06-14-2011, 01:01 AM | #1 | ||
Hall Of Famer
Join Date: Dec 2001
Location: Catonsville, MD
|
I need your help with a virus
I downloaded a program today from Steam, and afterwards, my PC started acting funny. It had screens pop up and tell me to download Anti Virus Vista 2012. I knew that was likely those nasty spyware/virus things that try to get you to do something. I brought up Firefox to get more info, and every window and tab said the same thing. I brought up Windows Task Manager and found a file name I didn't recognize, traced to a file folder with local file,s closed it, and deleted it. Then I brought up Firefox, and everything looked good.
I tried to open another program and it wouldn't open. Instead, it brings up the "Open With" Choose Which program to Open this File with window. WTF? I run Symantic, which I get for free from Wayne State, and it found some minor things, and I hoped that was the end. It wasn't, and I used Run As Administrator to open stuff, still unable to open things normally (this includes buttons on the lower toolbar at the bottom of Windows). I managed t d/l and reinstall the latest Firefox, just in case it lingered there. I ran on outdated AdAware. No dice. This isn't the first time that Symantic has blown saving my PC from stuff and not able to find it, even updated automatically. I decided to bite the bullet and purchase McAfee. I downloaded the file, and tried to open it with Administrator. My Task manager accepts that the install opens, and then it closes again just a few seconds later. I tried rebooted my PC, and some things would open with Administrator ,and others wouldn't (such as a new version of AdAware, my recently purchased McAfee ) Something weird is on my system. Reboots, nothing spicy in my Task Manager, Symantic missed, an outdated AdAware missed. My Google-Fu is unable to find a solution or even what the problem is. Why can't I open a quick little install file after trying to d/l it three times? What is interfering with my PC by forcing me to deal with these Open With windows? If you have experienced this, or have technical knowledge is this area, it would be greatly appreciated. I;ve bee working on it for an hour now to no solution.
__________________
Check out my two current weekly Magic columns! https://www.coolstuffinc.com/a/?action=search&page=1&author[]=Abe%20Sargent |
||
06-14-2011, 01:02 AM | #2 |
Hall Of Famer
Join Date: Nov 2000
Location: The State of Insanity
|
Get Spybot Search and Destroy
__________________
Check out Foz's New Video Game Site, An 8-bit Mind in an 8GB world! http://an8bitmind.com |
06-14-2011, 01:03 AM | #3 |
Hall Of Famer
Join Date: Dec 2001
Location: Catonsville, MD
|
Oh, it looks like I also d/l'd a song from iTunes today That's all I've d/led for most of a week.
__________________
Check out my two current weekly Magic columns! https://www.coolstuffinc.com/a/?action=search&page=1&author[]=Abe%20Sargent |
06-14-2011, 01:39 AM | #5 |
Hall Of Famer
Join Date: Dec 2001
Location: Catonsville, MD
|
Alright, I'm trying spybot search hand destroy right now.
__________________
Check out my two current weekly Magic columns! https://www.coolstuffinc.com/a/?action=search&page=1&author[]=Abe%20Sargent |
06-14-2011, 02:01 AM | #6 |
Hall Of Famer
Join Date: Dec 2001
Location: Catonsville, MD
|
I found five things, and one included whatever i was that was mucking about my system. Now McAfee is installed and running ,and it's finding new things too. It's like no one program finds everything. It's wierd.
__________________
Check out my two current weekly Magic columns! https://www.coolstuffinc.com/a/?action=search&page=1&author[]=Abe%20Sargent |
06-14-2011, 02:23 AM | #7 | |
Coordinator
Join Date: Nov 2003
|
Quote:
This has always been my experience whenever I've had something nasty. Whether it's different software's specializing in different things or whether it's the virus creators specifically blocking certain features of certain AV softwares I have no idea, but usually a safe mode boot, a run through of Spybot, Ad-Aware and AVG/Trend Micro followed by the same course again for good measure will kill anything and everything. |
|
06-14-2011, 08:18 AM | #8 |
Hall Of Famer
Join Date: Sep 2002
Location: Troy, Mo
|
Run this one first:
http://www.malwarebytes.org Run it until all is clean, then run this one: http://www.superantispyware.com |
06-14-2011, 08:24 AM | #9 |
Head Coach
Join Date: Oct 2000
Location: North Carolina
|
let me second combofix for something we used when nothing else would work. big fan of malwarebytes too.
|
06-14-2011, 08:25 AM | #10 | |
Resident Alien
Join Date: Jun 2001
|
Quote:
Those are my two weapons of choice. |
|
06-14-2011, 08:35 AM | #11 |
Head Coach
Join Date: Oct 2002
Location: Seven miles up
|
__________________
He's just like if Snow White was competitive, horny, and capable of beating the shit out of anyone that called her Pops. Like Steam? Join the FOFC Steam group here: http://steamcommunity.com/groups/FOFConSteam |
06-14-2011, 08:44 AM | #12 | |
College Benchwarmer
Join Date: Oct 2003
|
Quote:
MR, do you use the free versions? |
|
06-14-2011, 08:49 AM | #13 |
College Starter
Join Date: Dec 2006
|
I would 3rd the malwarebytes suggestion.
I had a nasty virus on my wife's laptop that even appeared in safe mode. I tried literally 5 different (free) anti-virus apps and malwarebytes got rid of the dam thing. |
06-14-2011, 09:20 AM | #14 |
SI Games
Join Date: Oct 2000
Location: Melbourne, FL
|
MalwareBytes is pretty bullet proof imho, whenever family or friends screw up their machines I generally find that does the trick.
|
06-14-2011, 09:22 AM | #15 |
Coordinator
Join Date: Jun 2002
Location: The scorched Desert
|
Malwarebytes is good and I would also throw in a recommendation for AVG2011 as a permanent virus protection. They have a free version that has done a better job than anything I have ever paid for.
|
06-14-2011, 09:34 AM | #16 |
H.S. Freshman Team
Join Date: Feb 2010
Location: Pistol City
|
I had something similar to this on my computer about two months ago. All I was thinking was I wanted to do with the person that came up with this. Finally got rid of the thing with a combination of MalwareBytes, Microsoft Security Essentials, and Glary Utilities.
|
06-14-2011, 09:38 AM | #17 |
Hall Of Famer
Join Date: Oct 2002
Location: Massachusetts
|
I'm surprised it was in a Steam game though. I find that tough to believe (not saying I don't believe you though). You might think about shooting them off an email and letting them know...
|
06-14-2011, 09:44 AM | #18 | |
Hall Of Famer
Join Date: Dec 2002
Location: Mass.
|
Quote:
I'm not going to say that it definitely was or wasn't Steam, but this is the exact type of symptoms from a very very very common iframe attack from simple web browsing. Many web sites (including various commonplace or trusted sites) get infected at times and most people's systems are vulnerable because they don't block scripts, don't block iframes and don't keep their system updated on security patches. Abe said he used firefox above, so I would recommend using the addon called "NoScript" and then when installing it, make sure to go into settings and disable iframes. I also always recommend people keeping systems patched for security issues regularly. Usually vulnerabilities are exploited within the day of being announced (and sometimes even before). |
|
06-14-2011, 04:00 PM | #19 |
Hall Of Famer
Join Date: Sep 2002
Location: Troy, Mo
|
|
06-14-2011, 04:14 PM | #20 |
General Manager
Join Date: Oct 2000
Location: Chicago
|
I agree with the tools that people are recommending, but if I'm trying to exterminate a virus then I would ideally like to have instructions that are specific to the one plaguing me.
Remove Win 7 Antispyware 2012 and Vista Antivirus 2012 name changing rogue (Uninstall Guide) I would try following the instructions listed here, and their "weapon of choice" is the aforementioned Malwarebytes program. In the event that you don't trust the site I've referenced, I'm guessing there would be similar instructions provided by Symantec, McAfee, or other AV vendors as well. Bottom line - I think Malwarebytes is a terrific program, but I prefer using it in tandem with virus-specific instructions rather than just hoping it (or some pairing of programs) are good enough to root this stuff out without knowing what exactly they are seeking. |
06-14-2011, 04:16 PM | #21 |
General Manager
Join Date: Oct 2000
Location: Chicago
|
Also, if you need to download software don't do it from the infected computer - I'm sure this is "duh" advice for many here, but I see people do this all the time. And they can't understand why the AV software won't download properly. Use another computer, copy any required software to a USB drive, and come back to your infected system well armed to fix the problem.
|
06-14-2011, 04:30 PM | #22 |
College Benchwarmer
Join Date: Oct 2000
Location: speak to the trout
|
Malware Bytes + system restore to a point before the infection has been the tried and true method in my office, and we get 1-2 of these a month.
__________________
No signatures allowed. |
06-14-2011, 04:40 PM | #23 |
College Benchwarmer
Join Date: Oct 2003
|
|
06-14-2011, 05:09 PM | #24 |
General Manager
Join Date: Aug 2001
Location: Kansas City, MO
|
I always install WinPatrol on my computers. If anything tries to install or adjust the registry, it lets me know. I haven't had a virus since I started using it, though I have averted many attacks.
|
06-14-2011, 07:53 PM | #25 | |
College Benchwarmer
Join Date: Oct 2003
|
Quote:
I've had this on my machines for years and really like it. |
|
06-15-2011, 01:36 AM | #26 |
Hall Of Famer
Join Date: Dec 2001
Location: Catonsville, MD
|
Luckily, with McAffee, The Spybot sweep and kill, Symantic and AdAwre we are rocking and clean.
__________________
Check out my two current weekly Magic columns! https://www.coolstuffinc.com/a/?action=search&page=1&author[]=Abe%20Sargent |
06-15-2011, 07:41 AM | #27 |
Pro Rookie
Join Date: Nov 2005
Location: Tennessee
|
If you are still having problems, these guys at safer networking forums will get you fixed up:
Malware Removal - Safer-Networking Forums |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
Thread Tools | |
|
|