Windows 7 Forums


Reply
Thread Tools

MSE was disabled by a virus attack

 
 
clifford_cooley clifford_cooley is offline
(c_c)
clifford_cooley's Avatar
Join Date: Mar 2009
Location: Arkansas, USA
Posts: 4,441
Thanked: 924
 
      08-27-2010
Thumbs down for:
  • Microsoft Security Essentials
After receiving the virus I had no control of the system. Task manager would not open. Computer properties would not open. Every time I tried to open a system folder or app, I was presented with a message stating the app I was trying to use had been contaminated. At the same time there appeared to be an application scanning my computer that I had not seen before. During all of this I was also presented a less than authentic security message from the Taskbar stating my security had been compromised, and was asking me if I wanted to allow this scanning program access to do something (I don't remember what the exact phrase was).

Thumbs up for:
  • Safe Mode
  • CCleaner
  • Malwarebytes
  • System Restore Points
Not being a stranger to the way these attacks operate, I knew that I only had one option. Ignore all messages and re-boot into Safe Mode. Once in Safe Mode, I could then run cleaning programs. First I ran CCleaner then Malwarebytes. Running CCleaner first will remove the trash so that the malware scanner is not scanning anything that would not need to be scanned. After removing all trash from my system, I then performed a Recovery by falling back on a System Restore Point. Once I realized Safe Mode was my only option, I was back to business in a matter of 10 minutes.


While MSE has caught a few attempts in the past, this time one got through. I will still continue to support and use MSE because, no Anti-virus application is 100% effective.
 
Reply With Quote
 
 
 
 
Mychael Mychael is offline
Established Member
Mychael's Avatar
Join Date: Mar 2010
Location: Melbourne, victoria
Posts: 1,122
Thanked: 87
Send a message via ICQ to Mychael Send a message via MSN to Mychael Send a message via Skype™ to Mychael
 
      08-27-2010
Good reason to have at least 2 AV going.
 
Reply With Quote
 
Cypress Cypress is offline
Member
Join Date: Aug 2010
Posts: 66
Thanked: 11
Send a message via MSN to Cypress
 
      08-27-2010
Thats one of the deficiencies of antimalware apps - they are reactive, and when they react, your system is compromised. And what were you doing to get infected?
 
Reply With Quote
 
Cypress Cypress is offline
Member
Join Date: Aug 2010
Posts: 66
Thanked: 11
Send a message via MSN to Cypress
 
      08-27-2010
Quote:
Originally Posted by Mychael View Post
Good reason to have at least 2 AV going.
In real time, maybe not. As a second opinion, its OK.
 
Reply With Quote
 
Mychael Mychael is offline
Established Member
Mychael's Avatar
Join Date: Mar 2010
Location: Melbourne, victoria
Posts: 1,122
Thanked: 87
Send a message via ICQ to Mychael Send a message via MSN to Mychael Send a message via Skype™ to Mychael
 
      08-27-2010
I run AVG and MSE no issues.
 
Reply With Quote
 
clifford_cooley clifford_cooley is offline
(c_c)
clifford_cooley's Avatar
Join Date: Mar 2009
Location: Arkansas, USA
Posts: 4,441
Thanked: 924
 
      08-27-2010
Quote:
Originally Posted by Cypress View Post
And what were you doing to get infected?
I was searching for something. I believe I was hit by a flash based virus from one of the sites in the search list. But then again I have no evidence.
 
Reply With Quote
 
Cypress Cypress is offline
Member
Join Date: Aug 2010
Posts: 66
Thanked: 11
Send a message via MSN to Cypress
 
      08-27-2010
Quote:
Originally Posted by Mychael View Post
I run AVG and MSE no issues.
Surprising.
 
Reply With Quote
 
Nibiru2012 Nibiru2012 is offline
Quick Scotty, beam me up!
Nibiru2012's Avatar
Join Date: Oct 2009
Location: Planet X
Posts: 4,739
Thanked: 1055
 
      08-27-2010
There is a new malware "scanner" trojan out that mimics MSE and then suggests buying and downloading one of five suggested programs, which are junk to begin with.

In hindsight I should have posted a thread about it, but I didn't. I thought just about everyone here would catch it.

Although this sounds like what hit Cliff is not that scenario.
 
Reply With Quote
 
davehc davehc is online now
Super Moderator
davehc's Avatar
Join Date: Jul 2009
Location: Denmark
Posts: 1,807
Thanked: 394
 
      08-27-2010
This is, maybe, the one to which Nibs refers?
http://www.brighthub.com/computing/s...les/69281.aspx

But, if not too private, can you remember what you were searching for, Cliff? I would be willing to give it a go. I am happy with MSE but would like to check out a bug, if there is such, for MS's information.
 
Reply With Quote
 
clifford_cooley clifford_cooley is offline
(c_c)
clifford_cooley's Avatar
Join Date: Mar 2009
Location: Arkansas, USA
Posts: 4,441
Thanked: 924
 
      08-27-2010
I was searching info on the movie "Iron Man 2" at that time. I can not remember which site I received the virus from.

To be honest I was jumping from one site to another pretty quickly when things started happening, so I couldn't point to one specifically anyway.

My main goal here was to point out the procedure I used to remove the virus.

I know the same procedure will not work in every instance. However it will work in many situations where you find yourself with a virus. Allot of times you may only need to use a restore point and disk cleanup then removal of the virus. This time I did not have that option without booting to Safe Mode.
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
slow downloads johnb1 Windows 7 Support 13 08-28-2010 11:08 AM
Top Clinton Official: Only A Terror Attack Can Save Obama Nibiru2012 Off-Topic Discussion 3 07-15-2010 05:46 AM
New attack bypasses EVERY Windows security product Jeffreyobrien Security 14 05-19-2010 05:11 AM
Kaspersky Anti virus Shirley Windows 7 Support 3 04-05-2010 09:58 PM
Kaspersky Virus 2009 bibleman Security 3 02-20-2010 06:03 PM


All times are GMT +1. The time now is 10:13 PM.
W7Forums is an independent website and is not affiliated with Microsoft Corporation.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33