck in drawers all the time.
1/5/2012 5:26:43 PM EDT
[#7]
all of this reformat stuff is true.

i support my extended families and friends computers. one person in particular is bad about getting viruses. he has an older PC with an 80 gig IDE drive. i got tired of pulling his drive out and mounting and scanning it so last go round a bout an 80 gig drive and once i had his system setup i cloned it to the second drive. low and behold it craps out on him, i pull the 2nd drive out of a drawer, slap that sucker in, reboot and go. then recopy 2nd drive to reformatted older drive.

i dont believe ive ever simply cleaned up an infected drive. it takes too long and never seems to get it all. id pre-scan his non os files, copy them to a holding disk, reformat and install his OS then copy his data files back over.

1/5/2012 5:52:50 PM EDT
[#8]
If you can identify the trojan you can get rid of it. But it may be a rootkit. Try Sophos or Kapersky. We had an office pc that did all that - Sophos found the root kit and killed it. The pc was fine.
1/6/2012 5:39:16 AM EDT
[#9]
Quoted:
If you can identify the trojan you can get rid of it. But it may be a rootkit. Try Sophos or Kapersky. We had an office pc that did all that - Sophos found the root kit and killed it. The pc was fine.


Would you bet $1M on it? There are some very sophisticated kits out there that even up to date AV/AM software won't find. I wouldn't risk it.
1/6/2012 5:56:28 AM EDT
[#10]
It can be tough. Went through 14 programs on the office pc before I found Sophos. Had to boot to safe mode without LAN but did kill it. Would have been easier to wipe and reinstall but we could not find some of the software discs we needed so could not wipe everything.
1/6/2012 9:36:54 AM EDT
[#11]
ugh, so its pretty bad huh?  i hope i can find the system disc that came with my laptop.  i might by one of those really big solid state drives to back up all of my photos and do it.  ughhhhhhhhhh...
1/6/2012 9:44:40 AM EDT
[#12]
If the pc is not allowing you to go to the website you have chosen - download from another pc and burn to disc or usb stick.
Follow their instructions carefully.
It takes some time but worked for me on the office pc that was toasted.
If you are on the westside I can help if I am in town when you are free.
LINK
CNET analyzer:
LINK