Malware Infection?

kwil

New member
Member
VIP
Local time
1:46 PM
Messages
105
I'd appreciate any advice on the following Malware problem. My girlfriend's computer was 'hijacked' a couple of days ago by some malware which claimed to have 'locked' the computer and demanded payment for 'unlocking'. It was obviously a scam though looked 'official', stating her IP address and location (both wrong, by the way!) When she tried going on the internet, the malware webpage appeared again, taking up the whole screen and allowing no other access, only a hyperlink to 'payment'. She's running Windows 7 Home (64-bit), uses mostly Firefox for web access. I loaded Spyware Blaster, Malwarebytes and Avast antivirus for her some time ago and she updates these religiously as well as running regular scans (I've taught her well!) However, may be just coincidence, but this malware hijack happened a very short time after a Windows Update. I noticed the malware had slipped an entry into 'msconfig' startup. It was showing a row of numbers with an 'exe' extension. So that would explain why it kicked in each time. I tried unticking the entry and rebooting. I saw it remained unticked in 'msconfig', though still there in the list as unchecked. Logging on to the web, the malware page again reappeared. Checking 'msconfig' I saw it had simply placed another 'number' entry with 'exe' extension. Here's what I did to 'cure' the problem, so far working but I'm still unsure whether I could or should do more to prevent this happening again to her. I unplugged her router. Using 'CCleaner'>Tools>Startup>removed offending entries. Manually flushed the 'DNS' cache via 'Command Prompt'>Run As Administrator>typing 'ipconfig/flushdns' Peformed an 'sfc' scan of her hard drive: as above + 'sfc/scannow'. This showed no problem. I also cleared out her Windows>Prefetch folder I then ran a full Avast and Malwarebytes scan of the system. Nothing was flagged. Though I'm aware malware can possibly infect System Restore, I decided to roll back her system to a month ago - thankfully, with my encouragement, she'd already set up daily system image + restore backups! My next move was to run full scans of the new restore - nothing amiss. The computer's been running perfectly since, the malware appears to have gone. However, I'd welcome any comment on the above, any steps I should have taken and other advice or software to include for future prevention. Many thanks
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Motherboard
ASRock H61M/U3S3
Memory
8.00 GB
Graphics Card(s)
Intel(R) HD Graphics Family
Sound Card
(1) Realtek High Definition Audio (2) High Definition Audi
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) ST3500413AS ATA Device (2) ST3500413AS ATA Device (3) Generic- Card Reader USB Device
I had a similar virus recently - fills whole screen, demands payment etc. On re-boot the virus screen was the first to load. I booted into safe mode and ran Malwarebytes which removed some stuff and seemed to fix the problem.

Unfortunately I discovered the virus had deleted my Windows firewall and the Action Center (that warns when firewall is off). I had system restore turned off, so getting the firewall back was not possible. Eventually I backed up my data and re-installed Windows.

You seem to have a better backup plan than I had, but I'd still check your firewall is turned on.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
self build
OS
Windows 7 pro x64 SP1
CPU
Intel i7-2600k o/c to 4.6GHz
Motherboard
MSI Z68-GD80
Memory
8GB Mushkin 1866MHz
Graphics Card(s)
Nvidia GTX 750 Ti 2GB
Sound Card
integrated
Monitor(s) Displays
Liyama ProLite 27"
Screen Resolution
1920*1080 px
Hard Drives
Seagate 2TB
PSU
Coolermaster GX 750W
Case
Antec 300 case + 5 fans
Cooling
Dark Rock Pro
Internet Speed
62Mbit down 18Mbit up
Antivirus
MSE
Browser
Firefox
Other Info
Blackgold BGT3650 Quad HD TV card. Also have various 3770 + 4770K render boxes.
I'd never trust that compromised computer again until a clean windows install (remove disk partitions, recreate and reformat) is performed...you'd never know what registry changes were made, etc.
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 10 Professional / Windows 7 Professional
CPU
Intel i5-3570
Motherboard
Lenovo Mahobay
Memory
16GB DDR3
Graphics Card(s)
AMD Radeon HD 7850 2GB
Sound Card
(1) Realtek HD Audio (2) AMD HD Audio
Monitor(s) Displays
LG LS192WS
Screen Resolution
1440 x 900 @ 32bit color
Hard Drives
(1) SUV300S37A/120G (2) ST3500413AS SATA Disk Device AHCI mode enabled.
PSU
Corsair HX620
Case
Thermaltake V4 Black Edition
Cooling
Cooler Master Hyper 212 + Artic Silver 5 on CPU/GPU
Keyboard
Dell SK-8115
Mouse
Razer Copperhead with MAPED mat (awesome!)
Internet Speed
100 Mbps up/down
Browser
Chrome

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Hi...thanks for taking time to reply.
Jed: firewall OK
OldMX: generally in agreement there, but have now run two more checks: Norton Power Eraser + Threatfire (both free). No infection or suspicious activity.
All in all, I think I've done the best I can.
Much as I like her, I'd rather keep her present preventative methods in place till Armageddon strikes...if ever.
Besides, only then will I show her how much she needs me! :D

Still, what an absolute drag..these scumbag scheisters deserve public hanging or a firing squad!
When big business hijacked the web, that's when computing become more pain than pleasure. Gave rise to other criminals beside the banksters!
Regards
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Motherboard
ASRock H61M/U3S3
Memory
8.00 GB
Graphics Card(s)
Intel(R) HD Graphics Family
Sound Card
(1) Realtek High Definition Audio (2) High Definition Audi
Screen Resolution
1920 x 1080 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
(1) ST3500413AS ATA Device (2) ST3500413AS ATA Device (3) Generic- Card Reader USB Device
Back
Top