Malware on my PC - External hard drive

Discussion in 'Malware Help (A Specialist Will Reply)' started by comet1998, Mar 5, 2011.

  1. comet1998

    comet1998 Private E-2

    Hi all,

    I have some spyware/malware of some description on my pc. Yay. I am going to remove it all using the sticky thread about spyware as I've used it before and had luck with it, but before I start I wanted to ask about my files.

    I have hundreds (actually a few thousand) of photos on my pc, as well as music and videos. I really dont want to lose these, especially the photos. If I was to buy an external hard drive to transfer all these files onto would the hard drive be safe from the viruses/malmare transferring over or would it get infected as well?

    Sorry for the stupid question, these photos just mean alot to me and I don't want to risklosing them.

    Thanks!

    Michelle
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is always prudent to have your important data backed up to begin with. So in that light alone you should get your photos and other important personal data backed up by any means.

    Since we don't know what infection you have or even what problems you have ( you did not tell us ) we have no idea what it may have infected. However either way you should back up your files just to be safe if something ever goes wrong during the cleaning process.
     
  3. comet1998

    comet1998 Private E-2

    Thanks for your reply.

    I have taken all my most important files off my pc and onto an external hard drive.

    I'll give you a bit of info about what the pc is doing.

    - my desktop has been hijacked with a massive warning message saying I have spyware and it needs to be fixed. It is blue with bright red writing.
    - it keeps rebooting every 20 mins or so.
    - there is some program popping up called system tools every few minutes, looks like a scanner of some description belonging to windows. I am pretty sure it is malware of some description. It does not appear in my programs list in control panel.
    - Warning messages keep popping up in the right hand side of the screen saying my computer is affected.

    The list keeps going but I'm sure I don't need to continue!

    My next issue is that I have been trying to go through your removal of spyware/malware thread however none of the programs I have downloaded will execute.

    - I cant uninstall WildTangent- it tells me I don't have the right permissions. There is only one user account on the computer and it is set up as administrator. There are no other programs in control panel that appear on your list of things to remove.
    - CCleaner, defogger, user account control settings, superantispyware, malwarebytes and combofix will not open. A pop up message on the right hand side of the screen says it is an infected file and it cannot execute. I have tried renaming them but have had no luck.

    Most other applications on my pc will also not open.

    Is there anything I can do or am I going to have to take it to a computer guru?
     
  4. comet1998

    comet1998 Private E-2

    I may have it sorted! I started in safe mode and seem to be able to open the applications.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Tool is fairly easy to remove. You just need to get the running process stopped and then delete the files and folders it creates to run its application at each startup. If you have been able to run in safe mode, then run the READ & RUN ME in safe mode. Otherwise, try the below to see if you can get started.


    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are a few different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    If you are having problems running Rkill, you can download iExplore.exe or eXplorer.exe, which are renamed copies of Rkill.com, and try them instead.

    Once you've gotten one of them to run then try to immediately run the following.

    Now run this: Using Malwarebytes Anti-Malware
     
  6. comet1998

    comet1998 Private E-2

    Thank you for your help!

    I have cleared out my computer now and it seems to be running perfectly.
    I got it running in safe mode and was able to run all the programs through there until there were no more threats detected.

    Thanks again!

    Michelle
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you ran our sticky then you need to run the below final cleanup instructions too.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds