 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - How do i stop popup claiming my PC has been infected? |
12-24-2011
|
#1 | | |
How do i stop popup claiming my PC has been infected? I have had this happen in the past week on two different Windows 7 PC's. I am sure that it is not a virus on either PC because after it happens I can shut the PC off without doing anything else then reboot and I scan with the latest version and updates of Spybot, Malwarebytes and Eset Nod32, all three come back as negative.
With IE8 I can be surfing the web and all the sudden I got a popup that says my PC has been infected and the resulting window looks like the program is scanning the PC. I have had this happen when I am at Yahoo's website so it does not have anything to do with questionable websites. I recall that the popups had a name like Microsoft Security Isentials 2012 or whatever. I believe that I have seen them called by two different names.
A month ago on an XP PC and last night on this PC I tried to shut the popup program down and all that did was get my PC infected. Running Spybot and Malwarebytes got rid of the infection and after that I ran Eset Nod32 and that came back with no infections found.
How can I get this to stop popping up on my PC and running its bogus scan?
| My System Specs | | OS Win7 Ult 64b CPU i7 950 Motherboard P6T Deluxe v2 Memory Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18 Graphics Card BFG GTX 285OCFU Monitor(s) Displays Asus VW266H PSU Corsair 850TX Case HAF-932 Cooling TRUE Rev C w/ Delta FFB1212EH-PWM Fan Hard Drives Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB |
12-24-2011
|
#2 | | Windows 7 Home Premium x64 |
Thats a infection. NOT from Microsoft ,heres instructions : Remove Win 7 Security 2012 (Uninstall Guide) | My System Specs | | System Manufacturer/Model Number Asus G74Sx OS Windows 7 Home Premium x64 CPU Intel i7 2670 Qm @2.20 Motherboard AsusTek G74Sx,1.0 Memory 8 GB DDR3 Graphics Card Nvidia Geforce GTX 560M -2040mb Monitor(s) Displays Generic Screen Resolution 1600 x 900 Hard Drives 500gb internal x 2 @ 7200 rpm
1t Western Digital External
500gb Seagate External |
12-24-2011
|
#3 | | Windows 7 Ultimate x86/Ubuntu |
Can you provide us with a Screenshot please.
Press Print Screen on your Keyboard, paste it into Paint (CTRL+V), Save it as [imagename].
Upload it to Tinypic
And upload it in your next post: Screenshots and Files - Upload and Post in Seven Forums | My System Specs | | OS Windows 7 Ultimate x86/Ubuntu CPU Intel Core i5 2500k at 3.3 GhZ Memory 2x4GB DDR3 1333Hz Graphics Card Ati Radeon 6770 Sound Card Speakers Monitor(s) Displays 1x 15" HD 572 Screen Resolution 1024x768 Keyboard Wired Keyboard Mouse Wired Mouse Cooling 3x Fans Hard Drives 2x500GB Internet Speed 10MB/s Other Info Netbook: Dell Inspiron Mini |
12-24-2011
|
#4 | | |
Thanks for the links it was useful information. That is what I had, but with Spybot and Malwarebytes I had already gotten rid of it. I downloaded and ran RKill and TDSSKiller, they did not find anything so the previous runs of Spybot and Malwarebytes got rid of it. After running RKill and TSDDKiller I ran Malwarebytes again to be on the safe side and Malwarebytes did not find anything.
My real question is how to I prevent this in the future? Isn't ESET NOD32 suppose to prevent this? I have ran into this twice now on Yahoo's website and I am tired of this! How do I stop it from attacking my PC? | My System Specs | | OS Win7 Ult 64b CPU i7 950 Motherboard P6T Deluxe v2 Memory Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18 Graphics Card BFG GTX 285OCFU Monitor(s) Displays Asus VW266H PSU Corsair 850TX Case HAF-932 Cooling TRUE Rev C w/ Delta FFB1212EH-PWM Fan Hard Drives Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB |
12-24-2011
|
#5 | | |

Quote: Originally Posted by idahosurge With IE8 I can be surfing the web
Not to be off-subject, but you prefer IE8 over IE9 ? 9 is said to be more secure. | My System Specs | | |
12-24-2011
|
#6 | | Windows 7 Home Premium 32 bit |
If it happens consistently at the same web site, I would suspect the web site. If it happens randomly, then there may be a piece of the malware remaining that didn't get removed.
Norton Power Eraser will remove stubborn malware. Norton Rescue Tools Quote: Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully. If you continue to have the same problem, you might want to try a Bootable AV rescue disk, which will scan the system before the infection has a chance to initialize. Here is a site with a list of disks you can use: Free Bootable AntiVirus Rescue CDs Download List
(Note, Kaspersky rescue disk has caused problems in the past. If they have remedied that, I do not know so you may wish to try one of the other disks before using that one)
It could also be random "fly by malware". If you are using Firefox, add a program called NoScript, that will stop any malicious scripts from running on a page. There is a similar program for IE, but I'm at a loss to recall what it is. Maybe someone can help me out on the name?
When you get that pop up message, it's best to use the Alt + F4 key to shut the window, since clicking on anything, including the red X can cause a d/l to initiate. Also, if it's convenient, shut down the net connection before shutting the window, to be even more sure something isn't sneaking into your system
Last edited by Borg 386; 12-25-2011 at 09:14 AM..
| My System Specs | | System Manufacturer/Model Number Dell Hell oh Well OS Windows 7 Home Premium 32 bit CPU Intel Core 2 Duo 2.93GHz Memory Not much with my ADHD Graphics Card ATI Radeon HD 4350 Monitor(s) Displays I have one...It's bright. A 19 inch CRT actually. Keyboard It's 10 years old and amazingly still works Mouse Same deal with the mouse, 10 yrs old, if it ain't broke... Case Don't get on my case...man :D Cooling I have an Air Conditioner & Diet Pepsi Hard Drives 250 GB Main Drive, 2 - 1 TB Externals, various FD's. |
12-24-2011
|
#7 | | Windows 7 Professional 64-bit |
According to bleepingcomputer.com you were suppose to merge FixNCR.reg first.
Also: | My System Specs | | System Manufacturer/Model Number Dell Inspiron 530 OS Windows 7 Professional 64-bit CPU Intel Core 2 Duo Processor E8300 @ 2.83GHz Motherboard Dell Inc. - ORY007 Memory 4GB DDR2 SDRAM (PC2-5300) Sound Card Integrated 7.1 Channel Audio Monitor(s) Displays 20" Widescreen Digital Flat Panel-E207WFP Screen Resolution 1680 x 1050 Keyboard Dell USB Keyboard Mouse Dell Optical USB Mouse Hard Drives Hard Drive #1 HITACHI 1TB OS Installed - Hard Drive #2 HITACHI 1TB For Backups Internet Speed DSL 3 meg |
12-24-2011
|
#8 | | |

Quote: Originally Posted by Flatiron According to bleepingcomputer.com you were suppose to merge FixNCR.reg first.
Also: I did run FixNCR.reg before I ran RKill and TDSSKiller. | My System Specs | | OS Win7 Ult 64b CPU i7 950 Motherboard P6T Deluxe v2 Memory Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18 Graphics Card BFG GTX 285OCFU Monitor(s) Displays Asus VW266H PSU Corsair 850TX Case HAF-932 Cooling TRUE Rev C w/ Delta FFB1212EH-PWM Fan Hard Drives Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB |
12-24-2011
|
#9 | | |

Quote: Originally Posted by torre 
Quote: Originally Posted by idahosurge With IE8 I can be surfing the web
Not to be off-subject, but you prefer IE8 over IE9 ? 9 is said to be more secure. I do prefer IE8 because I can not stand the way they changed the search function on IE9, but I may have to consider switching. | My System Specs | | OS Win7 Ult 64b CPU i7 950 Motherboard P6T Deluxe v2 Memory Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18 Graphics Card BFG GTX 285OCFU Monitor(s) Displays Asus VW266H PSU Corsair 850TX Case HAF-932 Cooling TRUE Rev C w/ Delta FFB1212EH-PWM Fan Hard Drives Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB |
12-24-2011
|
#10 | | |

Quote: Originally Posted by Borg 386 If it happens consistently at the same web site, I would suspect the web site. If it happens randomly, then there may be a piece of the malware remaining that didn't get removed.
Norton Power Eraser will remove stubborn malware. Norton Rescue Tools Quote: Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully. If you continue to have the same problem, you might want to try a Bootable AV rescue disk, which will scan the system before the infection has a chance to initialize. Here is a site with a list of disks you can use: Free Bootable AntiVirus Rescue CDs Download List
(Note, Kaspersky rescue disk has caused problems in the past. If they have remedied that, I do not know so you may wish to try one of the other disks before using that one)
It could also be random "fly by malware". If you are using Firefox, add a program called NoScript, that will stop any malicious scripts from running on a page. There is a similar program for IE, but I'm at a loss to recall what it is. Maybe someone can help me out on the name?
When you get that pop up message, it's best to use the F4 key to shut the window, since clicking on anything, including the red X can cause a d/l to initiate. Also, if it's convenient, shut down the net connection before shutting the window, to be even more sure something isn't sneaking into your system Thanks, I will keep this in mind.
Maybe I will try Firefox and NoScript. | My System Specs | | OS Win7 Ult 64b CPU i7 950 Motherboard P6T Deluxe v2 Memory Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18 Graphics Card BFG GTX 285OCFU Monitor(s) Displays Asus VW266H PSU Corsair 850TX Case HAF-932 Cooling TRUE Rev C w/ Delta FFB1212EH-PWM Fan Hard Drives Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB How do i stop popup claiming my PC has been infected? problems? All times are GMT -5. The time now is 01:11 AM. |  |