• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Nasty Malware on Acer Aspire one Netbook, please help.

Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
So, I recently got a Acer Aspire one from a friend that needed some work. It seems that it has a particularly nasty Malware program calling itself "Personal Antivirus. Now I have dealt with something like it before, but this one is quite a bit nastier than the one I dealt with, if I boot straight into normal XP is blocks the internet completely. In Safe mode with networking it blocks any Google searches.

I was able to get Malwarebyte's anti-malware installed, but when I run it, it doesn't load up on the screen, but it shows up in task manager under processes. I also installed Avast Anti-Virus, but that's supposedly "installed improperly" according to a window that pops up when I run it.

I tried running Acer's eRecovery Management program, but that also crashes.

I tried to get a system restore going, but when I choose a restore point and hit the next button nothing happens.

Anyone have any suggestions?
 
Joined
Dec 5, 2007
Messages
5,214 (0.87/day)
System Name Addison Clark
Processor Ryzen 9 7950x3D delid
Motherboard Asus X670E Hero
Cooling Custom Bykski loop CPU, GPU, 2x 360 rads, and 1x 280 rad with Arctic P12 and P14 ARGB fans
Memory G.Skill DDR5-6000 64GB CL30
Video Card(s) Gigabyte 4090 Aorus Master
Storage Kingston Fury 2TB and 4TB NVME
Display(s) Samsung 57"
Case Lian Li O11 mini
Audio Device(s) Onboard
Power Supply Thermaltake 1000w SFX-L
Mouse Corsair Dark Core RGB SE
Keyboard Corsair K95 Platnium
Software Win 11 Pro
Have you tried just renaming the executable of Malwarebytes to "M"? I've had to do that with some nasties. Also I'd give Microsoft Security Essential a try. Just download it and the definition file on another PC if you can. Go here to get the definition file for Microsoft Security Essential.
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
ARe you running the AV and MBAM in Safe Mode? That's another way to circumvent the virus....sometimes.
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
kenkickr, renaming the exe didn't help sadly, I'll see if it'll let me download Microsoft Security Essential.

brandonwh64, this thing has no DVD/CD drive, otherwise I would've put a new install of XP on.

DonInKansas, yes, I did, no dice on that.
 
Joined
Dec 5, 2007
Messages
5,214 (0.87/day)
System Name Addison Clark
Processor Ryzen 9 7950x3D delid
Motherboard Asus X670E Hero
Cooling Custom Bykski loop CPU, GPU, 2x 360 rads, and 1x 280 rad with Arctic P12 and P14 ARGB fans
Memory G.Skill DDR5-6000 64GB CL30
Video Card(s) Gigabyte 4090 Aorus Master
Storage Kingston Fury 2TB and 4TB NVME
Display(s) Samsung 57"
Case Lian Li O11 mini
Audio Device(s) Onboard
Power Supply Thermaltake 1000w SFX-L
Mouse Corsair Dark Core RGB SE
Keyboard Corsair K95 Platnium
Software Win 11 Pro
If you can't download them then grab them on another system, put them on a flash drive, and install them to the netbook.
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
If all else fails, you could also pull the drive, slave it to another rig, and run a full scan killing it that way if a reformat is a last resort.
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
Microsoft Security Essential is downloaded, installed, updated and scanning now, I'll let you guys know how it goes.
 
Joined
Jun 4, 2007
Messages
1,050 (0.17/day)
Location
indiana
Processor c2d e8400@ 3.8ghz 24/7
Motherboard Abit IP-35e 80$ lol
Cooling zalman cnps9700 led
Memory 2 x 2 gig patriot viper
Video Card(s) evga Gtx 285 oc
Storage 2 x 300gig sata seagate 7200.10 in raid 0/ 1.5TB for backup
Display(s) acer 24" TFT LCD AL2416WBSD
Case Antec 902
Audio Device(s) XtremeGamer Fatal1ty Pro series
Power Supply ocz gamextreme 700w
Software windows 7 ultimate
If all else fails, you could also pull the drive, slave it to another rig, and run a full scan killing it that way if a reformat is a last resort.

^^ THIS


Just do it first.... save yourself the time LOL
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
As far as pulling the hard drive, that would be a total pain in the arse, as I'd still have to end up buying a mini IDE hard drive adapter. Plus it's seems to be harder to take apart than the other 4 laptops I've taken down in the past. Guess it might be time to find a guide to take this thing apart...

Also, MSE has already found and killed 4 viruses, and blocked one known Trojan site from communicating with them, as it seems it was connecting to their servers.
 
Joined
Jun 4, 2007
Messages
1,050 (0.17/day)
Location
indiana
Processor c2d e8400@ 3.8ghz 24/7
Motherboard Abit IP-35e 80$ lol
Cooling zalman cnps9700 led
Memory 2 x 2 gig patriot viper
Video Card(s) evga Gtx 285 oc
Storage 2 x 300gig sata seagate 7200.10 in raid 0/ 1.5TB for backup
Display(s) acer 24" TFT LCD AL2416WBSD
Case Antec 902
Audio Device(s) XtremeGamer Fatal1ty Pro series
Power Supply ocz gamextreme 700w
Software windows 7 ultimate
If it is working ... keep on workin it :p MSE is REALLY good. :toast:
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
Yeah, it seems to be doing the job well, just killed another 2 infections.

I swear my brother is right about people only buying netbooks for porn. This thing is infected to hell and back from the looks of it, I'm only 1/3 of the way thru a quick scan and it's found a total of 6 infections... Hopefully after this I'll be able to run malwarebytes and avast, then I'll run a thorough scan with MSE.
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
MSE ended up removing a total of 10 infections in the end, I'm about to start up malwarebyte's in a moment.
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
So far I've removed 24 infections...
 
T

TechPowerDown

Guest
MBAM Is The Stuff, Great Suggestions From Everyone, Good Luck Man
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
Up to a total of 40 infections removed, had to restart after Mbam was done, going to run avast now. :D
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
Okay the grand total was 46 infections. All removed now. Next to defragment the hard drive, as it seems the owner never did such... >.<

Thanks for all your help guys!
 
Joined
Oct 2, 2004
Messages
13,791 (1.93/day)
When the system is so severely infected i recommend doing the system restore. On ACER systems you have to press Alt+F10 or Shift+F10 or Ctrl+F10, can't remember for sure now. This will initiate system restore and will restore the netbook back to factory default.

If you don't, i suggest you run every antivirus you can find on it, especially the big ones. Most of them provide online scanners where you don't need the actual program. Detection is the same.
BitDefender and NOD32 have it and bunch of others like F-Secure etc. No AV is 100% and with so many infections you just have to be sure. I stillr ecommend using ACER restore like i said in the beginning. And don't forget to install some capable AV after you do that to prevent further infections.
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
I was planning on doing that tomorrow. Just ran out of time today, that's all.
 
Joined
Jun 2, 2007
Messages
5,106 (0.83/day)
Location
Kansas
Processor Core i5 3570K
Motherboard AsRock z77 Pro4
Cooling Zalman CNPS10X Extreme
Memory 2x4GB GSkill Sniper
Video Card(s) MSI GTX970 Gaming
Storage 240GB OCZ ARC 100, Samsung Spinpoint F3 1TB
Display(s) LG 23" 1920x1080
Case Antec P100
Audio Device(s) Onboard
Power Supply Antec Edge 750W
Software Windows 8.1 Pro 64
When the system is so severely infected i recommend doing the system restore. On ACER systems you have to press Alt+F10 or Shift+F10 or Ctrl+F10, can't remember for sure now. This will initiate system restore and will restore the netbook back to factory default.

Serious infections also infect your System Restore files, making a System Restore pointless, if not worse for the system. Factory defaulting a netbook kills files, doesn't it? Might as well reformat.
 
Joined
Oct 2, 2004
Messages
13,791 (1.93/day)
I was talking about ACER eRecovery (as system restore), not Windows System recovery.
I don't see any point in formating as eRecovery does that anyway. You'll have to install the OS either way.
 

Athlon2K15

HyperVtX™
Joined
Sep 27, 2006
Messages
7,909 (1.23/day)
Location
O-H-I-O
Processor Intel Core i9 11900K
Motherboard MSI Z590 Carbon EK X
Cooling Custom Water
Memory Team DDR4 4000MHz
Video Card(s) ASUS TUF RTX 3080 OC
Storage WD WN850 1TB
Display(s) 43" LG NanoCell 4K 120Hz
Power Supply Asus Thor 1200w
Mouse Asus Strix Evolve
Keyboard Asus Strix Claymore
whats the full model number of this aspire one? it wouldnt happen to be a A0A150 would it?
 
Joined
Jan 24, 2010
Messages
3,603 (0.69/day)
Location
Oregon, USA
System Name GLaDOS
Processor AMD FX-9590 X8 4.7GHz
Motherboard ASUS Sabertooth 990FX
Cooling Corsair H80i v2
Memory Corsair Vengeance 24GB (2x8GB, 2x4GB) DDR3 1600 MHz
Video Card(s) ASUS ROG-STRIX-RX580-O8G-GAMINGOC
Storage WD Blue 3D NAND 1TB Internal PC SSD
Display(s) 2 Acer S231HL 23" LED backlit LCD's on a Dual LCD stand
Case Corsair iCUE 220T RGB Airflow
Audio Device(s) Onboard - Corsair Void Pro Wireless
Power Supply Corsair 850HXi 850W
Mouse Corsair Sabre RGB
Keyboard Corsair K70 LUX RGB
Software Microsoft Windows 10 Pro 64 Bit
Indeed it is the A0A150 I just got done doing the eRecovery so it's a nice fresh install. All the nasty malware and junk from before wouldn't let it run. That's how bad the infection was on this thing.
 

Athlon2K15

HyperVtX™
Joined
Sep 27, 2006
Messages
7,909 (1.23/day)
Location
O-H-I-O
Processor Intel Core i9 11900K
Motherboard MSI Z590 Carbon EK X
Cooling Custom Water
Memory Team DDR4 4000MHz
Video Card(s) ASUS TUF RTX 3080 OC
Storage WD WN850 1TB
Display(s) 43" LG NanoCell 4K 120Hz
Power Supply Asus Thor 1200w
Mouse Asus Strix Evolve
Keyboard Asus Strix Claymore
i have the same netbook,i was going to give you links to the recovery disc,but you still have your recovery partition :)
 
Top