Nightmare virus (windowsclick.com) and sounds like spyware/malware issues too.......

redgtxdi

Diamond Member
Jun 23, 2004
5,464
8
81
OK, I'm gonna cut/paste what she wrote me last which should self-explain our first 2 e-mails to eachother........

Ok. Uninstalled AVG. Then tried to download malwarebytes, and acted like it downloaded but didn't. So installed Avira Antivir, and scanned full scan. While scanning, I was trying to look up stuff on that computer, and kept rerouting everything to windowsclick.com, which is something called a UACD.sys virus. So I found this antispyware website that told me to delete the windowsclick.com virus by downloading avenger, and posting a script to delete the virus, and would auto reboot. Then it said to download Malwarebytes. Kept doing that, and the icon was on my computer, but wouldn't open. So on that same website, I scrolled down, and it said, if it isn't downloading, a trojan virus was preventing it from doing so. So it said to download avenger, and execute a different script, and when it rebooted and I clicked on the Malwarebytes icon, it came up.

Running that right now, and immediately found 4 objects infected. But I haven't heard one noise today from my computer.

Last night after I emailed you saying I hadn't heard any audio in awhile, at midnight the computer just started going again with all these advertisements, you've won a new nintendo wii - really loud. I thought I had turned off my speaker, and I looked and it was muted. I tried to use the button with the anti-sign on my volume, and kept prompting me to quick launch buttons, install/don't install. So I figure the virus just infiltrated everything it knew I would try to get rid of it.

Some people I saw on one of the forums said their computer was completely shut down and said it had rebooted and was playing advertisements, and couldn't get it to stop like it was possessed. Crazy!

I'd throw my computer off my roof right now if it didn't have a million pics, and other stupid documents that I haven't backed up that would take me hours to copy out. So now I'm determined to clean it up. Actually, I did download most of the pictures to cd's, but not a double back-up, so it wouldn't be totally detrimental. I just don't know which I've downloaded and which I haven't and don't want to spend the time.

An IT person at my work said to get a thumbnail drive? Thumb drive? And back up everything on that, then wipe out and restore my whole computer, and then scan the thumb drive. So if this doesn't work, that's what I'm doing.


Suggestions???

TIA!!!
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If her goal is to clean up the system instead of doing a clean install, I'd do this:

1) back up anything important, as a bail-out precaution

2) scan for rootkits and eliminate them. Avira makes an anti-rootkit utility: http://www.avira.com/en/support/support_downloads.html Report back with the names of any rootkits found.

3) max out AntiVir's heuristic detection capabilities for both its real-time "Guard" and its on-demand "Scanner." To do this, right-click the red umbrella icon in the system tray, choose "Configure AntiVir," and enable the Expert Mode checkbox. While in there, also enable all the optional threat detections, which are in the General section.

4) update AntiVir's virus definitions by right-clicking the red umbrella and choosing Start Update.

5) now that AntiVir is fully armed and updated, right-click the red umbrella icon and choose Start AntiVir, then go to Local protection > Scanner at the left, and double-click the Complete System Scan. Note the precise names of detected malware and report back on them.

6) try running Malwarebytes and Superantispyware, in Safe Mode if necessary.

7) run HijackThis 2.02 and post a logfile, and/or plug it into http://hijackthis.de/en for an auto-analysis.


I'd also run F-Secure's online scanner, which has rootkit, malware and spyware/adware detection and can remove stuff, not just detect it.
 

redgtxdi

Diamond Member
Jun 23, 2004
5,464
8
81
Thanks mech!!!


Will advise as soon as she runs some of the stuff & post back here.

And, yes, planning on getting her up & running on a regular backup schedule so in the future she can just format/reinstall.

:D
 

redgtxdi

Diamond Member
Jun 23, 2004
5,464
8
81
Ya, thanks mech. I've read your page before & it's definitely a good reference.

Now, just as we thought things were really improving. (Between Avira, Fsecure & supermalwarebytes) She was just about ready to call it "clean" but then this morning, her computer got stuck in a reboot cycle.

I've seen this more times than I can count lately. I've literally had 3 people come to me with this problem in the last month.

One was overheating (I think). Another was just weird cuz after being unplugged for a full-day, it just started. No muss, no fuss, just started up.

Now, my sister's laptop is doin' it. (And only one of the three PC's is one I built & setup originally). Sister's is an HP DV1000 so I'm hopin' hers came with a true XP disc so I can try a 'repair' (yes, the latter of the 2 repairs in XP disc) on hers, but if not I guess I'm gonna try & have to step her thru making a boot disc.

Needless to say, she's ready to throw this thing Olympic discus-style :laugh: