My old computer was Win XP and I’d run AdAware about once a week. It would always pick up a bunch of tracking cookies and minor crap picked up across the web.
My new computer is Win 7 and so far AdAware hasn’t picked up anything at all. It’s been a few weeks.
Is Win 7 just that much better at keeping a system clean? :gotme:
Computer has been running fine until today when I went to a shady website to watch / stream the Bills game. An alert came up after about an hour of watching the game saying Adobe Flash wanted to modify my system… I clicked ‘no’ but it kept asking over and over again. I did NOT click yes at any point and instead used ctrl-alt-del to close firefox. And then I started to get BS pop ups from “win 7 security” which is obviously some fake program.
I’ve seen that one already, it’s one of the more shitty ones to remove. Ok here we go.
#1. Do you have any other user accounts on the computer? If so log into that account, install Malwarebytes, update it, run and remove it #2. If you don’t have other user accounts, start the computer in safe mode and install Malwarebytes. To get into safe mode reboot the computer hit F8 repeatedly like your life depends on it.
It could be a lot worse than you think. Start with downloading Malwarebytes. Do a full scan. If you can’t run malwarebytes (virus won’t let you) then report back.
Well see I guess. How the fuck did I get this thing anyway? I’m sure Flash is updated on my system but maybe it has a hole… Windows is definitely up to date too.
Ran the two programs suggested by bleeping computer and I’m now scanning with Malwarebytes.
The reason you got the flash thing and your computer still got popped is because those malware websites try a bunch of different attack vectors at the same time.
There is currently some pretty sweet Java exploit, and a couple flash 0days that patches just came out for.
You could try running Firefox + Adblock Plus + NoScript
No matter how good the AV is most of it works off signatures and its extremely easy to pack/crypt an a virus on the fly so it doesn’t match anything in the signature database/definitions file of the AV.
It really starts with making sure all your software is current I would suggest http://secunia.com/vulnerability_scanning/personal/ this will find the majority of software on your PC and compare its to their database to see if its current it also allows you to update from with in.
I havent really read much in this thread, but im gonna paste the guide i made for removing these in a few minutes.
These viruses usually (almost always...) put themselves in the "c:\users\*username*\appdata" folder as a hidden file
for vista/7, and c:\docs + settings\*username*\application data\, in the root of those folders or inside another folder with about
10 random characters/numbers. So, all you have to do is delete that file and it will either allow you to have your computer back,
or you may have to do a couple other things.
First: if you see any of your files are hidden, not viewable, or items in your start menu are no longer there
(check programs>accessories and see if the typical stuff is there, or inside other folders). If for some reason,
any of that stuff is hidden or not visible, DO NOT CLEAR TEMP FILES OR RUN ANY CCLEANER/LIKE PROGRAMS.
these files get moved into the temp folder, and if removed will almost always
require a reinstall of the OS.
Restart computer into safemode (Just safemode, do not do safemode w/ networking). Log in, click start, run,
and load 'msconfig'. in msconfig, click 'Startup'. Look through that list for something 'weird'. it will either be
a bunch of random letters (ie. 9dXH3kL03.exe), Something Obvious (Win 7 Security.exe), or 3 letters (kvh.exe).
Sometimes there will be multiple ones, uncheck them if you see them. Another easy way to tell, is in the box, there
is the 'command' sort option. click on that and look for any programs that are listed to run in the c:\documents and
settings\ or c:\users. Those are going to be the virus(es).
If you uncheck them, write down/take note of where those locations are. (kvm.exe with a command of c:\docs +
settings\user\application data\kvm.exe") Thats the folder the virus is located. Browse to that folder (you may have
to unhide system files) and delete those files, and any other files that may have a similar name structure. (3 letters,
random characters, or obv virus names)
once they are deleted, restart the computer, and go into normal windows. if all is good, you will be able to open
programs and continue as if nothing happened. If not, you will still not be able to load programs (unless you right click
on them and choose 'start' - which is an option the virus usually creates to be able to run itself) and some of your files
are hidden.
If you are still unable to run programs or unable to find a lot of start menu programs or your personal files, post back
and ill send the fixes for those.
also, sometimes just running the latest versions of security essentials, windows updates, microsoft removal tool, and windows defender will remove and correct these issues.