• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Is my laptop infected?

Joined
May 12, 2009
Messages
5,196 (0.95/day)
System Name Dust Collector
Processor AMD Ryzen 5 3600X
Motherboard Asus B550I Aorus Pro WiFi AX
Cooling Alpenfohn Black Ridge V2 w/ Noctua NF-A9x14
Memory Corsair Vengeance LPX 16GB DDR4 3200MHz/CL16
Video Card(s) Power Color Red Dragon RX 5700 XT
Storage Samsung EVO+ 500GB NVMe
Display(s) Dell S2721DGF
Case Dan Case A4
Power Supply Corsair SF600 Platinum
Mouse Logitech G603
Keyboard Logitech G613
My laptop has been acting weird lately. Some webpages don't load, some redirect me, and I can't seem to do Windows Update or any antivirus software updates. I took the hard drive out and scanned it in another computer with MalwareBytes (3 trojans, all cleared, rescanned to be sure) and I still can't do any form of updates on the laptop.

I'm not sure what else to do, help me troubleshoot!
 
Joined
Jan 14, 2009
Messages
457 (0.08/day)
Location
On The Green
System Name B450+2700x
Processor Ryzen 2700x
Motherboard MSI B450 Tomahawk
Memory Ballistix Sport LT - BLS2K8G4D30BESBK
Video Card(s) EVGA GeForce GTX 1650 XC 4GB DDR5
Storage PNY SSD
Display(s) 2x LG 27" IPS
Case NZKT H510
Power Supply CORSAIR - RMx Series 850
Hey Kan...first make sure time and date are synced...next check your ad-ons running on your browser, sometimes a redirect is hiding in there...I like superantispyware or spyware doctor to scan after malwarebytes
 
Joined
Sep 26, 2010
Messages
231 (0.05/day)
System Name Vika
Processor Intel Core i3 2100
Motherboard Asus P8Z68-V Gen 3
Cooling Stock Intel
Memory G.Skill Ripjaws X 8GB DDR3
Video Card(s) HIS IceQ X Radeon HD 7970 @ 1100/1550
Storage Crucial M4 SSD 64GB, Samsung Spinpoint F3 1TB
Display(s) Viewsonic VX2453MH-LED 23.6in LED
Case Fractal Design Arc Midi
Audio Device(s) Asus Xonar DG
Power Supply Antec HCG 620W
Software Windows 7 Premium 64bit

{JNT}Raptor

New Member
Joined
Jul 12, 2005
Messages
732 (0.11/day)
Location
NY
System Name Ummmm...Mine
Processor I7 920 @ 4.2ghz @ 1.29v's load
Motherboard ASUS P6T Deluxe V2
Cooling Custom 1/2 inch H20
Memory 3x2gb Patriot Sector 7 @2008Mhz 27-9-11-9 1T
Video Card(s) EVGA GTX 580 SC 900/1800/1090
Storage 1-Mushkin 60gb SSD 1-500GB WD Black and 2-1TB 32mb WD Black
Display(s) 25 inch Hanns-G 2ms
Case Custom
Audio Device(s) Turtle Beach Catalina
Power Supply Corsair AX850 Pro Series-Modular
Software All Kinds...and then some.
Benchmark Scores 3dMark 11 P7066 Compare Link- http://3dmark.com/3dm11/251153
Check your internet settings/Lan settings to make sure a worm hasn't set you up with a proxy server....alot of malware is doing that...that way..you can surf all you want...but none of your software will update.....the redirecting and no updates is a giveaway.

Hope it helps. :)
 
Joined
Apr 16, 2010
Messages
3,456 (0.68/day)
Location
Portugal
System Name LenovoⓇ ThinkPad™ T430
Processor IntelⓇ Core™ i5-3210M processor (2 cores, 2.50GHz, 3MB cache), Intel Turbo Boost™ 2.0 (3.10GHz), HT™
Motherboard Lenovo 2344 (Mobile Intel QM77 Express Chipset)
Cooling Single-pipe heatsink + Delta fan
Memory 2x 8GB KingstonⓇ HyperX™ Impact 2133MHz DDR3L SO-DIMM
Video Card(s) Intel HD Graphics™ 4000 (GPU clk: 1100MHz, vRAM clk: 1066MHz)
Storage SamsungⓇ 860 EVO mSATA (250GB) + 850 EVO (500GB) SATA
Display(s) 14.0" (355mm) HD (1366x768) color, anti-glare, LED backlight, 200 nits, 16:9 aspect ratio, 300:1 co
Case ThinkPad Roll Cage (one-piece magnesium frame)
Audio Device(s) HD Audio, RealtekⓇ ALC3202 codec, DolbyⓇ Advanced Audio™ v2 / stereo speakers, 1W x 2
Power Supply ThinkPad 65W AC Adapter + ThinkPad Battery 70++ (9-cell)
Mouse TrackPointⓇ pointing device + UltraNav™, wide touchpad below keyboard + ThinkLight™
Keyboard 6-row, 84-key, ThinkVantage button, spill-resistant, multimedia Fn keys, LED backlight (PT Layout)
Software MicrosoftⓇ WindowsⓇ 10 x86-64 (22H2)
Also, you could go to "C:\WINDOWS\system32\drivers\etc" to look up the hosts file and check if it's clean (open it with notepad). There should be no other hosts but the loopback (127.0.0.1). If there are any other hosts, check if it was you who put them there, if not, delete them and save the file.
 
Last edited:
Joined
Mar 1, 2010
Messages
3,565 (0.69/day)
Location
By the Channel Tunnel, Kent, England
System Name Benny
Processor Phenom II 1055t @ 3.3GHz; 300x11; 1.380v; NB 2700; HT 2400
Motherboard ASUS Crosshair IV Formula (2002 BIOS)
Cooling Thermalright TRUE 120 Black + 2 Xilence Red Wing PWM 120mm (push/pull) + polycarbonate fan holders
Memory 8GB GeIL Ultra 2133MHZ C9 running at 1600MHz @ 7-7-7-21 1T 1.5v
Video Card(s) MSI Twin Frozr II GTX470 @ Stock w/CPU fan cable-tied on, as one of the GPU fans broke.
Storage 60GB OCZ Agility3 (OS);500GB WDC Grn; 1x1TB WDC Blk (Backup)
Display(s) ASUS PA823Q
Case Silverstone Raven 2 (all cables custom sleeved with velcro mod on side panel...)
Audio Device(s) X-Fi (Onboard) + Harmon Kardon HK6100 amp powering JVC HA-RX700's with Zalman mic
Power Supply Corsair HX650W
Software Win7 Pro x64
Benchmark Scores No benchies so making this space useful! Corsair M90, Logitech G19. Phobya FlexLight LED's (gawjus)
Also, you could go to "C:\WINDOWS\system32\drivers\etc" to look up the hosts file and check if it's cleaned (open it with notepad). There should be no other hosts but the loopback (127.0.0.1). If there are any other hosts, check if it was you who put them there, if not, delete them and save the file.

+1; this is most likely the solution.
If there is another address there, your laptop will connect to that and, in turn, can reinfect you (the address could be that of another infected computer for example).
 
Joined
Aug 10, 2007
Messages
2,142 (0.35/day)
Location
Austin TX
Processor i9 11900k
Motherboard Maximus XII Apex
Cooling Custom Liquid W/ 360x60 Radiator
Memory 32Gb Team XTREEM ARGB 3600 b-die
Video Card(s) Waterblocked MSI RTX 4070
Storage Intel 900p 480Gb + 4tb Intel 670p
Display(s) LG C2 evo 42"
Case Geometric Future Model 8
Audio Device(s) HD58X + Sennheiser GSX 1000
Power Supply Corsair RM 750x
Mouse Steelseries Aerox 5 wired
Keyboard Akko Mod 007b HE
VR HMD Samsung Odyssey+
Software Windows 11
try running tdss killer in safe mode first then hit it with combofix (MAKE SURE TO RE-NAME COMBOFIX TO SOMETHING ELSE)

those are classic symptoms of a tdss/aroueln rootkit infection which are not normaly picked up by malware bytes
 
Joined
May 12, 2009
Messages
5,196 (0.95/day)
System Name Dust Collector
Processor AMD Ryzen 5 3600X
Motherboard Asus B550I Aorus Pro WiFi AX
Cooling Alpenfohn Black Ridge V2 w/ Noctua NF-A9x14
Memory Corsair Vengeance LPX 16GB DDR4 3200MHz/CL16
Video Card(s) Power Color Red Dragon RX 5700 XT
Storage Samsung EVO+ 500GB NVMe
Display(s) Dell S2721DGF
Case Dan Case A4
Power Supply Corsair SF600 Platinum
Mouse Logitech G603
Keyboard Logitech G613
Hey Kan...first make sure time and date are synced...next check your ad-ons running on your browser, sometimes a redirect is hiding in there...I like superantispyware or spyware doctor to scan after malwarebytes

Done! Problem still exists.

Why not try speedtest? May be a internet problem.
http://www.speedtest.net/

Done! Internet is running fine, problem still present.

Also, you could go to "C:\WINDOWS\system32\drivers\etc" to look up the hosts file and check if it's clean (open it with notepad). There should be no other hosts but the loopback (127.0.0.1). If there are any other hosts, check if it was you who put them there, if not, delete them and save the file.

127.0.0.1 localhost
::1 localhost

I think it's clean.

+1; this is most likely the solution.
If there is another address there, your laptop will connect to that and, in turn, can reinfect you (the address could be that of another infected computer for example).

try running tdss killer in safe mode first then hit it with combofix (MAKE SURE TO RE-NAME COMBOFIX TO SOMETHING ELSE)

those are classic symptoms of a tdss/aroueln rootkit infection which are not normaly picked up by malware bytes


This is my next step. No luck, TDSSKiller didn't spot anything.

Thanks everyone so far!
 
Last edited:
Joined
Mar 1, 2010
Messages
3,565 (0.69/day)
Location
By the Channel Tunnel, Kent, England
System Name Benny
Processor Phenom II 1055t @ 3.3GHz; 300x11; 1.380v; NB 2700; HT 2400
Motherboard ASUS Crosshair IV Formula (2002 BIOS)
Cooling Thermalright TRUE 120 Black + 2 Xilence Red Wing PWM 120mm (push/pull) + polycarbonate fan holders
Memory 8GB GeIL Ultra 2133MHZ C9 running at 1600MHz @ 7-7-7-21 1T 1.5v
Video Card(s) MSI Twin Frozr II GTX470 @ Stock w/CPU fan cable-tied on, as one of the GPU fans broke.
Storage 60GB OCZ Agility3 (OS);500GB WDC Grn; 1x1TB WDC Blk (Backup)
Display(s) ASUS PA823Q
Case Silverstone Raven 2 (all cables custom sleeved with velcro mod on side panel...)
Audio Device(s) X-Fi (Onboard) + Harmon Kardon HK6100 amp powering JVC HA-RX700's with Zalman mic
Power Supply Corsair HX650W
Software Win7 Pro x64
Benchmark Scores No benchies so making this space useful! Corsair M90, Logitech G19. Phobya FlexLight LED's (gawjus)
Check firewall settings to make sure there's nothing being blocked, and also check services to make sure the virus hasn't disabled certain services.

If you're still getting redirected etc, then I think you're still infected. When I got hit with the ESQUL virus, malware bytes couldn't fix it for 3 days. On the third day, I updated Malware Bytes and it fixed it. Might just be the waiting game.


EDIT: wait wait wait, combofix didn't fix it???
 
Joined
May 12, 2009
Messages
5,196 (0.95/day)
System Name Dust Collector
Processor AMD Ryzen 5 3600X
Motherboard Asus B550I Aorus Pro WiFi AX
Cooling Alpenfohn Black Ridge V2 w/ Noctua NF-A9x14
Memory Corsair Vengeance LPX 16GB DDR4 3200MHz/CL16
Video Card(s) Power Color Red Dragon RX 5700 XT
Storage Samsung EVO+ 500GB NVMe
Display(s) Dell S2721DGF
Case Dan Case A4
Power Supply Corsair SF600 Platinum
Mouse Logitech G603
Keyboard Logitech G613
Check firewall settings to make sure there's nothing being blocked, and also check services to make sure the virus hasn't disabled certain services.

If you're still getting redirected etc, then I think you're still infected. When I got hit with the ESQUL virus, malware bytes couldn't fix it for 3 days. On the third day, I updated Malware Bytes and it fixed it. Might just be the waiting game.


EDIT: wait wait wait, combofix didn't fix it???

I've disabled the firewall, I always do. I assumed that Avast! or M$ Security Essentials would be enough, apparently not.

Oh I assumed ComboFix was a follow-up for TDDSKiller, when TDDS didn't pick up anything, I didn't bother with ComboFix. I'll give that a shot momentarily, right now I'm busy with another computer, I have to meet up with AudiTuner and complete a deal. ^_^
 
Joined
May 12, 2009
Messages
5,196 (0.95/day)
System Name Dust Collector
Processor AMD Ryzen 5 3600X
Motherboard Asus B550I Aorus Pro WiFi AX
Cooling Alpenfohn Black Ridge V2 w/ Noctua NF-A9x14
Memory Corsair Vengeance LPX 16GB DDR4 3200MHz/CL16
Video Card(s) Power Color Red Dragon RX 5700 XT
Storage Samsung EVO+ 500GB NVMe
Display(s) Dell S2721DGF
Case Dan Case A4
Power Supply Corsair SF600 Platinum
Mouse Logitech G603
Keyboard Logitech G613
You are using Avast? Replace it with MSE and report back.

I uninstalled Avast! and installed MSE. I can't update it, that's when I figured something was wrong. Windows Update didn't work, Malware Bytes wouldn't update, etc. I'm also being redirected to a few sites, and Malware Bytes' homepage does not load.
 
Joined
Mar 1, 2010
Messages
3,565 (0.69/day)
Location
By the Channel Tunnel, Kent, England
System Name Benny
Processor Phenom II 1055t @ 3.3GHz; 300x11; 1.380v; NB 2700; HT 2400
Motherboard ASUS Crosshair IV Formula (2002 BIOS)
Cooling Thermalright TRUE 120 Black + 2 Xilence Red Wing PWM 120mm (push/pull) + polycarbonate fan holders
Memory 8GB GeIL Ultra 2133MHZ C9 running at 1600MHz @ 7-7-7-21 1T 1.5v
Video Card(s) MSI Twin Frozr II GTX470 @ Stock w/CPU fan cable-tied on, as one of the GPU fans broke.
Storage 60GB OCZ Agility3 (OS);500GB WDC Grn; 1x1TB WDC Blk (Backup)
Display(s) ASUS PA823Q
Case Silverstone Raven 2 (all cables custom sleeved with velcro mod on side panel...)
Audio Device(s) X-Fi (Onboard) + Harmon Kardon HK6100 amp powering JVC HA-RX700's with Zalman mic
Power Supply Corsair HX650W
Software Win7 Pro x64
Benchmark Scores No benchies so making this space useful! Corsair M90, Logitech G19. Phobya FlexLight LED's (gawjus)
I've disabled the firewall, I always do. I assumed that Avast! or M$ Security Essentials would be enough, apparently not.

Personally, I've always had firewall on, and only allow:
Core Networking
Firefox
Homegroup
Maxis Broadband (My internety dongle)
Network Discovery
Orbit Downloader (Flash grabber + Download Accelerator)

Every time I install something, I check to make sure it hasn't allowed itself.

Oh I assumed ComboFix was a follow-up for TDDSKiller, when TDDS didn't pick up anything, I didn't bother with ComboFix. I'll give that a shot momentarily, right now I'm busy with another computer, I have to meet up with AudiTuner and complete a deal. ^_^

Combofix should deomlish the virus. It disables drivers etc. before doing it's thing. If a virus is using a driver to evade detection/spread, it's no sweat. Unfortunately, that's why a lot of people report problems connecting to the net after running combofix, as it's ruthless and will remove your LAN driver if it wants to.
Just make sure you let combofix update when it asks.
And be prepared to reinstall OS if you're using combofix... Although I've never needed to, YRMV.
 
Joined
May 12, 2009
Messages
5,196 (0.95/day)
System Name Dust Collector
Processor AMD Ryzen 5 3600X
Motherboard Asus B550I Aorus Pro WiFi AX
Cooling Alpenfohn Black Ridge V2 w/ Noctua NF-A9x14
Memory Corsair Vengeance LPX 16GB DDR4 3200MHz/CL16
Video Card(s) Power Color Red Dragon RX 5700 XT
Storage Samsung EVO+ 500GB NVMe
Display(s) Dell S2721DGF
Case Dan Case A4
Power Supply Corsair SF600 Platinum
Mouse Logitech G603
Keyboard Logitech G613
ComboFix took care of things, powerful little tool isn't it. Windows Update is working, MSE is updating, I'm able to visit MalwareBytes' homepage. I'll revive this thread should anything happen again.

Thanks everyone!
 
Joined
Aug 10, 2007
Messages
2,142 (0.35/day)
Location
Austin TX
Processor i9 11900k
Motherboard Maximus XII Apex
Cooling Custom Liquid W/ 360x60 Radiator
Memory 32Gb Team XTREEM ARGB 3600 b-die
Video Card(s) Waterblocked MSI RTX 4070
Storage Intel 900p 480Gb + 4tb Intel 670p
Display(s) LG C2 evo 42"
Case Geometric Future Model 8
Audio Device(s) HD58X + Sennheiser GSX 1000
Power Supply Corsair RM 750x
Mouse Steelseries Aerox 5 wired
Keyboard Akko Mod 007b HE
VR HMD Samsung Odyssey+
Software Windows 11
ComboFix took care of things, powerful little tool isn't it. Windows Update is working, MSE is updating, I'm able to visit MalwareBytes' homepage. I'll revive this thread should anything happen again.

Thanks everyone!

proof that combofix isnt as "bad" as people make it out to be
 
Joined
Oct 29, 2009
Messages
2,669 (0.50/day)
System Name Old Gateway / Steam Deck OLED LE
Processor i5 4440 3.1ghz / Jupiter 4c 8t
Motherboard Gateway / Valve
Cooling Eh it doesn't thermal throttle
Memory 2x 8GB JEDEC 1600mhz DDR3 / 16gb DDR5 6400
Video Card(s) RX 560D 4GB / Navi II 8CU
Storage 240gb 2.5 SSD / 1TB nvme
Display(s) Dell @ 1280*1024 75hz / 800p OLED
Case Gateway / Valve LE
Audio Device(s) Gateway Diamond Audio EMC2.0-USB 5375U ($15 a long ass time ago), Valve
Power Supply 380w oem / 65w valve USB-C
Mouse Purple Walmart special, 1600dpi. Black desk mat
Keyboard SteelSeries Apex 100 / virtual
VR HMD Lmao
Software Windows 10 / Steam OS
Benchmark Scores It can run Crysis (Original), Doom 2016, and Halo MCC. SD LE 45fps
every computer i've used combofix on so far no trouble. the only trouble i've had with it is sometimes it doesn't work and i have to use something else. as far as harming the computer... i've yet to see that.
 
Joined
Mar 1, 2010
Messages
3,565 (0.69/day)
Location
By the Channel Tunnel, Kent, England
System Name Benny
Processor Phenom II 1055t @ 3.3GHz; 300x11; 1.380v; NB 2700; HT 2400
Motherboard ASUS Crosshair IV Formula (2002 BIOS)
Cooling Thermalright TRUE 120 Black + 2 Xilence Red Wing PWM 120mm (push/pull) + polycarbonate fan holders
Memory 8GB GeIL Ultra 2133MHZ C9 running at 1600MHz @ 7-7-7-21 1T 1.5v
Video Card(s) MSI Twin Frozr II GTX470 @ Stock w/CPU fan cable-tied on, as one of the GPU fans broke.
Storage 60GB OCZ Agility3 (OS);500GB WDC Grn; 1x1TB WDC Blk (Backup)
Display(s) ASUS PA823Q
Case Silverstone Raven 2 (all cables custom sleeved with velcro mod on side panel...)
Audio Device(s) X-Fi (Onboard) + Harmon Kardon HK6100 amp powering JVC HA-RX700's with Zalman mic
Power Supply Corsair HX650W
Software Win7 Pro x64
Benchmark Scores No benchies so making this space useful! Corsair M90, Logitech G19. Phobya FlexLight LED's (gawjus)
proof that combofix isnt as "bad" as people make it out to be

Yea, I'd say about 8 or 9 out of 10 users don't have any problems using it.
Most people don't actually read bleepingcomputer.com's instructions before using Combofix and assume that it's a program that can be used regularly.
The people that know what damage it can do to your OS installation are the people who have actually read the instructions at bleepingcomputer. Unfortunately, it seems not many people do.
 
Top