Donate SIGN UP

I think I have a virus

Avatar Image
Yorky Lass | 14:38 Sat 05th Mar 2011 | Computers
25 Answers
I’m running XP Home, IE8. For over a week my back button has required several rapid clicks to work on some sites. I now have some unsavoury pop ups even though pop up blocker is turned on. System Restore will not work on any date either, it says it has failed. I have run a full scan on Malwarebytes and AVG but they show nothing. I have also run all these in Safe Mode and still get the same results.
I was wondering if I had a virus in System Restore itself. I know to turn it off and do a restart but if it wasn’t there then I loose all the restore points.
Has anyone any advice please?
I also have an external hard drive for back up and I know I have added a few files recently but can’t remember if it was before or after I noticed the back button not working. Once I have cleared my problem will it be best to delete everything on the external hard drive and back up again?
I have to go out now but will check back when I return.
Many thanks in advance.
Gravatar

Answers

1 to 20 of 25rss feed

1 2 Next Last

Best Answer

No best answer has yet been selected by Yorky Lass. Once a best answer has been selected, it will be shown here.

For more on marking an answer as the "Best Answer", please visit our FAQ.
Turn off System Restore, do full scan with a good online AV scanner like Housecall, then a full scan with Malwarebytes Anti Malware.
This 'may' need Rkill and Combofix method to sort it tho.
See how you get on with above to start with.
Switch System Resore back on after clean.
SR will replicate many infected files .. so can restore bed stuff, as well as the good stuff. Hence scanning/cleaning with it off.
Question Author
Thanks Craftypig for your very quick reply and thanks Albags.
Albags, I did exactly what you suggested and found 3 trojans with Housecall and 15 problems running Malwarebytes. All now saying clear. However since I logged back on AB I have had 3 chances to win something, one saying I'm the 1,000,000 visitor I could possibly be the winner of a mercedes. I can't remember if use to get these or if I'm paranoid and now notice everything,which I previously just ignored, or if my pop up problem hasn't been resolved.
Back button still taking a few clicks so that must be something totally different. Have you any more ideas please ?
Question Author
Now got a really rude pop up - help !!!!!! There must still be something lurking.
Hi
Have you cleared out ALL Temp Internet Files from browser, and emptied all other Temp Folders of files that are delete-able?

What Anti-Virus? Please don't say AVG Free.
If you are NOT wanting any ads or page displays ... go here ...
http://www.mvps.org/winhelp2002/hosts.htm

1/2 way down, download hosts.zip .................
Extract to desktop and run the mvps.bat
Restart. That will block ads almost completely.
I think you still have adware somewhere.
Open Add/Remove from Control Panel.
Look carefully down list for any shopping or price saver entries. Remove (or try to) if you see any.
Internet Explorer/Tools/Internet Options/Programs/Manage Add-Ons ...
Under Toolbars and Extensions, look for any suspect entries there. Disable if there are.

In Windows Explorer, navigate to Windows/Downloaded Program Files
Anything there you absolutely do NOT need .. R Click and Remove. (Windows downloads ActiveX and other stuff here to do with web use) Many infections start here.
Question Author
I'm not very technical so I hope by running Ccleaner that is clearing ALL Temp internet files that you mentioned. I do do that regularly.
Yes I am running AVG. I was wondering why it missed the Trojans!! I've looked at the link you sent but not being very technical,is it as complicated as it looks? I don't understand what you mean Extract to desktop and run the mvps.bat. I'm afraid.
I've looked at everything in the add/remove list and I can't see anything at all that I didn't expect to be there.
Thanks for you continuing help.
Hi
You have the saved zip file somewhere .. like desktop ..
R Click on and extract here.
You will see the contained files.
Double click on the mvps file (extension will be hidden with some peoples settings)
Question Author
Thank you Albags.
Back button still not working though, has anyone any ideas please. It's very annoying.
OK
I'll have a think .. Unusual problem.
Still getting any popups after the hosts file mod and a reboot?
Did you check the Add-Ons as asked earlier?
Once this is sorted, I advise you to remove AVG and install Microsoft Security Essentials. This is a lot better than AVG at the moment.
Windows installed MUST be a genuine copy tho.
You can try an over-install of IE8.
Download this and install. This may fix your back button problem : )

http://www.softwarepa...ernet-explorer-8.html
Albags has given excellent advice, but you could try downloading the free Avira anti virus programme and running it.(disable AVG while you do it).

I would ditch IE and use Firefox and its email prog. Thunderbird (though Yahoo webmail is good from security point of view)
I agree .. but two AV softwares should not be installed at same time.

Avira is also ok. I also agree about Firefox too. I used it for 4 years now. Firefox 4 Beta at the moment ... and good it is too.
However, one must get things ironed before they get put away : )
Bow to your wisdom Albags but I did say disable AVG while Avira is tried. A friend who is semi pro keeps it on a memory stick for this purpose.
Fair enough.
I run Hijackthis, RKill, Combofix and Stinger all from a USB stick just for 'special occasions' : )
Question Author
I have taken a look at the add-ons and the only lines on Toolbars and Etensions are to do with AVG and these are disabled as I am not using the AVG toolbar - is this right?
I have looked at the program files and I think I use everything. The trouble is I am not technical at all. So what looks ok to me may very well not be. Saw something called Gstatic.com so Googled it and found it was something to do with Google, but that was about the only thing that looked "strange". I'm still getting a few popups but what is "the hosts file mod and reboot" you asked about Albags? The only thing I understood there was reboot. You are writing to a real thicky!!!!!!!!
I am finding,however, that AB is the site I am having most problems with but am putting that down to the fact I am on here so long,

1 to 20 of 25rss feed

1 2 Next Last

Do you know the answer?

I think I have a virus

Answer Question >>