Author Topic: pop-up removal  (Read 3127 times)

0 Members and 1 Guest are viewing this topic.

onedog

  • Guest
pop-up removal
« on: August 23, 2008, 02:21:59 AM »
Hi all-This is my first post so I hope all goes well.
Today my computer became infected with a bogus virus warning pop-up. Avast detected two malware "bugs" and I deleted as instructed. However,upon reboot the bogus warnings reappeared on the desktop and avast agained warned of the same worms. I then disabled system restore,rebooted in safe mode,rescanned with avast and two spyware programs (Ewido and Super antispyware).  Upon rebooting back to normal mode avast detected nothing as did the anti-spyware programs. However the original pop-up window is still on my desktop  even though it now appears to be "dead" i.e. nothing happens when I click on it and it is not detected anywhere. Is it possible it is still active and hidden within the system somewhere and how do I get rid of that warning window?? Thanks so much in advance for any replies/help!!

wyrmrider

  • Guest
Re: pop-up removal
« Reply #1 on: August 23, 2008, 02:40:14 AM »
the antivirus popup is a symptom of a malware symptom
can be mild on virulent depending on the version and mix of the "package"
first
run Malware bytes Anti Malware (free) AND their Rogue remover
click the "remove" button which will also quarantine the found files

rt click on the avast ball and update Program (and database at the same time if necessary
then rt click and schedule a boot time avast scan
reboot

then start a new topic in the Virus and Worms forum and post the logs along with your system info, other  malware programs amount of memory, windows version etc

we'll figure out where to go from there

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: pop-up removal
« Reply #2 on: August 23, 2008, 03:22:41 AM »
I suggest:

1. skip, you've already done (Disable System Restore and then reenable it again.)
2. Clean your temporary files.
3. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
4. Use (again) SUPERantispyware, MBAM or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
5. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.
The best things in life are free.

onedog

  • Guest
Re: pop-up removal
« Reply #3 on: August 23, 2008, 08:53:22 PM »
Success!! I ran a avast boot scan and a virus/malware was found but when I tried to move it to quarentine , the cpu quit responding. So I rebooted, ran Malwarebytes and it found numerous problems (other programs never detected them) . Once again I ran a boot scan and and was was able to quarentine the virus. I restarted the computer end everything was gone (the bad stuff)! As a double check I also ran Avast rootkit checker and everything came back clean. I hope this all means that I am free to go out and play now. Thanks again very much for your all your help!!

jerry12

  • Guest
Re: pop-up removal
« Reply #4 on: August 23, 2008, 09:23:26 PM »
pop ups can be mean i hate them and a lot of times a pop up block will stop stuff that you need to show up its a vicious circle . :(

wyrmrider

  • Guest
Re: pop-up removal
« Reply #5 on: August 24, 2008, 12:34:48 AM »
go back to tech's list
run the superantispyware scan
do numbers 7 and 8

you could also install spywareterminator  or windows defender for some preventive care
if st leave off the optional toolbar etc

sometime later run the DrWeb or a KAspersky on line scan and post back if ANYTHING is found
notice how you had to ping pong back and forth with the removal tools to get at the baddie

now run ccleaner
defrag
set a new restore point

(no playing for you)