I think i have a virus....
playing on a gmod server and my chrome opens and links me to freecomputerupdates.com

what should I do because I only have ms security essentials....
< >
1-8 / 8 のコメントを表示
Go to Control Panel>Programs and Features and delete anything that is out of place, that would be my first step.
最近の変更はZigZachが行いました; 2014年7月13日 22時46分
Sometimes you "agree" installing those that you don't uncheck some "special additions" of some free software. By doing this most AV don't react. I would check installed programs for unknown entries.
Also just in case run a check with Malwarebytes.
akiranyo の投稿を引用:
Sometimes you "agree" installing those that you don't uncheck some "special additions" of some free software. By doing this most AV don't react. I would check installed programs for unknown entries.
Also just in case run a check with Malwarebytes.

yea thanks for your advice i found what the problem was.... so the other day [yesterday] i had to transfer some files over to my frineds laptop via usb in which his laptop is loaded with viruses when i plugged the flash drive in an odd flash drive manager came up and said "installing sofware to flash drive" and the computer never recognized the drive. so i just used a cd rom to transfer the files. anyway later that night i plugged in the flash device into my computer and everything looked fine on it. I am not saying that is was his laptop that gave my the virus. but it was very likely considering he has a antivirus system that is called noretuns that when he downloaded he thought it was the official norton.... i havent downloaded anything in the past 15 days besides dayz so meh :\ and i never leave the boxes cheaked when downloading adobe, java or any other program like that. thanks anyway i just did a system restore from 10 days ago and i will download malewarebytes in a bit. thanks
最近の変更はHølland601が行いました; 2014年7月14日 10時57分
Your Google Chrome is infected by malware or a 'drive-by'...

Open Chrome Menu on the browser toolbar.

Tools > Extensions

Look for odd extensions and click on the trash can to completely remove it.

Use anti-malware software such as:

Lavasoft Ad-Aware: http://www.lavasoft.com/products/ad_aware_free.php
Spybot Search and Destroy: http://www.safer-networking.org/mirrors/
Malewarebytes is another good one to use.

Ensure the URL are correct and valid before downloading, use a different web-browser or disable the extensions first.
最近の変更はAzza ☠が行いました; 2014年7月14日 11時38分
Azza ☠ の投稿を引用:
Your Google Chrome is infected by malware or a 'drive-by'...

Open Chrome Menu on the browser toolbar.

Tools > Extensions

Look for odd extensions and click on the trash can to completely remove it.

Use anti-malware software such as:

Lavasoft Ad-Aware: http://www.lavasoft.com/products/ad_aware_free.php
Spybot Search and Destroy: http://www.safer-networking.org/mirrors/
Malewarebytes is another good one to use.

Ensure the URL are correct and valid before downloading, use a different web-browser or disable the extensions first.

yea that is the first thing i did was looked at my extentions and there was nothing there.. also i recently downloaded malewarebytes from the official .org site about an hour ago. thanks and i am fairly sure the virus is gone. anyway it wasn't really a very bad virus from my understanding and from the reading i have done on the norton forums it is no trojan that is going to steal my credit card information. other people are having the same thing and the sites that it links the person to are blocked by google anyway... but what i think it is is a website to one of those indian teamviewer scams where they gain controll over the computer by having you go to a website and downloading a certain program simalar to teamviewer.
I snooped that website - it generates random URLs (so you can't access via the domain)

## (domain removed for safety)/o/treasure_javaupdate/Java_Updater_Setup.exe

SHA1: a6ab8b440208ff533413becfaacd1650d22b90f6
Name: TrojWare.Win32.IBryte.AE

iBryte Desktop contains remote access plus adware dump...

Ask Toolbar
Facemoods Toolbar
PageRage
Buzzdock
DropDowndeals
SanitySwitch
Babylon Toolbar
Yontoo Layers adware

So your right, it probably didn't reach you with it's full payload. The payload would of come from that second website, via a faked Java "Drive-By" download/install (ensure you haven't installed a new version or duplicate of Java lately - if unsure, remove them all and clean install the latest version from the offical website if you use it). However, the idea isn't to damage, rather dump ads onto your system, then offer fake software / payment help to clean up the mess they originally created.

Under your Control Panel > Programs And Features.
Look for and uninstall if found the following (plus any of the above previously mentioned):

Ask Toolbar
PlayBryte
Java (if publisher not Oracle or just smelling fishy)
最近の変更はAzza ☠が行いました; 2014年7月14日 15時26分
Azza ☠ の投稿を引用:
I snooped that website - it generates random URLs (so you can't access via the domain)

## (domain removed for safety)/o/treasure_javaupdate/Java_Updater_Setup.exe

SHA1: a6ab8b440208ff533413becfaacd1650d22b90f6
Name: TrojWare.Win32.IBryte.AE

iBryte Desktop contains remote access plus adware dump...

Ask Toolbar
Facemoods Toolbar
PageRage
Buzzdock
DropDowndeals
SanitySwitch
Babylon Toolbar
Yontoo Layers adware

So your right, it probably didn't reach you with it's full payload. The payload would of come from that second website, via a faked Java "Drive-By" download/install (ensure you haven't installed a new version or duplicate of Java lately - if unsure, remove them all and clean install the latest version from the offical website if you use it). However, the idea isn't to damage, rather dump ads onto your system, then offer fake software / payment help to clean up the mess they originally created.

Under your Control Panel > Programs And Features.
Look for and uninstall if found the following (plus any of the above previously mentioned):

Ask Toolbar
PlayBryte

yea i just got rid of java and i actually had 2 javas java update 55 and java update 7. i also don't have any unwanted programs like that on my list. i am fairly cartain that both of of the java things that i had were from oracle but when i deleted the java update 55 it promted me to get administrator acces from an unknown publisher [then deleted javaupdate 55 like the java update 7] which is kinda odd but it may be correct because usually when deleting stuff like that they dont throw there name out.
going to redownload java from here https://www.java.com/en/

and yes i made sure it didn't download mcafee with the java....
最近の変更はHølland601が行いました; 2014年7月14日 15時37分
< >
1-8 / 8 のコメントを表示
ページ毎: 1530 50

投稿日: 2014年7月13日 22時29分
投稿数: 8