SafeFeel.com

Free Computer Networking Security & Software Questions and Answers Website

Virus possibly? dont know what to do?

okay, i enjoy popups from this stupid anti spy ware program that keep coming up and i cant delete them! i hold unmarked programs on my computer relating to that spyware point that i never downloaded, so idk whats going on. also my framework is changed and i cant change it backbone. i share this computer next to other society and idk if I don`t know they downloaded it, but its driving me insane. so if you know whats going on please assist!!


Answers: Some of the posted info is adjectives, but I recommend SIMPLE SOLUTIONS to what may be a simple problem.

1) I approaching Spybot Search and Destroy because it's small and efficient. Try this intertwine:
http://www.spybot.info/en/download/index...

Your computer should own MsConfig.exe . You can find it near Start (icon on the bottom not here of your taskbar) > Run > MsConfig .

If not, you can download MsConfig.XP.exe as shareware. Try this join:
http://www.perfectdrivers.com/local/msco...

With MsConfig or MsConfigXP you can control what loads at boot merely by unchecking the item on a roll. From the row of tab you can monitor and control SERVICES and STARTUP items.

Many of the malwares nouns as services.

2) In Internet Explorer, use Tools (top flash menu)> Internet Options > Security tab > Restricted Sites . BLOCK access to the specific site that the Malware is trying to access.

If you can't give an account, check your browser History. On IE the History deity looks close to a sundial. For other browsers try Ctrl-H.

Between Spybot to gun down the program, MsConfig to hold on to it from reloading every time you boot and Browser Security to Block adjectives access, you should be capable of toy with it.

Good luck,
- CarlD

- - -
Here's an answer I previously posted roughly speaking Rootkit virii. Portions may be appropriate.

The first examine is, how do you know you enjoy Hacktool?

Most rootkits are stealthy; they singular take helpful when you access a secured website such as online bank. Then, surreptitiously, they email you login ID and password to someplace similar to Russia. Goodbye wall picture.

If you suggest you own a rootkit AND if you used the internet lately to access safe and sound websites, after examine your HISTORY.

For IE, click the deity which looks close to a sundial. For other browsers try Ctrl-H.

When you roll your mouse cursor over a history relationship, you should see the complete road. A street could even show the URL for the in safe hands website, your login ID, and your password, adjectives inbuilt contained by one big correlation.

Copy the offending cooperation. Use Tools > Internet Options > Security > Restricted Sites to block access to that network address.

Notify your bank or credit cards that your surety have be hack and CHANGE YOUR PASSWORDS.

I developed my own rootkit blocking system.

The problem is that you decimate it, after it reappear everytime you boot. You can never completely exterminate it.

I'll break it down.
1) Whenever a virus emerge, it creates specific files, usually contained by the Windows\System32 directory but they could be in several places.
2) Run a program resembling Spybot. Carefully log the complete report baptize and footpath of the files that Spybot removes.
3) CREATE A FAKE FILE TO OCCUPY THE EXACT LOCATION OF EACH INFECTED FILE. Take a word processor such as notepad. To illustrate, net a profile call FakeFile.txt beside a strip of schoolbook similar to "This is my rootkit blocking system".
4) Copy the Fakefile to respectively subdirectory where on earth the infected profile be located. Example: c:\Windows\System32\Fakefile.t...
5) Make as plentiful copies of Fakefile.txt as you obligation.
6) RENAME respectively Fakefile.txt to the exact given name of the infected record. Example: Rename Filefile.txt to BadVirus.exe .
7) Change the properties to Read Only.

You may necessitate to unlock the infected database up to that time you can delete, rename, etc. I use a shareware program call Unlocker.

http://www.softpedia.com/get/system/syst...

You may enjoy better results by Safe Booting, I prefer Unlocker.

Why does this system work? Because most rootkits create alike folder name surrounded by equal locations, over and over.
When they see an existing profile, they don't surmise to write over it or create an alternate profile name

Simple and significant, BUT you may involve to turn one step farther. Find a program call HijackThis and find a website that will analyze the HijackThis log.

You post the log. They report to you how to fix the problem. You may enjoy to remove registry key.

Here's a simple tip for using my blocking system. Rename the fakefile using a distinctive combination of upper and lower satchel characters. Your blocking revision might be name bAdViRUS.eXE . That track, you will know it's yours and not the ingenious.

Good luck.
- CarlD

Source(s):
http://trimagna.googlepages.com/myrootki...
One of the first things to do when you suspect malware is DISABLE System Restore.
If enabled, this allows malware to salt away contained by the computer and re-install itself.
So, to disable it, RIGHT-click on "My Computer." Select "Properties" later lower than the 'System Restore' tab, check 'Turn stale system restore' IF not already checked.
The subsequent most supportive things that would assist you are to use ONLINE scanners from websites to remove any malware on your PC.
The current best online scanners I prefer are from Kaspersky antivirus and Bitdefender antivirus. Together, these 2 scanners will find ALL the desperate stuff on your PC because they own the BEST detection rate.
First, use Kaspersky's. (FYI: ALL these scan require you to agree to a EULA and install an activex control which is needed to make the scan, so agree to them adjectives.)

*NOTE: Some scanners ONLY work beside IE or may not fully remove malware

http://www.kaspersky.com/virusscanner... (KAV)

Then scan near:
http://www.bitdefender.com/scan8/ie.html...


There are MANY other moral online scanners which you may choose to also use (which will appropriate longer but ensure safety):

http://onecare.live.com/site/en-us/defau... (Windows Live Onecare)

http://www.emsisoft.com/en/software/ax/... (A-squared scanner)

http://www.ewido.net/en/onlinescan/... (ewido)

http://www.ca.com/us/securityadvisor/pes... (Spyware scan)

http://www.ca.com/us/securityadvisor/vir... (Virus scan)

http://www.pandasecurity.com/homeusers/s... (Panda Antivirus)

http://www.housecall.trendmicro.com/... (TrendMicro)

http://www.eset.com/onlinescan/... (Nod32)

http://support.f-secure.com/enu/home/ols... (F-secure)


After using these, it's ESSENTIAL to install at lowest possible 3 antispywares. Do NOT use more than 1 antiVIRUS as they conflict.

The best things in go are FREE, and great free software can be found @:

Superantispyware.com (Superantispyware FREE version)
lavasoft.com (Ad-aware)
emsisoft.com (A-squared FREE)
safer-networking.org (Spybot S&D)
javacoolsoftware.com (SpywareBlaster, EULAlyzer, & MRU-Blaster)
microsoft.com (Windows Defender)
grisoft.com (AVG AV)
Avast.com (Avast AV)
avira.com (Avira AV)
activevirusshield.com (AOL Virus Shield, which is primarily Kaspersky for free)
siteadvisor.com (Tells you how protected websites are)
phoenixlabs.org (Peerguardian blocks malware, governing body, and anti-p2p org's)
zonealarm.com (Top Notch Firewall)
comodo.com (Another Top Notch firewall)
iobit.com (Advanced Windows Care)
Eusing.com (Registry cleaner)
ccleaner.com (Junk database cleaner)



Now if you can afford it, the best software to BUY are:

Spy Sweeper
Security Task Manager
Norton Internet Security (Uses CPU but it's nice if you can afford to use those resources up)
Kaspersky (BEST! =D )
Bitdefender
F-secure (Same as Kaspersky)
Linkscanner (Blocks exploits in concrete time)
Advanced Uninstaller

If in attendance's ever ONE wallet you suspect is infected, you can be in motion to a couple of sites that enjoy single folder scanners which use MULTIPLE engines to scan a report.
They are virusscan.jotti.org and virustotal.com

If you're PC is squeaky verbs, re-enable system restore because it IS well brought-up to hold but we needed to shut it stale to delete the malware.
Just RIGHT-click on "My Computer." Select "Properties" consequently below the 'System Restore' tab, UN-check "Turn bad system restore."


*Another entity to consider is using another browser besides Internet Explorer. IE have profoundly of payment holes,
making it smaller quantity sheltered than other browsers. I prefer Firefox from mozilla.org.
It's of late as flowing to use and have like mad of spick and span little add-ons you can toy around beside. By itself, it is also safer from exploits than IE.*


As other, things will rise and fall for you. I hope the best for everybody. As other, others may disagree but in attendance's solely one path to find things out---try it! As long
as you hold an UPDATED Antivirus, Antispyware, & firewall, things will shift smoothly. And browse sagaciously. As a side memo, please email me any/all websites you get the infection from or if any are popping up or hijack your page so I can assist further financial guarantee software's measures.
Sometimes you may procure a NEW and Unknown malware and I can submit it to be blacklisted to companies.
Thx. Hope I be competent to oblige and fix anything needed. If I own, please consider returning & departing a nice comment and
"Best Answer" to whomever you think deserves it...
I do not suggest you turn rotten system restore. Find the program in control panel/add and remove programs/remove the program. Then control panel/internet connections/change connections/generals tab/delete adjectives of your cookies and history, run a virus program, restart.