{"id":326,"date":"2011-06-06T15:53:55","date_gmt":"2011-06-06T20:53:55","guid":{"rendered":"http:\/\/www.properwichita.com\/consulting\/?p=326"},"modified":"2011-06-06T15:55:00","modified_gmt":"2011-06-06T20:55:00","slug":"tip-there-is-malware-on-my-computer-wichita-it-support","status":"publish","type":"post","link":"http:\/\/www.properwichita.com\/consulting\/2011\/06\/06\/tip-there-is-malware-on-my-computer-wichita-it-support\/","title":{"rendered":"Tip: There IS Malware on My Computer &#8211; Wichita IT Support"},"content":{"rendered":"<h2>Wichita Computer Support Tip for 6 June 2011<\/h2>\n<p>My last post asked the question &#8216;<a title=\"Tip: Is there Malware on My Computer? \u2013 Wichita IT Support\" href=\"http:\/\/www.properwichita.com\/consulting\/2011\/06\/01\/tip-is-there-malware-on-my-computer-wichita-it-support\/\">Is there Malware on my Computer?<\/a>&#8216;\u00a0 Who knew that it would be a prophetic article?\u00a0 This weekend even the seasoned computer tech fell victim to this common curse.\u00a0 With current antivirus protection and good practices, even veterans contract these dreaded parasites.<\/p>\n<p>Without any prompting, my computer contracted a malware infection over the weekend and required a little bit of advanced removal to fix.\u00a0 Let&#8217;s look at some real-life examples in pictures and descriptions.\u00a0 If you see anything like this on your own machine, call a professional.\u00a0 The removal was not simple and anything but easy.<\/p>\n<p>For background, I was surfing the Internet and visited a page professing to have a tool I needed for stress-testing a network (read hacking) to determine if there were any security issues.\u00a0 Once the page loaded, Internet Explorer 9 shut down and restarted on its own.\u00a0 Within moments, I was presented with this popup:<\/p>\n<div id=\"attachment_327\" style=\"width: 634px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/malware01.jpg\"><img aria-describedby=\"caption-attachment-327\" loading=\"lazy\" class=\"size-full wp-image-327\" title=\"Windows Security Service Malware Popup\" src=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/malware01.jpg\" alt=\"Windows Security Service Malware Popup\" width=\"624\" height=\"463\" srcset=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/malware01.jpg 624w, http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/malware01-300x222.jpg 300w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/a><p id=\"caption-attachment-327\" class=\"wp-caption-text\">Windows Security Service Malware Popup<\/p><\/div>\n<p>It took a double-take to realize that this was <strong>not<\/strong> a message from the operating system.\u00a0 It looks a lot like the Action Center in Windows 7.\u00a0 I closed out the message box, already fearing I had trouble.\u00a0 Another popup followed:<\/p>\n<div id=\"attachment_328\" style=\"width: 634px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware02.jpg\"><img aria-describedby=\"caption-attachment-328\" loading=\"lazy\" class=\"size-full wp-image-328\" title=\"Scareware Malware Screen\" src=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware02.jpg\" alt=\"Scareware Malware Screen\" width=\"624\" height=\"445\" srcset=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware02.jpg 624w, http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware02-300x213.jpg 300w\" sizes=\"(max-width: 624px) 100vw, 624px\" \/><\/a><p id=\"caption-attachment-328\" class=\"wp-caption-text\">Scareware Malware Screen<\/p><\/div>\n<p>It looks legitimate, but again is not.\u00a0 These are my files, all right, but none of them are infected with a virus (except this virus!)\u00a0 I spent a moment capturing these screens though I knew that I had to get moving on getting it removed.\u00a0 This screen was followed by this one:<\/p>\n<div id=\"attachment_329\" style=\"width: 364px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware03.jpg\"><img aria-describedby=\"caption-attachment-329\" loading=\"lazy\" class=\"size-full wp-image-329\" title=\"Malware Screen Number Three!\" src=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware03.jpg\" alt=\"Malware Screen Number Three!\" width=\"354\" height=\"262\" srcset=\"http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware03.jpg 354w, http:\/\/www.properwichita.com\/consulting\/wp-content\/uploads\/2011\/06\/Malware03-300x222.jpg 300w\" sizes=\"(max-width: 354px) 100vw, 354px\" \/><\/a><p id=\"caption-attachment-329\" class=\"wp-caption-text\">Malware Screen Number Three!<\/p><\/div>\n<p>The <strong>Register<\/strong> button would have offered me complete removal, probably at the low price of $89.00.<\/p>\n<p>I went to my trusty applications (Malwarebytes, SuperAntiSpyware) and neither of the two would run.\u00a0 I rebooted to safe mode, to just be presented the same popups.\u00a0 System restore had been disabled.\u00a0 I eventually downloaded another application (Combofix) from another computer and ran it on the infected machine.\u00a0 Several scans later and a half-dozen reboots and I was clean.\u00a0 The programs installed included downloaders, which are nice little malware applications designed to install even more malware on your machine.<\/p>\n<p>If you see messages like the ones above, give us a call at Proper Technology Solutions at (316) 337-5628.\u00a0 Though the first two tools above are easy enough for most users, I don&#8217;t recommend ComboFix for non-advanced users.\u00a0 The longer these problems exist on your computer or network, the harder they are to remove.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wichita Computer Support Tip for 6 June 2011 My last post asked the question &#8216;Is there Malware on my Computer?&#8216;\u00a0 Who knew that it would be a prophetic article?\u00a0 This weekend even the seasoned computer tech fell victim to this &hellip; <a href=\"http:\/\/www.properwichita.com\/consulting\/2011\/06\/06\/tip-there-is-malware-on-my-computer-wichita-it-support\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[],"_links":{"self":[{"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/posts\/326"}],"collection":[{"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/comments?post=326"}],"version-history":[{"count":2,"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/posts\/326\/revisions"}],"predecessor-version":[{"id":331,"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/posts\/326\/revisions\/331"}],"wp:attachment":[{"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/media?parent=326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/categories?post=326"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.properwichita.com\/consulting\/wp-json\/wp\/v2\/tags?post=326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}