Hi there,
I think i have a virus on my computer that i have partially dealt with. since yesterday i have been getting lots of pop ups advising me that computer is infected (including a 'windows security' alert asking me if i wihed to run antivirus software-which i closed)and also i was unable to open any program watsoever on my Administrator account. My guest account still worked fine, but i cannot download anything on the guest account.
I was unable to run any antivirus/malware programes in admin account-however i was able to do so in guest. Avira Antivir picked up a few files which it said it had dealt with. also i ran the malwarebytes software-which found nothing, as did symentac.
However logging back on to Admin-the problem still persisted.
Anyway- the next time, as soon as i had logged into administrator account i opened task manager (i would not have been able to open this if i had waited a few mins for all programmes to open up on start up). it showed no applications but many processes open. there were 2 processes both called fddqsysguard.exe which looked suspicous. also there was a process called wscntfy.exe which kept moving up and down the list-so icould never end task it. everytime it moved, a red warning shield would appear in the bottom right tray.many of these shields appeared.
i restarted the computer in safe mode. in msconfig-start up i saw 2 suspicious startup items. both were called fddqsysguard. both had same command ( C:Documents and settings\Administrator\Local Settings\Application Data\josnwb\fddqsysguard.exe) and the same location (HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run).
I unchecked both of these startupitems. i then went to the folder josnwb and deleted it-i then emptied recylce bin.
on restarting the computer-i have noticed that everything seems to be working ok now in admin account. however in msconfig there is still 1 file that says under start up items fddqsysguard.exe. the command is the same, but the location no longer has the HKLM prefix -it just starts of with software. i also can not see any folders named josnwb. i have unchecked this again and restrted the computer. now everytime i start my computer it automatically opens msconfig and advises me that i am only open in selective start up and i should change to normal startup. howver evrytime i selct normal start up-the fddqsysguard.exe is always checked. so now i just ignore the sys config warning that comes up on start up.
my IE wasnt working-until i uncheked the proxy settings.
Everything appears to be working but i still think that the virus may be lurking on my pc. do you have any suggestions please?
also i cannot seem to update avira.-itsaysan error occured dutring download.
many thanks
I think i have a virus on my computer that i have partially dealt with. since yesterday i have been getting lots of pop ups advising me that computer is infected (including a 'windows security' alert asking me if i wihed to run antivirus software-which i closed)and also i was unable to open any program watsoever on my Administrator account. My guest account still worked fine, but i cannot download anything on the guest account.
I was unable to run any antivirus/malware programes in admin account-however i was able to do so in guest. Avira Antivir picked up a few files which it said it had dealt with. also i ran the malwarebytes software-which found nothing, as did symentac.
However logging back on to Admin-the problem still persisted.
Anyway- the next time, as soon as i had logged into administrator account i opened task manager (i would not have been able to open this if i had waited a few mins for all programmes to open up on start up). it showed no applications but many processes open. there were 2 processes both called fddqsysguard.exe which looked suspicous. also there was a process called wscntfy.exe which kept moving up and down the list-so icould never end task it. everytime it moved, a red warning shield would appear in the bottom right tray.many of these shields appeared.
i restarted the computer in safe mode. in msconfig-start up i saw 2 suspicious startup items. both were called fddqsysguard. both had same command ( C:Documents and settings\Administrator\Local Settings\Application Data\josnwb\fddqsysguard.exe) and the same location (HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run).
I unchecked both of these startupitems. i then went to the folder josnwb and deleted it-i then emptied recylce bin.
on restarting the computer-i have noticed that everything seems to be working ok now in admin account. however in msconfig there is still 1 file that says under start up items fddqsysguard.exe. the command is the same, but the location no longer has the HKLM prefix -it just starts of with software. i also can not see any folders named josnwb. i have unchecked this again and restrted the computer. now everytime i start my computer it automatically opens msconfig and advises me that i am only open in selective start up and i should change to normal startup. howver evrytime i selct normal start up-the fddqsysguard.exe is always checked. so now i just ignore the sys config warning that comes up on start up.
my IE wasnt working-until i uncheked the proxy settings.
Everything appears to be working but i still think that the virus may be lurking on my pc. do you have any suggestions please?
also i cannot seem to update avira.-itsaysan error occured dutring download.
many thanks