Solved How do i stop popup claiming my PC has been infected?

idahosurge

New member
Member
Local time
2:50 AM
Messages
81
I have had this happen in the past week on two different Win7 PC's. I am sure that it is not a virus on either PC because after it happens I can shut the PC off without doing anything else then reboot and I scan with the latest version and updates of Spybot, Malwarebytes and Eset Nod32, all three come back as negative.

With IE8 I can be surfing the web and all the sudden I got a popup that says my PC has been infected and the resulting window looks like the program is scanning the PC. I have had this happen when I am at Yahoo's website so it does not have anything to do with questionable websites. I recall that the popups had a name like Microsoft Security Isentials 2012 or whatever. I believe that I have seen them called by two different names.

A month ago on an XP PC and last night on this PC I tried to shut the popup program down and all that did was get my PC infected. Running Spybot and Malwarebytes got rid of the infection and after that I ran Eset Nod32 and that came back with no infections found.

How can I get this to stop popping up on my PC and running its bogus scan?
 

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan

My Computer My Computer

At a glance

Windows 10x64 Build 1709Intel i7 7700HQ Kaby Lake16 GB DDR4 @2400Nvidia Geforce GTX 1060
Computer type
Laptop
Computer Manufacturer/Model Number
MSI GE72VR Apache Pro-416
OS
Windows 10x64 Build 1709
CPU
Intel i7 7700HQ Kaby Lake
Motherboard
Micro-Star Intl. MS-179B (U3C1)
Memory
16 GB DDR4 @2400
Graphics Card(s)
Nvidia Geforce GTX 1060
Screen Resolution
1920x1080 120Hz
Hard Drives
256 GB Nvme M.2 SSD

1TB HDD@7200
Cooling
Cooler Blast 4
Keyboard
Steel Series
Antivirus
Bit Defender Free
Browser
Edge

My Computer My Computer

At a glance

Windows 7 Ultimate SP1 - 64 BitIntel Core i5 2500k2x4GB DDR3 1333HzAti Radeon 6770
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Novatech iRush Pro
OS
Windows 7 Ultimate SP1 - 64 Bit
CPU
Intel Core i5 2500k
Motherboard
Foxconn H67M-S/H67M-V/H67
Memory
2x4GB DDR3 1333Hz
Graphics Card(s)
Ati Radeon 6770
Sound Card
None
Monitor(s) Displays
Samsung S22B150
Screen Resolution
1920x1080
Hard Drives
2x500GB
PSU
500W
Cooling
Fan
Keyboard
HP KU0316
Mouse
Wireless Logitech M185
Internet Speed
20MB/s
Antivirus
Avast Free
Browser
Google Chrome
Other Info
Logitech M185 Mouse
KU-M316 Keyboard
Thanks for the links it was useful information. That is what I had, but with Spybot and Malwarebytes I had already gotten rid of it. I downloaded and ran RKill and TDSSKiller, they did not find anything so the previous runs of Spybot and Malwarebytes got rid of it. After running RKill and TSDDKiller I ran Malwarebytes again to be on the safe side and Malwarebytes did not find anything.

My real question is how to I prevent this in the future? Isn't ESET NOD32 suppose to prevent this? I have ran into this twice now on Yahoo's website and I am tired of this! How do I stop it from attacking my PC?
 

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan

My Computer My Computer

At a glance

Win 7, 32bit, Premium
OS
Win 7, 32bit, Premium
If it happens consistently at the same web site, I would suspect the web site. If it happens randomly, then there may be a piece of the malware remaining that didn't get removed.

Norton Power Eraser will remove stubborn malware.

Norton Rescue Tools

Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully.
If you continue to have the same problem, you might want to try a Bootable AV rescue disk, which will scan the system before the infection has a chance to initialize. Here is a site with a list of disks you can use:

Free Bootable AntiVirus Rescue CDs Download List

(Note, Kaspersky rescue disk has caused problems in the past. If they have remedied that, I do not know so you may wish to try one of the other disks before using that one)

It could also be random "fly by malware". If you are using Firefox, add a program called NoScript, that will stop any malicious scripts from running on a page. There is a similar program for IE, but I'm at a loss to recall what it is. Maybe someone can help me out on the name?

When you get that pop up message, it's best to use the Alt + F4 key to shut the window, since clicking on anything, including the red X can cause a d/l to initiate. Also, if it's convenient, shut down the net connection before shutting the window, to be even more sure something isn't sneaking into your system
 
Last edited:

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various

My Computer My Computer

At a glance

Windows 7 Professional SP1 64-bitIntel Core 2 Duo Processor E8300 @ 2.83GHz4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)Intel(R) G33/G31 Express Chipset Family
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Inspiron 530
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core 2 Duo Processor E8300 @ 2.83GHz
Motherboard
Dell Inc. 0RY007 (Socket 775)
Memory
4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)
Graphics Card(s)
Intel(R) G33/G31 Express Chipset Family
Sound Card
Integrated 7.1 Channel Audio
Monitor(s) Displays
Acer G245HQL 23.6" LED(1920x1080@60Hz)
Screen Resolution
1920 x 1080
Hard Drives
Disk 0 HITACHI 1TB OS Installed - Disk 1 HITACHI 1TB For Backups
Keyboard
Dell USB Keyboard
Mouse
Dell Optical USB Mouse
Internet Speed
DSL 10 meg
Antivirus
Symantec(SEP)
Browser
Pale Moon

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan
If it happens consistently at the same web site, I would suspect the web site. If it happens randomly, then there may be a piece of the malware remaining that didn't get removed.

Norton Power Eraser will remove stubborn malware.

Norton Rescue Tools

Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. You should use this tool very carefully.

If you continue to have the same problem, you might want to try a Bootable AV rescue disk, which will scan the system before the infection has a chance to initialize. Here is a site with a list of disks you can use:

Free Bootable AntiVirus Rescue CDs Download List

(Note, Kaspersky rescue disk has caused problems in the past. If they have remedied that, I do not know so you may wish to try one of the other disks before using that one)

It could also be random "fly by malware". If you are using Firefox, add a program called NoScript, that will stop any malicious scripts from running on a page. There is a similar program for IE, but I'm at a loss to recall what it is. Maybe someone can help me out on the name?

When you get that pop up message, it's best to use the F4 key to shut the window, since clicking on anything, including the red X can cause a d/l to initiate. Also, if it's convenient, shut down the net connection before shutting the window, to be even more sure something isn't sneaking into your system

Thanks, I will keep this in mind.

Maybe I will try Firefox and NoScript.
 

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan
It could also be random "fly by malware". If you are using Firefox, add a program called NoScript, that will stop any malicious scripts from running on a page. There is a similar program for IE, but I'm at a loss to recall what it is. Maybe someone can help me out on the name?


Were you talking about AdBlock IE? With google this is the only thing I can find for IE that mentions anything about NoScript.
Adblock IE

Everyother thing regarding NoScript and IE8 on Goolge says the NoScript function is included.
 

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan
Hi, idahosurge.

I suggest that you check for vulnerable third-party software on your computer -- Java and Adobe products have had critical security updates due to vulnerabilities. In addition, with Java, you need to check add/remove programs to make sure you don't have any old versions still installed, as didn't get the update process correct for many years.

To check if your system is missing security updates or has insecure applications, install Secunia Personal Software Inspector or, alternatively, visit Secunia - The Leading Provider of Vulnerability Management and Vulnerability Intelligence Solutions . The Secunia Software Inspector runs through your browser with no installation or download required and does the following:
  • Detects insecure versions of applications installed
  • Verifies that all Microsoft patches are applied
  • Assists you in updating your system and applications

In addition, as long as you are not having a problem opening .exe's and desktop shortcuts aren't missing, it wouldn't hurt to do a thorough cleaning of temp files:

Download TFC to your desktop

  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean


A month ago on an XP PC and last night on this PC I tried to shut the popup program down and all that did was get my PC infected.

Unfortunately, your attempt at closing the pop-up was actually permission to install. Never click anywhere on the fake A/V pop-up box. Instead, use the keyboard combination Alt + F4 to close it.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
Thanks Corrine, I updated Java to 6.30 and updated Acobat 9 Pro. I had already ran Secunia. I use CCleaner so running TFC was not necessary.
 

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan
One thing NOT to do is click anywhere on the pop-up. Including the X. Close the tab or IE.

I have had this happen when I am at Yahoo's website so it does not have anything to do with questionable websites.
Sorry to disagree but Yahoo is one of the worst offenders for malware infections. They sell ad space and don't control the contents. Any third-party hack can put what they want in the ad, including scripts, and Yahoo doesn't filter them. It got so bad Yahoo and anything related is blocked on my PCs. Also be sure you have the latest version of Adobe Flash. And don't allow Flash to run on all web pages--Be selective. It's another "open door" to your PC.
 

My Computer My Computer

At a glance

Windows 7 Pro-x64i7-2600 3.4GHz - 3.8GHz Turbo8Gb - 2x4GB, Muskin 991770 PC3-1333Integrated Intel HD 2000
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
One thing NOT to do is click anywhere on the pop-up. Including the X. Close the tab or IE.

I have had this happen when I am at Yahoo's website so it does not have anything to do with questionable websites.
Sorry to disagree but Yahoo is one of the worst offenders for malware infections. They sell ad space and don't control the contents. Any third-party hack can put what they want in the ad, including scripts, and Yahoo doesn't filter them. It got so bad Yahoo and anything related is blocked on my PCs. Also be sure you have the latest version of Adobe Flash. And don't allow Flash to run on all web pages--Be selective. It's another "open door" to your PC.

Thanks for the information regarding Yahoo, now I know!

Adobe Flash has been upgraded, thanks!
 

My Computer My Computer

At a glance

Win7 Ult 64bi7 950Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18BFG GTX 285OCFU
OS
Win7 Ult 64b
CPU
i7 950
Motherboard
P6T Deluxe v2
Memory
Mushkin Redline #998691 DDR3 1600MHz @ 6-7-6-18
Graphics Card(s)
BFG GTX 285OCFU
Monitor(s) Displays
Asus VW266H
Hard Drives
Seagate 7,200 RPM 750GB
WD VR 10,000 RPM 300GB
WD VR 10,000 PPM 600GB
PSU
Corsair 850TX
Case
HAF-932
Cooling
TRUE Rev C w/ Delta FFB1212EH-PWM Fan
Any site can be bad, even the supposed "safe" sites. In the past, sites such as Fox News, The New York Times, Time Magazine and other popular sites have all been infiltrated with malicious code and banners.

Firefox offers a nice plug in called QuickJava, which allows you to enable/disable Java, CSS, Silverlight and other functions, all from the status bar quickly without having to dig though settings.
 

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Nicely explained, Borg 386.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate

My Computer My Computer

At a glance

Window 7 Home Premium 32 bitAMD Athlon 2
Computer Manufacturer/Model Number
Compaq Presario
OS
Window 7 Home Premium 32 bit
CPU
AMD Athlon 2
As Carwiz said, never click anywhere on one of those popups. That's like inviting a vampire into your home. Without the invitation, they can't enter.

When you see a popup, try to close the browser to clear it. If that option is disabled by the malware, then right-click the Taslbar, open Task Manager, and try to stop the browser under the Applications tab. In some cases, the malware delivery program (popup) just recreates itself. When that happens, try rebooting the computer to avoid infection. If you run across a situation where rebooting is also blocked, just hold in the power button and shut the computer down. The potential for damage is lower with a forced shutdown than it is from the infection.
 

My Computer My Computer

At a glance

Windows 7 Home Premium, 64-bitIntel Core i7-920 processor (8 MB L3 cache, 2...8 GB Dual Channel DDR3 SDRAM at 1066 MHz – 4 ...ATI Radeon HD 5450 1GB DDR3
Computer Manufacturer/Model Number
Dell XPS 9000 Desktop
OS
Windows 7 Home Premium, 64-bit
CPU
Intel Core i7-920 processor (8 MB L3 cache, 2.66 GHz)
Memory
8 GB Dual Channel DDR3 SDRAM at 1066 MHz – 4 DIMMs
Graphics Card(s)
ATI Radeon HD 5450 1GB DDR3
Sound Card
Integrated 7.1 channel audio
Monitor(s) Displays
Dell UltraSharp 2007FP with AS501 Sound Bar
Hard Drives
640 GB 7200 rpm SATA hard drive
FreeAgent Go 320 GB external hard drive
Internet Speed
AT&T 3G wireless via Sierra Wireless USBConnect device
Other Info
Microsoft Security Essentials
Windows Firewall
Another options to close the popup is the keyboard command Alt + F4.
 

My Computer My Computer

At a glance

Windows 7 & Windows Vista Ultimate
OS
Windows 7 & Windows Vista Ultimate
Back
Top