Question:
My computer is in distress. It's just been overrun by spyware and possibly viruses. Help!?
Nick P
2007-05-18 15:53:24 UTC
I have a laptop with Windows XP Pro. I only had a free antivirus program installed. My wife recently went to a music download site and the laptop has now been completely hijacked. Internet Explorer windows start popping up as soon as I boot up. It won't connect to my wireless network and is slow as a snail. Progams are getting installed automatically and there are icons all over the desktop. I downloaded Spybot and ran several scans, but it's not helping much. Is there anything I can do short of erasing the hard drive? Is that even going to solve the problem?
Fourteen answers:
Elvis
2007-05-18 15:56:01 UTC
Try this free online tool



http://www.trendsecure.com/portal/en-US/free_security_tools/housecall_free_scan.php
G
2007-05-18 15:56:35 UTC
Before your reformat, scan your PC with this. Its free and safe to use.



http://superantispyware.com/

SUPERAntiSpyware is the most thorough scanner on the market. Our Multi-Dimensional Scanning and Process Interrogation Technology will detect spyware that other products miss! SUPERAntiSpyware will remove ALL the Spyware, NOT just the easy ones!

Easily remove over 100,000 pests such as SmitFraud, Vundo, WinFixer, SpyAxe, SpyFalcon, WinAntiVirus, AntiVermins and thousands more!



If you still have the same problem, scan your PC in safemode. This is how safemode works.



For Windows XP



If the computer is running it is best to shut down Windows and then turn off the power.



Begin by first clicking on the Start Button and then click on Turn Off Computer.



Now click on the Turn Off red colored icon to shut down your computer system.



It is best to wait between 15 to 30 seconds before you turn your system back on.



Turn on your computer and start tapping the F8 key on your keyboard.



Some Computers may display a keyboard error message if you begin tapping F8 too quickly.



Restart your computer again and begin tapping the F8 key a brief second or two later.



When the Windows Advanced Options Menu appears, Choose the Safe Mode option and hit Enter.



Windows will now boot your computer up in Safe Mode.
anonymous
2007-05-21 12:58:39 UTC
The one thing to remember about spyware removers is that they all do something different. Unfortunately, spyware and malware changes so quickly that there's really not a single application that can do it all for you. You may have to try more than one.



There's one thing that you should know, however. There are plenty of FREE spyware removers available. Get one of those before you throw down your hard earned money to buy one. Paying for a spyware remover should be a last resort with so many good free removers on the market. A lot of times, a free package will do the job with you having to come out of pocket.



You can find some more information on spyware and spyware removers, as well as some free spyware remover downloads on this page:



http://www.axalda.info/spyware.html
?
2007-05-18 16:02:51 UTC
First, you probably should run both Spybot and Ad-Aware SE. Both are free.



Second, they may do a better job if you run them in Safe Mode:



To get into Safe Mode:



1.Log out and reboot your machine.

2.When the machine starts the reboot sequence, press the F8 key

3.Select Safe Mode from the resulting menu.

4.The machine will continue booting, but the Windows desktop will look different. You won't be able to see the Internet, for instance. You may have to log in as Administrator to delete the bad files.

5.When you're finished, log out and reboot back into normal mode.
fuck off
2007-05-18 16:02:10 UTC
Download ADAware SE and AVG from www.download.com.

Also go into program files and delete anything that you suspect is infecting your computer. It is also worth booting up in safe mode and then deleting all these things. Also if you know what you are looking for go into regedit and delete them from there.If you have Spybot find the uninstall tab in the tools part and select what you know is infecting your computer.
cynthia ©
2007-05-18 15:58:00 UTC
Almost the same thing happened to my computer. Depending on where your wife went, it could've been just a virus site where they "pretend" to give out music. if you're downloading programs such as Spybot it won't help. sometimes those are fake. since you have mostly no programs on there, try reformating your computer, i reformated mine and it really helps! but remember to back up all of your files. Good luck!



*****Spy Ware or Anti Spy Ware or any of those other programs don't work!!! They're fake!!! they'll just give you more viruses!!!!!!!!!!*********
anonymous
2007-05-18 15:59:39 UTC
if you format with the windows disk, it will wipe your hard drive of everything. then you can reinstall. guess you know by now the term safe surfing, and that paid versions to protect you are better, but in defence of your free ain't virus, it does not look for spyware or malware. get adaware se and

a2squared, update all and run scans off line. you may still need bigger guns.
jojo5050
2007-05-18 15:58:17 UTC
DON'T DO ANYTHING THAT THE ABOVE GUYS ARE TELLING YOU, THERE JUST TRYING TO PLUG YOU THEIR SOFTWARE, WHICH MIGHT BE INFECTED ANYWAY.



USE SYSTEM RESTORE..............



Unplug any internet leads, switch on your computer, click on start, then all programs and then accessories, when you've got that menu, go down to system tools.

When you've got system tools got to SYSTEM RESTORE, now try restoring the computer back to a time when it was running better.



If it works, you will NOT have lost any programmes or files.

Definately try this BEFORE you reformat, as with reformatting you'll lose everything.
susuz@sbcglobal.net
2007-05-18 16:43:51 UTC
its called an adclick trojan refer back to my question (https://answersrip.com/question/index?qid=20070515232036AASglcn)

which has some solutions in answers i had that trojan about two days ago lol i used avast and the methods in the answers part to fully get rid of it but i will tell u what to do here as well



1. first download avast anti-virus

2. turn off system restore

3. scan your computer with avast

4. schedule a boot-time scan with avast (the scan may take up to 2 hours)

5. after your boot time scan rescan normally with avast

6. after the regular scan shutdown and restart your computer in safe mode (when turning on your computer repeaditely press f8 and select safe mode from the menu)

7. once in safe mode scan with avast

8. shutdown and turn your computer back on (it will be in normal mode)

9. download a-squared anti-malware

10. scan and delete any spyware and you have a completely trojan and spyware free system after you complete all these steps.



(note: turning off system restore, boot-time scanning, and safe-mode scanning all prevent the trojan from creating a copy of itsself when detected and all must be completed in the respectedly in order for the trojan to be completedly wiped from your system
anonymous
2007-05-18 15:56:17 UTC
Reformat your Hard Drive. All issues will be solved in less than an hour.
ScarletBloodDoll
2007-05-18 15:57:19 UTC
I would suggest you get AD-Aware or Spyware Doctor.
anonymous
2007-05-19 04:19:40 UTC
For all computer related problems please check out

http://computer-probs.blogspot.com/

It not only gives complete solutions but also offers

free downloads of effective softwares which can detect

and eliminate all spy ware /virus /ad ware /Trojans completely.
Yuy R
2007-05-18 15:58:38 UTC
Get Ad-aware, run it. Try doing this in safe mode.



Reformatting is your best bet.
anonymous
2007-05-19 04:04:47 UTC
This is the best advice money can buy, your gratitude is appreciated(you're welcome).

Follow these steps and it will remove almost all viruses and malware/spyware from your computer. It will also make your computer run faster.

.

•I know this procedure looks long, but much of this is explanatory text to help less experienced people.

•Please do not cheat by skipping any steps. You are only hurting yourself if you do. And you will waste more time. The goal is to get your PC fixed. Completing the steps in this generic guide may or may not resolve all of your malware problems, but in all cases it gets your PC into a known state to help make it easier for me to fix your problems. After completing all steps, if you still need help, please send a new question. You may have a problem trying to run steps in safe mode on user accounts that have limited priviledges. This will only be on Windows 2K, XP, & 2003 systems. Limited user accounts will not show when you boot into safe mode. You have two options, run the steps in normal boot mode which may not work to remove malware, or you can temporarily change the user account to an admin account and then complete the steps.

•0: Preliminary House Cleaning & Setup



Unistall Malware thru your computers Add?Remove program.

You MUST be sure that MSconfig is not being used to control Startups. Note: That some Window's OSs (like Win 2K) do not have MSconfig!

•MSConfig Startup Mode

Please go to Start > Run > type msconfig and click OK!

Select the General tab and select Normal Startup.

Thenclick Apply and OK and reboot PC before continuing.

Remain in this Normal Startup mode while your PC is being cleaned of malware.

1: Secondary House Cleaning



This second step of house cleaning may save a load of time later .

•Empty any quarantine folders for antivirus and antispyware applications. Make sure you do this. Logs could be huge otherwise. If you are a Symantec/Norton user make sure you empty their Norton Nprotect folder guarding the Recycle Bin. Empty your Recycle Bin

•Download and install CCCleaner

•MAKE SURE you download and avoid getting the Yahoo Toolbar version. I do not want you to install any unnecessary baggage.

•Also it is recommeded to login to all other User Accounts on the PC including the Administrator account which will only show when you boot in safe mode. Run CCleaner on each account. This can greatly reduce scan time and log sizes from the later scanning you will do below.

2: Enable viewing of hidden files, system files and file extensions



Some programs hide themselves by making their files invisible in normal Windows settings. Not doing this would allow file extensions commonly used by trojans and spyware to be hidden, for example a file ending in .exe or dll making manually finding it, if needed, difficult to impossible.





3: Do not use Multiple Antivirus Applications or Software Firewalls

•Antivirus: If you have multiple antivirus applications installed on your PC, please choose the one you prefer and uninstall all others. Do this now before continuing because you will only be asked to do it later if not done now. This does not mean online scanners. It is only referring to full antivirus applications like McAfee, Symantec, AVG, Avast, AntiVir, Kaspersky, etc.

•Firewall: Only use one software firewall. Running multiple software firewalls is unnecessary and using more than one software firewall on the same connection could cause issues with connectivity to the Internet or other unexpected behavior including excessive use of system resources which will slow down overall PC performance.

4: Downloading Tools



Download the following tools and save in your favorite download folder or create one, for example C:\Spyware Tools or C:\Downloads. ( It is not a good idea to download them to any folder within C:\Documents and Settings.) And then install, update, and configure as indicated below. Do not run the scans until later when indicated. Also DO NOT confuse the word download with the actual installation of the program. You should install all programs to their recommended (by the install program). default installation folders. First you download the files and then you install (if the program requires installation) the program. It is also a bad idea to download and save anything you need into any kind of Temp folder. Malware hides in Temp folders and standard cleaning practices will delete everything from Temp folders.



Download GetRunKey.Zip and ShowNew.Zip from the below links and extract all files from both ZIP files into a folder of their own. You can extract both ZIP files into the same folder. Like C:\MGTools While these tools will run from your Desktop, i strongly recommend that you DO NOT extract them to your Desktop. Please install them where recommended. Do not run the scans yet!!!





SpyBot - Search & Destroy

•PLEASE leave all settings at default!!!! Install, do the search for updates now and get any updates, then fix the below problem with Spybot default products. If you get an error message about "bad checksum" when trying to update, just choose a different server location. Also look for the Immunize feature in Spybot and use it. Do not use the Teatimer function. It can be a resource hog and also makes removal of certain problems more difficult. Make sure you leave the SDhelper ( IE bad download blocker) checked to install (this is the default).

•Fixing SpyBot's Ignore Products Bug: Please run SpyBot and get into the Advanced mode by selecting Mode and then Advanced mode. Then select Settings and the in the left column select Ignore Products. In the right window pane make sure the All products tab is selected. Then in that window, right click your mouse and choose "Deselect all". Now exit Spybot. We will run a scan later.

Now if running Windows XP, 2K or NT do the below. If you have Windows 95, 98, or ME skip to Downloads for Older Windows OS below. CounterSpy and AVG Antispyware will no longer run on the older Windows's OS.



CounterSpy



•If you had previously used a CounterSpy trial, you may not be able to run it again. If this is the case, then run the below AVG Antispyware Removal procedure and attach the log later.

AVG Anti-Spyware

•Only run the AVG Anti-Spyware procedure if you could not run CounterSpy. You do not need to run both of these.

Note: If you are using an older Windows OS you may not be able to run some of the above tools! So if you are running Windows 95, 98, or ME run SUPERAntiSpyware and save a log from it so you can attach it. This step is not required if you are running Windows XP, 2K or NT) HOWEVER, no matter what OS you are running, if you could not run CounterSpy or AVG Antispyware then run SuperAntiSpyware.





5: Cleaning Malware





Important Note Before continuing with the below scans:



The best method to remove malware is to do it after booting in Safe Mode with no connection to the internet possible and no browsers running. Booting in safe mode is important because best results are achieved since safe mode disables most drivers and running programs. If you cannot boot in safe mode due to the malware problem then run the scans in normal boot mode but make sure you tell us later in any messages you post.



Thus you will need to print or save these instructons locally in a text file so you can refer to them while offline. Do this before continuing!

•Reboot into safe mode

•Physically unplug your cable to the internet (even if you have dial-up, unplug modem)

•Shut down ALL unrequired applications including browsers

•Run Ccleaner with the default options to clean out temporary files. Only use the Default Scan on the Windows Tab and select Run Cleaner. Do not run any other options from other tabs.

•Run Spybot Search & Destroy and allow it to fix all that it finds. Make sure you use the Immunize feature and use the SDHelper function but do not use Teatimer.

•For Windows XP, 2K and NT users

•Run CounterSpy - Make sure you have it Quarantine all detections! Also attach the log from CounterSpy later if you still have problems. To get the log after scanning. Click View -> Spyware Scan -> View Spyware Scan History. Next click on the scan you want to view, then click view full details of scan. Right-click anywhere in the window that just opened, click on Select All, right-click again select Copy. Now open notepad and right-click anywhere in notepad and select Paste. Now Save As CounterSpy.txt. If you could not run CounterSpy for any reason, run the steps in the following link for AVG Antispyware Running AVG Anti-Spyware and allow it to fix all that it finds. Save the log as requested and attach it later if you still have problems and have to post a message requesting support.

•For Windows 95, 98 and ME users

•you should now run SuperAntiSpyware

6A: Online Virus And Trojan Scanning



Please run the below two online scanning tools and make sure you save and attach the logs later to any request for help that you post. From step 5 you should already be in safe mode but you will need to reconnect your cable now and possibly reboot and choose Safe Mode with Networking Support. If you cannot connect in safe mode for any reason (like dial-up users), run the online scanners in normal boot mode. You will need to use Internet Explorer to run these online scans. Also MAKE SURE YOU HAVE THE LATEST SUN JAVA Version installed by checking against the below link which normally has the most current version. This may help prevent some problems in trying to get these online scanners to run. Before installing the current version, you should uninstall all previous versions first!!!!





*** MAKE SURE YOU RUN BITDEFENDER BEFORE PANDA ACTIVE SCAN ***

*** But if Bitdefender cannot be run then run PandaActiveScan anyway ***





Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. Once Bitdefender completes the scan:



Click-on the Detected Problems tab. When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that i can easily view later while reviewing your log. All i have to do is rename the file to bdscan.html.



If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to me.



Panda ActiveScan It will only fix certain viruses and trojans. Most items found will not be fixed. When it finishes the scan click on See Report . Then in the next window click Save Report. The default report name is Activescan.txt. Just save it where you can find it so you can attach to your message when you begin a thread with a request for help. If you have any problems trying to get a PandaActiveScan log,If you use Avast antivirus and it gives you and error like below when trying to use Panda, just disable Avast while your run the scan. The error is a false positive. See the below link for more info.

Do the following and see what happens......


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...