Start a Conversation

This post is more than 5 years old

Solved!

Go to Solution

1038

May 24th, 2016 14:00

Drive-by infection..!

Did a Google search today and found a result which seemed right. Clicked the link and started reading that website but didn't click any links on the page.

A Windows Defender (Win 10 Pro) box suddenly popped up in middle of the screen saying the site was potentially harmful and advised me to click a button in that box to go to my home page. Wasn't sure whether that was  legit, so I instead closed the IE11 window.

A short while later WD popped up again, this time saying it found Exploit: HTML/Axpergle.AK on my system. The MS site says this exploit comes in emails, but I'm assuming it came from the site WD warned about.

WD said it could remove the exploit but I needed to reboot so I did. Currently running Malwarebytes on that PC, but I don't know if it would detect/remove this exploit if It were still there.  Guess I'll also run SAS when MBAM is done.

Anything else I should do?

It ain't safe out there! :emotion-41:

3 Apprentice

 • 

15.3K Posts

May 25th, 2016 10:00

Double-click on the MBAE icon/shield in your system tray to open the user interface.

Click on the SETTINGS tab.

UNcheck the box marked "Show sytem tray notification tooltips".

3 Apprentice

 • 

15.3K Posts

May 24th, 2016 15:00

According to the page you linked to, WD is supposed to be able to detect and remove that threat.   Since you followed its advice to reboot in order to complete the removal, hopefully, it did.

Running MBAM is prudent... I don't have the same faith in SAS any more.

Yes, it's a jungle out there.   Two things for consideration in the future:   when surfing unknown sites --- indeed, even when surfing known "SAFE" sites (which can be compromised without notice) --- consider using either 1) MalwareBytes Anti-EXPLOIT https://www.malwarebytes.org/antiexploit/ or 2) Sandboxie  http://sandboxie.com/

Stress that NEITHER of these will scan/remove EXISTING infections... but each is pretty good at intercepting/preventing NEW exploits as you encounter them.

Both programs offer FREE versions... for MBAE, I wouldn't even bother to "activate" the trial, just let it default to the free version.

10 Elder

 • 

44.3K Posts

May 24th, 2016 16:00

Thanks for the good advice.

Looks like I got hosed...  [:'(]

MBAM didn't detect anything but something wasn't right. Launched SAS and it said an update was available, but "There was an error installing this update" every time I tried to install it and SAS wouldn't run.

I couldn't do anything related to settings. I could open the Update & Security pane, but clicking Check for Updates, Accounts, or Privacy wouldn't do anything. I could still open and run apps and IE11.

Launched System Restore and the most recent restore point (~10 days old) failed after ~30 min. The prior restore seems to have worked. Though  it took a couple of extra reboots before the latest MS updates would install. And the SAS update installed too.

The site I visited that started this mess was at top of the Google results and Google is usually good at screening out bad sites. So the site may have gotten compromised recently and/or very stealthily.

For what it's worth, I don't do anything critical on this PC, so if I had had to wipe/reinstall, I would have wasted a lot of time, but not lost anything irreplaceable.

Off with their hand...!

3 Apprentice

 • 

15.3K Posts

May 24th, 2016 16:00

MBAM didn't detect anything but something wasn't right...

Ron,

I was assuming --- apparently erroneously --- that WD had successfully alleviated what it found.   But if you're saying (or "sensing") that things weren't right... that your system was indeed compromised... I would have suggested that you consider submitting your findings for malware analysis at the likes of SpywareHammer or Landzdown (&etc.)   At this point, having regressed back (at least) 2 restore points, I don't know how much they'd find anymore.   But something to keep in mind, next time (IF there is a "next time").

10 Elder

 • 

44.3K Posts

May 24th, 2016 20:00

I didn't know if WD successfully removed that exploit or not, and also didn't know if the exploit had allowed something else into that system before the exploit was detected by WD.

After rebooting according to WD's instructions, the PC seemed to be running slowly. And even though MBAM found nothing, none of the Win 10 security settings screens would open, and SAS wouldn't update or run.

It's possible things just got messed up by WD removing the exploit but I wasn't willing to take a chance, so I ran the System Restore.

Scans with the updated SAS and with WD found nothing after the restore, and it seems to be running "normally" again, so I believe it's clean now. And there were no account passwords, banking info or anything else of value on that PC so I should be safe -for now.

BTW: I installed the free MBAE as you suggested but now I keep getting a pop-up saying the system is being protected by...  Is there a way to kill the pop-up or do I have to live with it unless/until I buy the paid MBAE ?

Thanks!

10 Elder

 • 

44.3K Posts

May 25th, 2016 14:00

No Events found!

Top