so stupid me downloaded a file the other day that i probably shouldnt have and now i get these constant pop-ups about how my computer is infected with viruses and spyware Check that your Windows HOSTS file does not contain an entry for any AVG / Grisoft websites in it... UHOH! You may wish to Subscribe to this thread so that you are notified when you receive a reply.

Your firewall is doing its job by blocking this kind of traffic and alerting you about these intrusion attempts. 3 more replies Relevance 79.17% Question: Infected by WIN.MSSQL.worm.helkern + some downloader antivirus integrated with GMER actively protecting over 230 million PCs aswMBR - antirootkit with avast! I'm thinking I might have picked up malware/spyware on there perhaps. It's just that everytime this happens, my internet disconnects.

When the window opens click on the startup tab and make sure there are checkmarks in every entry. Post the entire contents of C:\ComboFix.txt into your next reply. Other programmes trigger Ashampoo for authorisation of programmes however AVG8 does not trigger Ashampoo Firewall permission box.

I also had one that said the attack was resulting from /DEVICE/HARDDISKVOLUME1/PROGRAM FILES\SAFARI\SAFARI.EXE.

Any help will be much appreciated!


DDS (Ver_10-12-12.02) - NTFSx86
DDS (Ver_10-12-12.02) - NTFSx86

Should a legitimate entry be removed (otherwise known as a 'false-positive'), simple steps can be taken torestore the entry.

Would it make sense to System Restore to before the first attempt at installing AVG 8 Free then un-install AVG 7.5 free before again downloading a fresh copy of AVG 8

clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives. BLEEPINGCOMPUTER NEEDS YOUR HELP! Please continue as follows:Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Anyway everything looks and appears clean now (no more pop ups and random websites), however i keep seeing an intrusion being blocked by norton so i guess im still infected... Around this time my firewall program "Zone Alarm" kept going off when I switched my computer on.

My IE just froze my PC this has happened a few times now :( 

Answer:Regular Attacks 

Attacking computer has not been blocked, its address is possibly spoofed.I also have added Malware Antispyware; SuperAntispyware and SpywareBlaster to see what i can find but they all find nothing. Double click combofix.exe & follow the prompts.

I downloaded a bad file earlier today that evidently was bundled with malware/viruses. Botnets and Zombie computers scour the net and will randomly scan a block of IP addresses. Double click on combofix.exe and follow the prompts.

I stopped the scan when gmer started scanning windows folderGMER - http://www.gmer.netRootkit scan 2010-03-25 02:23:43Windows 5.1.2600 Service Pack 3Running: gmer.exe; Driver: C:\DOCUME~1\Ali\LOCALS~1\Temp\aftirfoc.sys---- System - GMER 1.0.15 ----SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter

Some of the executables in the firewall permissions list don't appear among those in the AVG 8 folder (avgam.exe, avgnsx.exe) Firewall has no provision for 'safe' Internet addresses.

Please, do not select the "Show all" checkbox during the scan. Please also tell us if you have your Windows CD/DVD handy.Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain Where is it coming from and is there a way to shut it down, report it, put it out of business? I can't run gmer on my computer.

The link to this virus is: hxxp:// Disabled By MOD The virus restricted me from accessing my local disk drive via conventional means, conventional meaning just going to My Computer and I just wonder if someone could take a look as the guy from PC World only looked at it for 5-10 minutes.

Answer:Infected by WIN.MSSQL.worm.helkern + some downloader + can't even run gmer log, Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help.

I don't have any idea how to disinfect my computer. My name is Gringo and I'll be glad to help you with your computer problems. News 2013.01.04 Detect and remove rootkits with GMER 2013.01.03 New version 2.0.18327 with full x64 support has been released. 2011.03.18 New version has been released. 2010.11.24 New version It has been happening for about a month and happens without warning and randomly - it might happen about 7 or 8 times all in one go, or it might (like