Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

So my mother-in-law got a virus

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU
 
lazarus Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-13-11 12:18 PM
Original message
So my mother-in-law got a virus
She's running Vista (I know), with Microsoft Security Essentials, and does most of her surfing in AOL. She got an email purportedly from IRS.gov, clicked on a link inside, and boom.

It's the pc performance and stability analysis report, I believe.

Here's the issue. When she tries to run MSE, it gives an error message. Explorer has disappeared, but she still has Firefox. When she tries to download malwarebytes, another error message.

Since all the advice I'm finding on Google involves doing those two things, I'm kinda stuck. I'd put MWB on a thumb drive and put it on her pc that way, but she's two states away.

Help please.

:hi:
Refresh | 0 Recommendations Printer Friendly | Permalink | Reply | Top
Earth Bound Misfit Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-13-11 02:49 PM
Response to Original message
1. Try this...
http://www.bleepingcomputer.com/download/anti-virus/rkill
Program Description:

RKill
is a program that was developed at BleepingComputer.com that attempts to terminate known malware processes so that your normal security software can then run and clean your computer of infections. When RKill runs it will kill malware processes and then import a Registry file that removes incorrect file associations and fixes policies that stop us from using certain tools. When finished it will display a log file that shows the processes that were terminated while the program was running.

As RKill only terminates a program's running process, and does not delete any files, after running it you should not reboot your computer as any malware processes that are configured to start automatically will just be started again. Instead, after running RKill you should immediately scan your computer using some sort of anti-malware or anti-virus program so that the infections can be properly removed.


RKill - What it does and What it Doesn't - A brief introduction to the program http://www.bleepingcomputer.com/forums/topic308364.html
Printer Friendly | Permalink | Reply | Top
 
haele Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-13-11 05:46 PM
Response to Original message
2. She is in a malware process loop, getting banners overlaying all windows -
Edited on Thu Oct-13-11 05:46 PM by haele
I got her onto bleepingcomputer.com through firefox, but she couldn't see past the pop-up banner that instantly covered it. Banners also popped up over other internet sites. It's telling her that her hard-drive is defective, personal data can be lost, yadda, yadda, and after she hit the "fix it" button (which she had done before calling us), it asked for her computer registration number and visa card number. hmmmm....
I was working with mom over the phone to see what was going on; we checked her programs, and Microsoft Security Essentials had disappeared from her directory, as well as any other security programs besides the shell of the long-defunct Norton. What worries me is that this has been on her computer since last night, when she opened the e-mail just before she went to bed. She apparently was able to use the computer fine in the morning initially, she checked her bank account( :( ) and logged onto the AO-Hell e-mail account she was using, and it was when she was in the middle of checking that, that all the banners and flashing icons started popping up on her screen.

Hopefully, it's just a phish looking for a credit card number, and not a keystroke logger or serious trojan. I did what I could, but between the distance, her inexperiance and uncertainty with the computer, and the damn banner blocking everything, she's decided to call in a computer tech to clean it up. Luckly, she does most all her banking in checks or face to face (she does nothing online financially other than checking the balances), and her credit cards are not credit/debit linked to one of her accounts, but full on credit.

I would have tried to create a new user account for her and had her move over there while figuring what to do with her virus, but she was so distressed after a half hour or so over the phone, she decided it would be better to have someone over to show her what to do as they were fixing it for her.

Any ideas if this was more than just a credit card phishing trip? I'm scared it might be a more serious trojan.

Anyone know a good tech in Albuquerque?

Haele
Printer Friendly | Permalink | Reply | Top
 
steve2470 Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Oct-13-11 06:24 PM
Response to Reply #2
3. can she afford to just nuke the hard drive ?
Or does she have really important data that has to be saved ?

If so.... I know no one in Albuquerque, sorry.
Printer Friendly | Permalink | Reply | Top
 
haele Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Oct-14-11 07:06 AM
Response to Reply #3
4. Well, we did do a back-up on thumb drives for her four weeks ago -
But the computer was Dad's domain for the most part, and there's a lot of stuff on there that she still has to go through, as well as anything she may have saved from e-mail since we did the back-up.
I don't think she wants to nuke the hard-drive; not only is there a sentimental issue going on, she hasn't used a computer since 2002 when she retired from the university, and she's feeling very lost about the whole thing. I think they were still on Windows 3.1 or 95 at best when she left, so she hasn't caught up with much of the technology yet.
She's terrified of "blowing the computer up".

Hopefully, a tech will be able to fix it.

Haele
Printer Friendly | Permalink | Reply | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Jan 02nd 2025, 07:53 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » DU Groups » Computers & Internet » Computer Help and Support Group Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC