Computer Support Forum

New Android lock-screen-type Ransomware ITW (ESET Research)

Question: New Android lock-screen-type Ransomware ITW (ESET Research)

WELIVESECURITY.COM - Aggressive android ransomware in USA: Tricks users with adult videos

ESET researchers have discovered the first known Android lock-screen-type ransomware spreading in the wild that sets the phone?s PIN lock.

Malware writers have stepped up their game, and with the new Android ransom-lockers, detected by ESET as Android/Lockerpin.A, users have no effective way of regaining access to their device without root privileges or without some other form of security management solution installed, apart from a factory reset that would also delete all their data.

Moreover, this ransomware also uses a nasty trick to obtain and preserve Device Administrator privileges so as to prevent uninstallation. This is the first case in which we have observed this aggressive method in Android malware.

CLICK HERE TO CONTINUE READING

Unlocking the device

The only way to remove the PIN lock screen without a factory reset is when device is rooted or has a MDM solution capable of resetting the PIN installed. If the device is rooted then the user can connect to the device by ADB and remove the file where the PIN is stored. For this to work, the device needs to have debugging enabled otherwise it?s not possible (Settings -> Developer options -> USB Debugging). User can use the following set of commands to unlock the device:


Code:
> adb shell
> su
> rm /data/system/password.key
After running the above commands, the PIN or password lock screen will be removed and the user can get to the device. In some cases, a device reboot is needed.

Conclusion

Fortunately, you can?t download this application from the official Google Play Store. This Trojan can be delivered to users from third party markets, warez forums or torrents. The most effective way to avoid getting infected and being locked out from your device is by proactive preventative measures.

Relevance 100%
Preferred Solution: New Android lock-screen-type Ransomware ITW (ESET Research)

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/download.php. (This link will automatically start a download of Reimage that you can save to your computer.)

Answer: New Android lock-screen-type Ransomware ITW (ESET Research)

Exactly such stuff is why i dont like Android at all.......

6 more replies
Relevance 71.75%

Google Android Security: How we stop fraudulent apps from holding you ransom
Recently we shared our 2016 Android Security Year in Review, which looks at how we protect Android users and their data. Today, we're taking a closer look at how we shield people from a rare?but particularly disruptive?potentially harmful app (PHA) known as ransomware. We?ve long had protections from ransomware in Android, and we added new ones in Nougat as well.

Ransomware is a type of app that restricts access to your device until a sum of money is paid. Ransomware usually presents itself in one of two forms: apps that restrict access to your device and then demand payment to regain access to the device, or apps that encrypt data on the device?s external storage (such as an SD card) and then demand payment to decrypt your data. To make the scam more convincing, fraudsters sometimes pretend to be from a credible law enforcement agency and accuse you of doing something illegal so you?re more likely to pay.Click to expand...

Ransomware protections in Android Nougat
With the release of Android 7.0 Nougat, we added to existing defenses against ransomware, and also made some changes to address some of the newer tactics of ransomware scams. Here are a few examples:

Safety blinders: Apps can no longer see which other apps are active. That means scammy ones can?t see what other apps are doing?and can?t inform their attacks based on activity.

Even stronger locks: If you set a locks... Read more

Answer:Ransomware Protection in Android Nougat (Google Android Security)

Spawn said:


Google Android Security: How we stop fraudulent apps from holding you ransom

Ransomware protections in Android Nougat
With the release of Android 7.0 Nougat, we added to existing defenses against ransomware, and also made some changes to address some of the newer tactics of ransomware scams. Here are a few examples:

Safety blinders: Apps can no longer see which other apps are active. That means scammy ones can?t see what other apps are doing?and can?t inform their attacks based on activity.

Even stronger locks: If you set a lockscreen PIN prior to installing ransomware, ransomware can?t misuse your device?s permissions to change your PIN and lock you out.

Whacking clickjacking: ?Clickjacking? tricks people into clicking something, often by obscuring permission dialogs behind other windows. You?re now protected from ransomware attacks that use this tactic to sneakily gain control of a device.
More Information at Source: How we stop fraudulent apps from holding you ransom
Related topic: Google - Android Security; How Verify Apps protects you against Potentially Harmful AppsClick to expand...

Great news ahead! If you have a device that will get upgraded to Nougat
 

4 more replies
Relevance 70.93%

News-friendly version: BlackEnergy trojan strikes again: Attacks Ukrainian electric power industry




On December 23rd, 2015, around half of the homes in the Ivano-Frankivsk region in Ukraine (population around 1.4 million) were left without electricity for a few hours. According to the Ukrainian news media outlet TSN, the cause of the power outage was a ?hacker attack? utilizing a ?virus?.

Looking at ESET?s own telemetry, we have discovered that the reported case was not an isolated incident and that other energy companies in Ukraine were targeted by cybercriminals at the same time.

Furthermore, we found out that the attackers have been using a malware family on which we have had our eye for quite some time now: BlackEnergy. Specifically, the BlackEnergy backdoor has been used to plant a KillDisk component onto the targeted computers that would render them unbootable.Click to expand...

Technical Report by ESET: BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry

Further Reading: SANS Security Blog | Potential Sample of Malware from the Ukrainian Cyber Attack Uncovered
 

More replies
Relevance 70.93%

The Gesellschaft zur Verfolgung von Urheberrechtsverletzungen (GVU) Ukash Ransom is a computer virus, which will display a bogus notification, that pretends to be from the German Cyber Crime police and states that your computer has been blocked due to it being involved with the distribution of pornographic material, SPAM and copyrighted content.

The GVU virus will lock you out of your computer and applications, so whenever you?ll try to log on into your Windows operating system or Safe Mode with Networking, it will display instead a lock screen asking you to pay a non-existing fine of 100 Euro in the form of a Ukash or PaySafeCard code.
Furthermore, to make its alert seem more authentic, this virus also has the ability to access your installed webcam ,so that the bogus GVU notification shows what is happening in the room.

To remove the GVU virus follow this guide: http://malwaretips.com/blogs/remove-gvu-virus/
 

More replies
Relevance 67.65%

Groove Music app doesn't have a Back button for tracks when the screen is locked nor does it have one for the Preview Screen at the top. This is completely unacceptable. Every music app player has this....

More replies
Relevance 66.83%

There are a number of Android apps (Google Play-sourced only), mainly photo and video-related, which I like a lot, although I don't really like using a tablet. I've researched a bit into Android emulators which run on Windows 7 e.g. here

6 best Android emulators for PC | Android Authority

and while the idea sounds great, I wonder -- Android is said to have loads of security flaws. I work pretty hard to keep my Win 7 PC clean (I hope!). Is there a risk that by running Android apps, I'm running security risks?

Answer:Does running an Android emulator bring Android-type security risks?

First of all, it's simply not true that Android has "lots of security flaws". Of course it's not immune to viruses and attackers, but it's not inherently that its an immense risk in it. There are vulnerabilities, but most problems actually came from using untrusted software that abuses the devise. As always, the number one vulnerability in any system is the user.

Now to business. There is no exact answer to that question. It will greatly depend on what emulator do you use and how it's exactly implemented, how does it manages to run Android software and how much does it emulated and how exactly. Frequently, I would expect a different implementation of the Android low level API, meaning that bugs in Android will never afect an emulator (which in turn can have its own bugs), unless some behavior is there "by design", in which case the emulator should attempt to copy it.
Besides, I would expect the emulator to isolate the host computer from malicious Android software (which is not generally aware of Windows existence). Unless an Android virus specifically targets a particular flaw of a particular version of a particular emulator (which as already happened with virtual machines), I won't worry too much about it.

The comes the problem of what programs do you install on the emulated Android. When you install a virus there, it will attempt to do the same malicious actions than it would do on a real phone. Some actions will work the same, for example those i... Read more

1 more replies
Relevance 66.83%

There are a number of Android apps (Google Play-sourced only), mainly photo and video-related, which I like a lot, although I don't really like using a tablet. I've researched a bit into Android emulators which run on Windows 7 e.g. here

6 best Android emulators for PC | Android Authority

and while the idea sounds great, I wonder -- Android is said to have loads of security flaws. I work pretty hard to keep my Win 7 PC clean (I hope!). Is there a risk that by running Android apps, I'm running security risks?

Answer:Does running an Android emulator bring Android-type security risks?

First of all, it's simply not true that Android has "lots of security flaws". Of course it's not immune to viruses and attackers, but it's not inherently that its an immense risk in it. There are vulnerabilities, but most problems actually came from using untrusted software that abuses the devise. As always, the number one vulnerability in any system is the user.

Now to business. There is no exact answer to that question. It will greatly depend on what emulator do you use and how it's exactly implemented, how does it manages to run Android software and how much does it emulated and how exactly. Frequently, I would expect a different implementation of the Android low level API, meaning that bugs in Android will never afect an emulator (which in turn can have its own bugs), unless some behavior is there "by design", in which case the emulator should attempt to copy it.
Besides, I would expect the emulator to isolate the host computer from malicious Android software (which is not generally aware of Windows existence). Unless an Android virus specifically targets a particular flaw of a particular version of a particular emulator (which as already happened with virtual machines), I won't worry too much about it.

The comes the problem of what programs do you install on the emulated Android. When you install a virus there, it will attempt to do the same malicious actions than it would do on a real phone. Some actions will work the same, for example those i... Read more

1 more replies
Relevance 64.37%

I recently purchased the Aspire R. I established a 4 digit pin code to unlock my Aspire. Until recently, when I tapped on the field to input my pin a on screen number keypad would appear in which I could use to type in the pin and unlock my laptop. That keypad has somehow dissapeared. I'm hoping someone might be able to help me change a setting or do something to get the on screen keypad to reapear when I tap on the field of the lock screen. Thank you in advance.

Answer:Lock Screen: on screen keypad to type in pin to un...

Aspire R what? What is the model number?Can you enter the pin with the keyboard?

1 more replies
Relevance 64.37%

I recently purchased the Aspire R. I established a 4 digit pin code to unlock my Aspire. Until recently, when I tapped on the field to input my pin a on screen number keypad would appear in which I could use to type in the pin and unlock my laptop. That keypad has somehow dissapeared. I'm hoping someone might be able to help me change a setting or do something to get the on screen keypad to reapear when I tap on the field of the lock screen. Thank you in advance.

More replies
Relevance 63.96%

hi

may i ask if somebody does test some variant of ransomeware against eset hips?

i would like to test some of them ,inside a virtual machine but i'm pretty scarry of them
thanks
eset hips include a new feature

 

Answer:Did somebody test ESET's HIPS against ransomware?

Yes I've test it ESET's HIPS, it's the worst...
 

1 more replies
Relevance 63.14%

Have you been infected by one of the new variants (v3 or v4) of the notorious ransomware TeslaCrypt? If your encrypted files had the extensions .xxx, .ttt, .micro, .mp3 or were left unchanged, then ESET has good news for you: we have a decryptor for TeslaCrypt.

We have been covering this malware for a few months now, sometimes along with Locky or beings pread by Nemucod. Recently, TeslaCrypt?s operators announced that they are wrapping up their malevolent activities:

On this occasion, one of ESET?s analysts contacted the group anonymously, using the official support channel offered to the ransomware victims by the TeslaCrypt?s operators, and requested the universal master decryption key.

Surprisingly, they made it public.

This allowed ESET to create a free decrypting tool promptly, which is able to unlock files affected by all variants of this ransomware. For instructions on how to use the decryptor, please visit the ESET Knowledgebase website.

Download : http://download.eset.com/special/ESETTeslaCryptDecryptor.exe

How do I clean a TeslaCrypt infection using the ESET TeslaCrypt decrypter
? How do I clean a TeslaCrypt infection using the ESET TeslaCrypt decrypter??ESET Knowledgebase
 

More replies
Relevance 62.32%

Hi,

I'm using Win 8.1 Pro. I want to use Microsoft Remote Control app on my Ipad to connect my PC (w Win8). Connection is ok, I can see my PC on the Ipad, but on my PC's screen the lockscreen will be visible. After the leaving the app I can't type my password
on my PC (return to normal use), I can see the textbox, PC doesn't accept any keyboard input. I have only one option, to restart the PC.

May I ask your help?

More replies
Relevance 62.32%

In addition to HIPS settings, here are settings for ESET's firewall to improve protection against ransomware

Tutorial in .pdf http://www.nod32.com.hr/Portals/66/PDF/anti-ransomware-techbrief_en.pdf
 

More replies
Relevance 62.32%

Hi!
I just found really nice looking ESET's tutorial for custom rules for HIPS to improve protection against ransomware. The video is for business products, but it applies also for home products:
Also a tutorial in .pdf http://www.nod32.com.hr/Portals/66/PDF/anti-ransomware-techbrief_en.pdf
 

More replies
Relevance 62.32%

No specific module to turn on in ESET IS but found a video here

for FW setup against ransomware, here

Configure Firewall rules for ESET to protect against ransomware

and for HIPS setup against ransomware it's here

Configure HIPS rules for ESET to protect against ransomware

So that pretty covers the ransomware protection for ESET IS

Why don't they just have a check box to enable ALL the above like for other vendors?
 

More replies
Relevance 62.32%

"A unique data-stealing trojan has been spotted on USB devices in the wild ? and it is different from typical data-stealing malware. Each instance of this trojan relies on the particular USB device on which it is installed and it leaves no evidence on the compromised system. Moreover, it uses a very special mechanism to protect itself from being reproduced or copied, which makes it even harder to detect.

What really sets this malware apart, however, is its self-protection mechanism."

The protection mechanism

The malware consists of six files. Four of them are executables and the other two contain configuration data. To protect itself from copying or reverse engineering, the malware uses two techniques. Firstly, some of the individual files are AES128-encrypted; secondly, their filenames are generated from cryptographic elements.

The AES encryption key is computed from the unique USB device ID, and certain disk properties of the USB drive hosting the malware. Hence, the malware can only run successfully from that particular USB device.

The name of the next file in malware execution chain is based on actual file content and its creation time. It is the first five bytes of SHA512 hash computed from mentioned attributes (file content concatenated with eight bytes of the creation time).

Because of this, filenames are different for every instance of this malware. Moreover, copying malware to a different place will replace the file creation time so that malicious a... Read more

Answer:Self-Protecting "USB Thief" Trojan (by ESET Research)

Webroot says "You are protected" against this very threat. However... Webroot uses the concept of trusted processes - and is default-allow for anything it doesn't detect as malicious.

I say "You are NOT protected" by Webroot's USB shield - until proven otherwise.

When I asked for proof of protection against the threat covered in the article - of course I got no reply.
 

1 more replies
Relevance 61.91%

I have a computer running Windows 7 that has been locked up for some months now. It is a Toshiba Portege ultrabook (no disks). I found the thread used to get rid of the virus using a program called Hitman which requires running the program for a 32 or 64 bit machine. The only other machine I have is my Toshiba Thrive. Can I somehow get the program and run it from this machine, so that I can get it onto a jumpdrive and then to the infected machine? I hope that was clear. I will do my best to answer any questions. Thanks in advance

Answer:Ransomware fix using Android tablet

Hi there,my name is Marius and I will assist you with your malware related problems.Before we move on, please read the following points carefully. First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding. Perform everything in the correct order. Sometimes one step requires the previous one. If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem. Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me. Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts. If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed. Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean. My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.   Let´s do this manually:  Scan with FRST (Recovery Environment)To run FRST on Vista and Windows7:For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a fla... Read more

more replies
Relevance 61.91%

How soon..?

ThreatPost reports that the Reveton cyber-crime gang is advertising an Android version of CryptoLocker. This program seems to have no way to actively infect an Android smartphone or tablet. To get it you have to actually download the APK file.

To trick you into doing this, the malware masquerades as a porn application. As you'd expect, this malware is designed to hide out on porn sites. If I'd said it once, I've said it a thousand times, never download Android apps from third-party sites of any sort and don't, no matter what operating system you're running, download programs from porn sites.

If you're fool enough to do this anyway and get infected, any time you try to use your device, you'll be shown a warning display that accuses you of viewing child pornography or equally ugly and illegal porn. It then goes on to say that you'll face a jail term of five to 11 years, unless, of course, you make a payment of $300 via MoneyPak. This is a legitimate pre-paid debt card service.

At this time, it's unclear if this malware, labeled Koler.A really is a port of CryptoLocker or simply a malware program using the infamous ransomware name in vain. From the limited experience security companies have had with this program it seems most likely it is not actually encrypting your files.

Source: ThreatPost via ZDNet
 

Answer:CryptoLocker Ransomware on Android, soon?

I guess CryptoLocker is up !

CM CryptoLocker Cleaner
 

6 more replies
Relevance 61.5%

ESET launch today the new generation of Mobile Security for Android

http://www.eset.com/int/home/products/mobile-security-android/
https://play.google.com/store/apps/details?id=com.eset.ems2.gp
 

Answer:New generation of ESET Mobile Security for Android

Thanks for the share.
 

4 more replies
Relevance 61.5%

Link to article

"Earlier this month, the word ramsomware became a hot topic in Android realm when a deadly threat called Simplelocker left various devices malfunctioning. The program, which appeared to be a Trojan, could automatically encrypt photos, videos, documents etc. stored on a device and demand a ransom for them to be decrypted again. Victims of Simplocker, or any such future threats, would be happy to find that they can now recover files without paying cybercriminals thanks to Avast?s latest security tool calledavast! Ransomware Removal on the Google Play Store. The free app will not only remove the ransomware Trojan for you, but also unlock the encrypted files on the infected device.

...Avast?s Ransomware Removal tool is for one-time use only for prevention and more permanent protection against Simplelocker. If your mobile device hasn?t been affected by ransomware, Avast also recommends a free app called ?Mobile Security & Antivirus? after the scan test to protect your device from future threats. When you?ve completed the scan test, you will also need to uninstall the app by tapping its button at the bottom."
 

More replies
Relevance 58.63%

Of all the malware threats out there, ransomware is arguably the nastiest. It locks your computer, encrypts your files, and then demands payment to free your data. You can remove it easily enough, but doing so won?t get you your files back. And unfortunately ransomware is beginning to make its way on to Android devices.

Avast has just released a Ransomware Removal app which will eliminate this type of threat from infected Android phones and tablets. It scans your device, tells you if you?re infected and if you are it will remove the malware and (according to Avast) decrypt your hijacked files.

Obviously, ransomware locks your device, making it difficult to take action, but you can install the app remotely.

The installation process is as follows:
Go to http://play.google.com from your computer.
Login to the Google Play with the same user information you use to login to your phone.
Search for the Avast Ransomware Removal application.
Click on the "Install" button, and the app will be installed on your device in a minute.
After the app is installed, click the app name in the notification bar.
The app will start and provide you with further instructions.
Uninstall the app when finished so you can install it again in the future if necessary.

The app was created following the discovery of a new proof-of-concept ransomware threat called SimplLocker which is able to encrypt photos, videos, and documents stored on smartphones and tablets. You can watch a video of i... Read more

Answer:Avast releases Android app designed to clean up ransomware from phones and tablets

Very nice! I will bookmark this this page!
 

2 more replies
Relevance 58.22%
Question: Ransomware .lock

Need assistance on how to recover files infected by ransomware .lock virus that has encrypted which has rendered my files unusable at this moment. Tried data recovery software and run antivirus tools but got no help till now. I got a HTML message from the hackers asking for payment for my files to be restored.
 

More replies
Relevance 58.22%

Russian anti-virus company Doctor Web has released a free Dr.Web utility that decrypts files corrupted byAndroid.Locker.2.originransomware. Once an Android handheld is infected, the malicious program encrypts photos, documents, videos and other information stored on the SD card, locks the device's screen and demands a ransom to restore it to normal operation. To counter this threat, users of Dr.Web comprehensive protection software for Android can now request the utility from Doctor Web's technical support.

Discovered in May, the extortionist Android.Locker.2.origin poses extreme danger to user data. On an infected mobile device, the extortionist searches the available memory cards for files with the following extensions: .jpeg, .jpg, .png, .bmp, .gif, .pdf, .doc, .docx, .txt, .avi, .mkv, and .3gp. It encrypts the files and adds the extension .enc to the filenames. Then the mobile device's screen is locked, and a message is displayed that accuses the user of distributing adult content and demands a ransom to unlock the device. To enhance the effect, the extortionist can also add a photo of the user, made with the handheld's front camera, to the ransom demand message.


After thoroughly examining the ransomware, Doctor Web designed a special utility that will most likely decrypt files corrupted by the malicious application, making it unnecessary for users to pay a ransom.

The utility scans the available SD card for encrypted files and attempts to r... Read more

Answer:Free Dr.Web utility restores files encrypted by Android.Locker.2.origin ransomware

Thank you Petrovic
 

2 more replies
Relevance 55.76%

Norton App Lock 1.2 for Android is now available.

The version number is 1.2.0.247 for Android.

Changelog

Minor defect fixes and stability improvements.
Source: Norton App Lock 1.2 for Android is now available!
 

More replies
Relevance 55.76%

On 11-19 ransomware screen popped up and locked the XP machine (sp3). Immediately tried to reboot and it would then without hesitation the lock screen again.
 
Next tried safemode boot and it just loops back to the selection menu and starts regular windows boot as default.
 
Then got updated version of Kaspersky Rescue 10 and boot it from CD drive, scanned and the result was:
 
Trojan.Win32.Sasfis.eixw      object:    sda2/windows/servicepackfiles/i386/rpct.dll
 
Kaspersky could not delete or quarantine due to permissions being read only by owner. this seems to be the case with everyfile now. Not encrypted,  just hijacked.
 
Could not do all of the prelim scans etc. as requested for new topic due to boot loop and lock.
 
Could the ransom and sasfis be one in the same or are there two issues.
 
have other machines so I just left it until now when I could come back and work on it.
 
Also there does not seem to be any encryption as the file extensions remain unchanged and I can preview the jpeg's while running the Kaspersky.
 
Any suggestions?
 
Thanks,
 
Trinitas
 
 
 

Answer:XP & Trojan.Win32.Safis.eixw & ransomware lock

Greetings Trinitas and to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.If you would allow me to call you by your first name I would prefer to do that.===================================================Ground Rules:First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problem... Read more

5 more replies
Relevance 55.76%

I recently upgraded to Windows 8.1, but it reset my custom lock screen image.  I tried re-applying it but the lock
screen preview in the settings is stuck on a load loop.  Does anyone know why that is and why it won't set my custom image as the new lock screen image?
i can't find the  C:\ProgramData\Microsoft\Windows\Systemdata, folder,
in my laptop
how to get default lock screen images in 8.1? plz help me..

Answer:Lock Screen Custom Image Stuck on Load for Windows 8.1, (Can't see the default lock screen images)

Please take a look at this link and it should solve your problem.
http://www.eightforums.com/tutorials/29621-start-screen-set-default-background-image-windows-8-1-a.html

12 more replies
Relevance 55.35%

Hi,

how to disable Caps lock, num lock, scroll lock screen messages?



I have desktop pc with two keyboards usb and bluetooth. Also TOSHIBA Bluetooth Stack software, but in device manager: keyboard > hid keyboard device both using microsoft drivers. And I dont have any software installed for keyboards. Also bluetooth has separate system tray indications (it is also disabled) so its not that. I made some googling and found other fix it with Hkey_Local_Machine\Software\Widcomm\BTConfig\General KeyIndication set to 0, but I dont have it in registry. Acualy I dont have anywhere in registry KeyIndication. So any ideas how to disable it? Thanks

Answer:Caps lock, num lock, scroll lock screen messages

Hi,

You'll find that the messages are controlled by a piece of software that came pre-installed on your machine when you bought it. Try looking for a Hotkey managing app to see if the notifications can be disabled.


OS

9 more replies
Relevance 53.71%

Malwarebytes Introduces Malwarebytes for Android, Featuring Proprietary Anti-Ransomware Technology
? Malwarebytes now provides superior mobile protection for Android users to protect against growing levels of mobile malware

? Android ransomware increased more than 100 percent between Q1 and Q2 2017

SANTA CLARA, Calif. ? August 24, 2017 ? Malwarebytes?, the leader in advanced malware prevention and remediation solutions, today announced the release of Malwarebytes for Android, featuring targeted defense against mobile malware, ransomware, adware, infected applications and unauthorized surveillance. Combining multiple distinct protection layers, Malwarebytes for Android is a more effective and efficient replacement for antivirus on mobile devices.

According to data collected by Malwarebytes, incidences of Android malware increased more than five percent since the start of the year. Most notably, incidents of Android ransomware increased 138 percent in Q2 2017 (April to May) over Q1 (January to March) 2017, with Jisut, SLocker and Koler ransomware collectively accounting for nearly 95 percent of these detections. While Android ransomware is growing at this rapid pace, Trojans and potentially unwanted programs remain the biggest issues for Android users. Android Trojans accounted for more than 48 percent of all Android malware detections in the first half of 2017 and potentially unwanted programs accounted for 47 percent of all detections.

Malwarebytes for Android... Read more

Answer:Malwarebytes Introduces Malwarebytes for Android,Anti-Ransomware Technology

yawn another one bites the dust

malwarebytes is surely losing revenue with windows thanks to their useless detection so they are now trying to explore avenues with android.
 

8 more replies
Relevance 51.66%

I have a new ideapad 100 laptop. I already have a Kensington lock and it doesn't work on the ideapad. I have no idea what to buy. Thank you for help.

More replies
Relevance 50.84%

When i try to wake my phone up, it shows "resuming" for two or three seconds and then displays the lock screen. Is anyone else facing this issue ? Is there any solution to this problem ?

More replies
Relevance 50.84%

id like to know if I can create a lock screen when my computer boots up to completely lock it from a very advanced user? Or any other ideas would be great. I'd like to know when im not home my computer is completely locked from my very spying boyfriend! I live alone, but sometimes he's here while im working. Im using windows 7 home premium. Thanks ahead of time for any ideas
 

Answer:would know if ican setup a lock screen wheny computer boots up to completly lock it .

Re: would know if ican setup a lock screen wheny computer boots up to completly lock

Don't log in :-D

Use a very difficult password. We have plenty of password generators on majorgeeks.
Enable the system admin account and password protect it.
Those two are probably enough. How advanced is he?
 

9 more replies
Relevance 50.43%

My friends dv7-1135nr is not posting. The num lock and caps lock led light will flash once every 2 seconds at the same time. According to HP this issue is a " not functional" cpu. I am ordering another cpu for 16.00 off ebay because this is cheaper opposed to ordering another board. Anyone else have this issue? And if so did you fix it ?
 

Answer:dv7-1135nr black screen caps lock/num lock flashing

6 more replies
Relevance 50.43%

Hi, new to these forums, hope I don't break any rules or anything here.

My laptop is a
Sony Vaio - Model: SVE141R11L
Product name: SVE14135CXB
Pre-loaded with Windows 8 x64
Intel(R) Core i5-3230M CPU @ 2.60GHz
6GB RAM w/ 900GB HDD space
Purchased in Navy Exchange last year (around July 2013)

I have dropped it once or twice from at most a 3ft fall inside a padded case. I mostly use my computer for school work, some gaming, extensive video/photo editing, internet browsing. I've installed some debatable programs but have been installed long ago. Most of my programs included Microsoft Office, Adobe suite, Steam, iTunes, uTorrent, McAfee VirusScan Enterprise, Winrar, VLC, etc. But are now gone due to the refresh I had just done last week for prior problems, but still experience problems.

I recently been having issues with my computer where it just won't respond at all. Like today, I had it working for a few hours, but then went out and left my laptop on the lock screen, and came back to it being completely stuck. Completely stuck as in, no keys or clicks would unlock the screen to the login prompt. However, my cursor was fully able to move around the screen, and my caps/num lock buttons work as they display the lights enabling/disabling them. The time when it was stuck was 8:03pm, but the clock was stuck on 7:55. But on the bottom of the front of the laptop, the HDD orange light is not lit up at all, which I believe suggest that the HDD is not reading/properly reading. Oddly e... Read more

Answer:Windows 8 Lock Screen Stuck, Cursor/num/cap lock work

Sounds like one too many drops killed the computer. You may get lucky and find a local mom & pop shop that will fix it cheaper then Sony.

3 more replies
Relevance 50.43%

Hello all,
 
To get straight to the point, I have an Asus G74SX-XR1. It's got an Nvidia GeForce 560M video card. I use this computer for my karaoke business. After one night everything was fine, but then I tried to turn on my computer the next day and I got to the "starting windows" screen but then at login I got black screened. Naturally I thought a driver problem, so I went into safe mode (screen works) and tried different drivers but none of them allowed me to see the normal windows startup. 
 
I thought, ok, I just want and need a working computer, So I decided to upgrade and go to an SSD. I installed it and decided to reformat. Well upon reformatting, I still get the same problem!!! No login screen. The backlight is on but as soon as the finish setup screen appears I lose any graphics on the screen. Please help! Urgent!
 
EDIT: External VGA monitor works fine. Only laptop display doesn't. It's not the display/screen because it shows the post and starting windows perfectly.

Answer:Black screen at login, works in safe mode, done research no solution found

If your laptop display is only working in Safe mode, that means you have a driver issue, or you have it set to only use an external monitor.  You can go into the bios and set it to use only the laptop LCD.  Unhook the second monitor from the unit.  Also when you get into Safe mode, uninstall both the monitor & GPU drivers, along with any associated software for the Graphics chipset and monitor.
 
When windows boots back up, it will find and load the default Microsoft or manufacturer drivers for your machine.  Now of course, you can boot back into Safe mode, and install the drivers downloaded from the manufacturer website for your machine.  NVidia has been having issues with their drivers, both for Windows & Linux, so do not download from their site, the generic drivers for your GPU.

4 more replies
Relevance 50.43%

Well, I have no idea what caused this but the tablet buttons (even the on/off button) the lights for caps lock and scroll lock as well as the automatic screen orientation change when I flip it to be a tablet have stopped working.Also the screen does not turn off anymore when the lid is closed. Reinstalled pretty much all of the drivers, no effect.Any ideas? Is this thing already broken?

Answer:X41 tablet buttons + scroll lock and caps lock lights + screen orientation change stopped working!

well, SOMETHING is broken.. though it would seen unlikely it is hardware.. a question: did you load anything new just before this happened..?anything at all..scanner drivers or printer drivers or a new application..? OH!, welcome to the lenovo community..! 





Bill Morrow, kept by parrotsSysop - forum.thinkpads.comX300, T60p, X60s,X60T (sxga+), Transnote, MacBook Pro, iPhone, iPod----She was not what you would call refined.She was not what you would call unrefined.She was the type of person who kept a parrot.Mark Twain

4 more replies
Relevance 50.43%

I've tried searching through the forum but can't see anyone who has a similar issue.

I can access the lock screen settings and I can see all available apps and have set a detailed status app and a couple of less detailed ones. However, when I actually get to the lock screen after having set the apps to appear, there is nothing but the time and date and WiFi in bottom-right corner.

Could this be because I am logging in locally rather than using a MS account?

Answer:Lock screen apps not showing up on lock screen

I'm having exactly the same issue, and I log in using a Microsoft account.

- CMW

18 more replies
Relevance 50.43%

Can anyone tell me how to eliminate the lock screen preview and bypass the 'Sign In' button on the lock screen?

I often put my computer to sleep then to bring it back (in Windows 7) I would simply hit the space bar and turn on my mouse and it would go straight to my desktop. Now, I hit the space bar turn on my mouse, and it takes me to the lock screen preview then I hit the space bar and it takes me to a lock screen where I have to click 'Sign In' even though I have no password set.

I'm guessing I'll no longer be able to hit the spacebar, turn on my mouse and go directly to the desktop but if I can hit the spacebar, turn on the mouse, then hit the space bar one last time, that would be satisfactory.

Answer:Lock Screen Preview and Lock Screen nuisance

Turns out, the instructions I found to not require a password at the sign in screen did the trick for me.

1 more replies
Relevance 50.02%

Lenovo Y720 So, when I hit caps ock or num lock an on screen display tells me whether capslock or num ock has been pushed. While I appreciate it is helpful for some, in my case it become a hinderance. You need to remove "num lock" for single key print screen request, and if I have a short time frame, I am stuck without being able to screenshot until the num lock indicator goes away.  How do I turn off the on screen display.  Now, before you send me to the previously asked questions of similar nature, I have tried. There is no "display settings" in Control Panel. There is no "advanced display settings" on the settings panel. And there is no way to control it through NVIDIA or Intel graphics settings (that I can see).  Thanks kindly. 

More replies
Relevance 50.02%

T470 20HE model Windows 10 64-bitFn key actions are displayed with on-screen icons/symbols (Volume/Mute, Mic, Display brightness), however when I select Caps lock or Num lock, there is no on-screen display.I re-installed the latest Lenovo Power Management Driver and Hotkey Features Integration for Windows 10 but no success.When I open the Display Settings >> Display adapter properties >> Screen configurations, the section "Indicator settings for Numlock and Capslock" is missing.Here are the Lenovo instructions: https://support.lenovo.com/us/en/solutions/HT002122 See attached file for comparison of the Screen configurations settings and my actual settings. Interestingly, in the Lenovo Hotkey Features Integration for Windows 10 (64-bit) - Laptop 9.0.07 (current version) Readme.txt, (https://download.lenovo.com/pccbbs/mobiles/n1wvu28e.txt ) there is a reference to a fix in the 9.0.0.6 as follows:<9.0.0.6>
- (FIX) Fixed CapsLock and NumLock OSD issue that the screen configuration
setting function in display adaptor properties control panel may not
work. Please advise if there is another fix to show the Capslock and Numlock on the display. 


























OSD comparison.pdf ?138 KB

More replies
Relevance 50.02%

Hi. I recently bought a new R5-417T laptop, and in the process of personalisation found no intuitive way to disable the caps-lock or num-lock notifications. (Windows 10 btw)  ^Notification in question^ How would I go about disabling this? I've tried looking in the BIOS, in regedit and some mythical "Launch Manager" program bundled with older acer laptops that I can't find a working version for.

Answer:How to DISABLE Caps-lock and Num-lock screen notif...

Caps lock is thr Caps lock key.For Num lock try Fn and F11.

7 more replies
Relevance 50.02%

Hi. I recently bought a new R5-417T laptop, and in the process of personalisation found no intuitive way to disable the caps-lock or num-lock notifications. (Windows 10 btw)  ^Notification in question^ How would I go about disabling this? I've tried looking in the BIOS, in regedit and some mythical "Launch Manager" program bundled with older acer laptops that I can't find a working version for.

Answer:How to DISABLE Caps-lock and Num-lock screen notif...

Caps lock is thr Caps lock key.For Num lock try Fn and F11.

6 more replies
Relevance 50.02%

ANyone have aclue how to get these working again  i did a clean install of windows and for the life of me can't get these to work I've installed all drivers from the drivers page with no luck

More replies
Relevance 50.02%

I have a Acer Aspire 7750G-9411 laptop. I recently had to reload my operating system. since then the "on-screen " icon for the cap's lock and number's lock does not show up. I made sure to download and install all of the drivers but have been able to restore this one frature. Thanks for any help you can give me. Cliff

Answer:on-screen icon for Caps lock / number's lock is mi...

If you are using Windows 8, then it is important to note that the on-screen indicators for Num Lock and Caps Lock are not available in Windows 8. To know more about this, you can refer to the link below:http://acer.custhelp.com/app/answers/detail/a_id/30035/~/no-num-lock-and-caps-lock-indicator If you are using Windows 7, you can check if following the steps below helps:1. Click on "Start".2. Type keyboard in the "Search" field.3. Double-click "Keyboard options".4. Go to "Key settings" tab and then, go to "Key settings" list.5. Locate and double-click "Caps Lock" and select the option "Display Caps Lock status on screen". Click "Finish".6. Follow Step 5 for Nums Lock as well. Hope this will resolve your issue.

1 more replies
Relevance 50.02%

Good afternoon,

I just did a clean install of 7 to fix errors with my laptop, and it fixed one, but not the other main issues,
My caps lock, and number lock button on the keyboard don't have a light on it and the pop up that is supposed to pop up doesn't show up on screen.
I figured by doing a clean install it would all magically appear again... I was wrong, I have tweaked everything I could think of looking/trying to change setting from the keyboard in control panel, (including messing around with ease of use) and Gateways so called "support" area was of no help, as well as googling the issue has led me down a path of useless tips, I have also looked on this forum for help.

Any help in this area would be GREATLY appreciated!!

Answer:Caps Lock/Num Lock, on screen pop up gone Gateway NV77

Ok, I have a problem I have set up the sound, and it does not play a sound.

1 more replies
Relevance 50.02%

My hp touchsmart tx2 when I power on the display stays black but num lock and caps lock lights flash ?

More replies
Relevance 49.61%

Trying to run chkdsk /f and this is the message I receive.

Answer:Type of file is NTFS Cannot lock current driv

NTFS is not a file type, it's a file system.http://en.wikipedia.org/wiki/NTFS

4 more replies
Relevance 49.2%

Ok I've been suffering this issue with Windows 10 for as long as I can remember, and it's stopping me using it as the primary OS.

In short I have two, intermittent issues which nothing I do seems to resolve.

1: After waking up from sleep and typing my username password and hitting return, the screen goes black. Cursor moves, Windows + P operates (Screen options do appear from the right) but doesn't actually make any difference, and I'm stuck having to hard reset because ctrl alt del doesn't work either. This isn't an every time issue, hence googling seems to fail miserably because all the examples are people getting it every time. This, for me, is a 3 in 10 regularity.

2: Logging a user off occasionally sees the lock screen ... locking up. Ironically. Mouse moves, and power button DOES work but that's all that works.

These issues are plaguing me and I just cannot fix them - endless googling has left me empty handed, and I've tried disabling SLI. No help. I've tried disabling apps. No help. Nothing I do makes any difference and event viewer doesn't seem to reveal anything useful either.

Anyone got any idea how I can resolve this?

System is:

132GB SSD OCZ
2TB Seagate HDD
4790K
2x980Ti SLI
32 GB RAM @ 1800 Corsair
Asus Z97-A
Windows 10 & Windows 7 dual boot 64.

Answer:Being absolutely tortured by lock screen lock ups...please help!

Disable Internal PLL Overvoltage. It should be 'Auto' by default. Choose 'Disable' from the dropdown and disable it.

Attachment 89957

See how it goes. Let us know.

17 more replies
Relevance 49.2%

Ok I've been suffering this issue with Windows 10 for as long as I can remember, and it's stopping me using it as the primary OS.

In short I have two, intermittent issues which nothing I do seems to resolve.

1: After waking up from sleep and typing my username password and hitting return, the screen goes black. Cursor moves, Windows + P operates (Screen options do appear from the right) but doesn't actually make any difference, and I'm stuck having to hard reset because ctrl alt del doesn't work either. This isn't an every time issue, hence googling seems to fail miserably because all the examples are people getting it every time. This, for me, is a 3 in 10 regularity.

2: Logging a user off occasionally sees the lock screen ... locking up. Ironically. Mouse moves, and power button DOES work but that's all that works.

These issues are plaguing me and I just cannot fix them - endless googling has left me empty handed, and I've tried disabling SLI. No help. I've tried disabling apps. No help. Nothing I do makes any difference and event viewer doesn't seem to reveal anything useful either.

Anyone got any idea how I can resolve this?

System is:

132GB SSD OCZ
2TB Seagate HDD
4790K
2x980Ti SLI
32 GB RAM @ 1800 Corsair
Asus Z97-A
Windows 10 & Windows 7 dual boot 64.

More replies
Relevance 49.2%

Hi All.

I have a new one installed Lenovo T450s with Windows 10 Entreprise.
I have joined the machine into a domain without some active GPO.
When I'm at home or sitting at a customer and must unlock the screen, it takes a war! It is as if searching for the DNS server for my AD domain as my PC is a member of.
In Windows 7 or Windows 8 there is no problem.
This is not a problem in Windows 7 or Windows 8.
Some have suggestions?

Thank you

More replies
Relevance 49.2%

I ran two 20a plugs to my rack and used wire rated for 30a. I was thinking, I should swap those out for twist lock and just buy more wire and run two more 20a circuits. What type of plug is typical for server stuff, and is it 120v or 240v? I want to run whatever I am more likely to need in the future for say, a big UPS, rectifier, etc so that it's there and ready to go.

I'm guessing L6-30? Also do these plugs typically fit in a standard wiring box? Never installed one before.
 

Answer:What is a typical twist lock plug type for server stuff?

Mostly I've seen L5-20, 208V
 

7 more replies
Relevance 49.2%

Hi everyone,  I have bought a Lenovo T570 and a VGA to USB Type-C converter to had an external display on it. The problem is when I lock the computer I need to manually unplug and plug the converter to turn on the external display. Have you an isue like this and do you know how to avoid this ? Thank.

More replies
Relevance 48.38%

Hi,

(First of all: I ain't good at English because I come from Holland.)

I own a Satellite A100 PSAA8, it used to be working very well :)
But since a few weeks I have a strange keyboard problem.
I can only type capital letters when caps-lock is off, and I can't type any numbers at all, and a full stop is a: > and a comma is: <
I thought it was a software problem so I formatted the hard disk, then I tried the Toshiba recovery disk.

But it did not work I get a couple of errors with symbol files missing (or something like that) then in the window appears: 0:000 and whatever I am typing it doesn't work. So I grabbed the Windows XP Pro. CD, but when I get to the chapter when I must fill in my serial number, I still can't type any numbers and only capital letters with caps-lock off.

Then I (tried) to install Windows 2000 and still I can't type any numbers, etc.(but the hard disk is empty :S) then I insert a Ubuntu live CD and the keys under ubuntu are working perfect(?). I just doesn't get it. PLEASE HELP!!

Answer:Satellite A100 PSAA8: I can type capital letters when caps-lock is off

Hello Ikke

Believe me it is not easy to say for sure what the problem can be?
Please check if the keyboard is recognized properly in device manager. Be also sure the language settings are the right. So much about possible software reasons for not working keyboard.

It is also possible that there is hardware problem. Maybe is keyboard cable defective or the keyboard controller. It is also possible that keyboard itself is faulty.

In my opinion you should contact authorized service in your country. They can test it with brand new keyboard and see if the keyboard is defective.

2 more replies
Relevance 48.38%

Hi,
I found a Google play download for android on softsonic but get error "file type exe not found" when selected from ad card? This is a nextbook PREMIUM 8SE multi touch capacitive screen, 800x600 pixels, 4.3 display 1080p, AML8726-M3 Cortex A9 1 GHz, DDR3 512 MB, Android OS 4.0 ice cream sandwich, OTA compatible, easy connect WIFI 802.11 b/g/n
That is all the specs I see. Any fixes? Thanks

Answer:file type exe not found"google play apk"android download error

Your post is confusing. Reads like your device is running an Android OS -- ICS. But, ".exe" files are MS Windows files, not Android. They're generally executables but can also be self-extracting archives Either way, they will do you no good on a machine running Android.

4 more replies
Relevance 47.97%





ESET Internet Security 2017 - BETA Edition​
 

Answer:ESET Internet Security 10 and ESET NOD32 Antivirus 10 - 2017 Edition BETA

Worth testing in a VM , the new features look tempting Thanks for sharing this.
 

8 more replies
Relevance 47.97%

Hi all, i am working in the ESET as a Global Digital PR. I don't want to spam this forum with advertising messages. Everything i want is to inform the community, which can help us with our beta tests that you can join.

We have recently opened public beta program for our security solution ESET Smart Security 6 and ESET NOD32 Antivirus 6 with some new interesting features like for example anti-theft.

You can participate by following this link: http://www.eset.com/beta/v6/

We also pick every week one 100 beta testers, who will win one year license and we prepared one little surprise

Please, if you have any questions, just ask, i am here for that

Answer:ESET Smart Security 6 and ESET NOD32 Antivirus 6 opened for public BETA

Please note that this program is a pre-release beta version of a product and not completely tested to ensure its stability or reliability.What is beta software?After an initial round of in-house testing, software publishers often release new programs to be tested by the public. These pre-release versions are called beta software, usually denoted by a "b" in the version number, e.g., Netscape Navigator 2.0b5. Since the publisher couldn't possibly test the software under all possible conditions, it is reasonable to expect that wider use of the software may uncover problems that were not discovered during in-house testing. The publisher expects to be notified when users find such problems so that the program can be fixed before its official release.In general, you should expect to run into bugs whenever using any piece of beta software. These bugs may range in severity from minor features that don't work to problems that cause your computer to crash. You should decide whether the benefit of new features in a beta program outweighs the risk of program instability before choosing to use a piece of beta software. You should also be aware that UITS will not have thoroughly tested beta software, nor will the software be guaranteed by its maker, so you should not expect the same level of support as you would receive for an official release version of the program.The goal of a beta program is to collect information regarding the performance, quality, stability, and fu... Read more

1 more replies
Relevance 47.97%

ESET published a Technical Alert for customers running Microsoft Windows Vista and ESET Smart Security who plan to upgrade to Windows 7. Windows 7 upgrades with ESET Smart Security

Microsoft has notified software developers that some of the technologies used by security, backup, disk utility and network management programs are incompatible with the Windows Vista to Windows 7 upgrade process. This is a direct result of Microsoft?s design decisions and impacts most antivirus solutions that scan network data.
ESET has verified that the Personal firewall module in both versions 3 and 4 of ESET Smart Security is affected. The problem only affects computers being upgraded to Windows 7 from Windows Vista SP1 and SP2. Customers working with new installations of Windows 7 will not experience these problems, nor will customers upgrading from Windows XP (which performs a clean install).
ESET NOD32 Antivirus is not affected.
ESET is working closely with Microsoft as we approach the official launch of Windows 7 to address any potential compatibility issues and promptly communicate issues like this to our valued partners. Further information is available at ESET Knowledgebase - How do I safely upgrade from Windows Vista to Windows 7 with ESET Smart Security installed?.

Note: This issue only affects computers being upgraded to Windows 7 from earlier versions of Windows. Unaffected are first-time or clean installations of Windows 7. In addition, ESET NOD32 ... Read more

Answer:ESET Technical Alert for Windows 7 Upgrades w/ESET Smart Security

Well...I have done clean installation of W7 RTM and I didn't see any docs or manuals. ESET NOD32 supports W7 RTM.
btw it works with W7

1 more replies
Relevance 47.97%

ESET Internet Security? 10 and ESET? NOD32? Antivirus 10 - 2017 Edition Beta










Known Issues

? Upgrade from previous versions is not supported - clean installation is required
? Reset settings to default doesn?t work



? Webcam protection is not yet fully implemented
? Webcam protection is not able to detect all applications requesting access to the camera, for example Vidyo
? Home Network protection feature is not fully functional yet
? Email Client integration settings are missing in Advanced setup of ESET NOD32 Antivirus
? ESET service is not marked as protected after OS upgrade (from Windows 7/8 to Windows 10)



Source and Beta download: http://www.eset.com/int/beta/edition2017/

More replies
Relevance 47.97%

Mod Edit:  Merged posts, moved from Gen Security to AV/AM Software - Hamluis. Hi, I am interested to purchase one of these: ESET NOD32 AntivirusorESET® Multi-Device Security Pack Please answer to the next 5 questions: 1. Tell me please, after receiving the CD-KEY from ESET can I activate and start the 365 days license after 3 weeks or 1 month of receiving? I've done my best(in my available time for it) to find the answer in here: Software End User License Agreement | ESET but I couldn't resolve it. 2. For the ESET® Multi-Device Security Pack, after activating for example one of the 3 license, which is the maximum time to activate the other 2, for their 365 days availability please? 3. Is it possible to start the license after 3 weeks or 1 month after receiving it for ESET NOD32 Antivirus or ESET® Multi-Device Security Pack if I buy them from any worldwide official ESET shop from ESET :: Select your country please? 4. Tell me please, if I will decide to buy ESET® Multi-Device Security Pack after installing one of the licenses on a Windows device, can I cancel it and install it on a Linux or Android device, or vice versa? 5. Are there any official ESET phone numbers/live chat/e-mail support(answer within a few hours) anywhere in the world speaking English, which are open on Saturday and Sunday too, or 24/7 and can answer to the above 4 questions, or any other technical queri... Read more

Answer:Buy ESET NOD32 Antivirus OR ESET Multi-Device Security Pack

xspeed,
 
Just a thought. You indicate there are no support reps presently available. Could this be why ....
 
ESET North America Support Hours
 
Last Revised: December 30, 2015
 
ESET North America will operate on a holiday schedule Thursday, December 31, 2015. Please note our revised hours of operation for this particular date: 5:00 a.m. to 4:00 p.m. PST.In addition, ESET North America will be closed in observance of the New Year holiday Friday, January 1, 2016. Normal business hours will resume on Monday, January 4, 2016, from 5:00 a.m. to 7:00 p.m. PST.
 
http://support.eset.com/alert5767/
 
Best of luck ..
Carol

8 more replies
Relevance 47.97%

Hi,

I am interested to purchase one of these:

ESET NOD32 Antivirus
or
ESET Multi-Device Security Pack

Please answer to the next 5 questions:

1. Tell me please, after receiving the CD-KEY from ESET can I activate and start the 365 days license after 3 weeks or 1 month of receiving?

2. For the ESET Multi-Device Security Pack, after activating for example one of the 3 license, which is the maximum time to activate the other 2, for their 365 days availability please?

3. Is it possible to start the license after 3 weeks or 1 month after receiving it for ESET NOD32 Antivirus or ESET Multi-Device Security Pack if I but them from any official ESET shop from ESET :: Select your country please?

4. Tell me please, if I will decide to buy ESET Multi-Device Security Pack after installing one of the licenses on a Windows device, can I cancel it and install it on a Linux or Android device, or vice versa?

5. Are there any official ESET phone numbers/live chat/e-mail support(answer within a few hours) anywhere in the world speaking English, which are open on Saturday and Sunday too, or 24/7 and can answer to the above 4 questions, or any other technical queries please?

Thank you very much.
Warm regards and a happy new year !
 

Answer:Buy ESET NOD32 Antivirus OR ESET Multi-Device Security Pack ?

1) Not sure on this, but I believe you can activate it few mths later. Best is refer to their terms and conditions before making purchase. Sometimes they mention when is the due date for activation.

2) Upon purchase, you only have a single key that activate 3 device. There is no separate license key for each device. Activation would mean the same start date applied to all 3 devices.

3) Same as Q1.

4) As long as you do not exceed more than 3 devices using the same license key (in this case is ESET pack 3 User), there is no need to uninstall.

5) ESET Customer Care

Hope that helps.
Cheers!
 

1 more replies
Relevance 47.97%

So I won ESET in a giveaway, really excited, and trying to decide what computer to install on. On my main laptop, I am using CIS (proactive config, firewall-custom, small tweaks) and really like it. I am trying to decide whether to try ESET on main PC or on my brother's gaming PC (more advanced user than I am, so probably would be fine with ESET, but also more interested in games than AV toys )

If anyone is familiar with both- what are the key differences between ESET and Comodo? For example, It seems that ESET has built in exploit protection...but not sure on other key differences. Anything I would be giving up with Comodo (virtual kiosk, auto-sandbox, etc.)? Also, any experience with ESET and gaming?

Thanks everyone!
 

Answer:Differences ESET vs. Comodo Internet Security & how to get ESET license activated?

When you look closely at Comodo and ESET they have only slight differences... of which you are already aware.

ESET's real advantage is better surf protections and signatures whereas Comodo has the integrated auto-sandboxing feature.

Both have an anti-bot exploit feature... not really a complete anti-exploit capability like MBAE or HMPA.

Both have a gaming mode which suppresses alerts and notifications.

Performance-wise I see little difference between Comodo and ESET; both have acceptable system impact.

It is highly likely that if you enjoy using Comodo you will also enjoy ESET.
 

10 more replies
Relevance 47.97%

ESET Internet Security? 10 and ESET? NOD32? Antivirus 10 - 2017 Edition Beta










Known Issues

? Upgrade from previous versions is not supported - clean installation is required
? Reset settings to default doesn?t work



? Webcam protection is not yet fully implemented
? Webcam protection is not able to detect all applications requesting access to the camera, for example Vidyo
? Home Network protection feature is not fully functional yet
? Email Client integration settings are missing in Advanced setup of ESET NOD32 Antivirus
? ESET service is not marked as protected after OS upgrade (from Windows 7/8 to Windows 10)



Source and Beta download: http://www.eset.com/int/beta/edition2017/

More replies
Relevance 47.97%

This computer had problems with infections and virus issues in the past. It was given to me. Just installed ESET Smart Security 8.0 today. Problems with Group Policy controlling windows firewall so I disabled it and use Eset personal firewall. I cannot access my Eset scan logs or Eset at all now. When I try to I get a pop-up message "Error communicating with kernel"  I don't know how to fix this, other than to ask you guys for some help. I wanted to post the scan results for you. I tried to repair/reinstall Eset and it tells me that it is already installed but I cannot open it up. I know that it found 3 Trojans, I also ran R-kill before downloading Eset and I saved the results of the scan. I seem to have another problen with Hosts, here is a copy of the scan.
 
 
 
 
 
Rkill 2.7.0 by Lawrence Abrams (Grinler)http://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 05/16/2015 10:18:34 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3
Checking for Windows services to stop:
 * No malware services found to stop.
Checking for processes to terminate:
 * No malware processes found to kill.
Checking Registry for malware related settings:
 * No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous c... Read more

Answer:Trojan, infected 3, ESET found these.Now cannot open ESET to re- scan

Hello and welcome to Bleeping Computer! I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.
We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.
To help Bleeping Computer better assist you please perform the following steps:
*************************************************** In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/576663 <<< CLICK THIS LINK
If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.
***************************************************If you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of t... Read more

14 more replies
Relevance 47.97%

Key features available in version 8: ESS
Botnet protection: Brand new technology that protects against infiltration by botnet malware to prevent spam and network attacks detected in outbound traffic from your computer. Botnet protection searches outgoing network communications for known malicious patterns, and matches the remote site against a blacklist of malicious ones. Any detected malicious communication is blocked and reported to the user. Click to view a screenshot.
Enhanced Exploit Blocker: Protects against attacks on web browsers, PDF readers, Office documents, as well as Java communications and Java-based software that provides the ability to eliminate lockscreens and ransomware.
ESET SysRescue Live: The next generation of the ESET SysRescue utility, ESET SysRescue Live allows you to create a bootable disk, in the form of a USB flash drive or CD/DVD, with the ability to scan and clean your system even when you cannot boot into Windows. ESET SysRescue Live is a Linux-based malware cleaning tool that runs independent of the operating system from the ESET Smart Security retail CD.
HIPS Smart mode: Only suspicious system events trigger a notification beyond the set of pre-defined rules in Automatic mode (operations such as system registry, active processes and programs).
ESET Cybersecurity Education (North America only): New Cybersecurity Education introduces a more interactive and game-like approach to training. This replaces the previously named ESET Cybersecurity Tr... Read more

Answer:ESET Smart Security and ESET NOD32 AV Version 8 Have Been Released

Source:
https://forum.eset.com/topic/3327-eset-smart-security-version-8-has-been-released/
https://forum.eset.com/topic/3328-eset-nod32-antivirus-version-8-has-been-released/
 

33 more replies
Relevance 47.56%

ESET Smart Security
ESET Smart Security keeps your computer or laptop safe with intelligent multi-layered protection combining proven antivirus, antispyware, firewall, anti-rootkit and antispam capabilities. Based on ESET NOD32 Antivirus, it protects you from viruses, worms, spyware, and all Internet threats. It conserves resources and improves computer speed. You are protected at the highest level while you work, social network, play online games or plug in removable media.

ESET NOD32 Antivirus
Your best defense against viruses, trojans and other forms of malware?and the top choice for IT professionals. Powered by the ThreatSense engine with advanced heuristics, which blocks far more unknown threats than the competition. The latest generation of the legendary ESET NOD32 Antivirus takes your security to a whole new level. Built for a low footprint, fast scanning, it packs security features and customization options for consistent and personalized security online or off.

Changes in ESET NOD32 Antivirus 9.0.375:
Fixed: Activation issues
Fixed: Vulnerability fixes (ESET Customer Advisory: Mitigations for vulnerabilities in ESET?s EXE installers?ESET Knowledgebase)
Other: SHA-2 signature updated
Changes in ESET Smart Security 9.0.375:
Fixed: Activation issues
Fixed: Stability fixes in Banking and Payment Protection module
Fixed: Vulnerability fixes (ESET Customer Advisory: Mitigations for vulnerabilities in ESET?s EXE installers?ESET Knowledgebase)
Other: SHA-2 ... Read more

More replies
Relevance 47.56%

NOD32 for Windows is the best choice for protection of your personal computer. Almost 20 years of technological development enabled ESET to create state-of-the-art antivirus system able to protect you from all sorts of Internet threats. ESET Smart Security boasts a large array of security features, usability enhancements and scanning technology improvements in defense of your your online life.

ESET Smart Security
ESET Smart Security keeps your computer or laptop safe with intelligent multi-layered protection combining proven antivirus, antispyware, firewall, anti-rootkit and antispam capabilities. Based on ESET NOD32 Antivirus, it protects you from viruses, worms, spyware, and all Internet threats. It conserves resources and improves computer speed. You are protected at the highest level while you work, social network, play online games or plug in removable media.

ESET NOD32 Antivirus
Your best defense against viruses, trojans and other forms of malware?and the top choice for IT professionals. Powered by the ThreatSense engine with advanced heuristics, which blocks far more unknown threats than the competition. The latest generation of the legendary ESET NOD32 Antivirus takes your security to a whole new level. Built for a low footprint, fast scanning, it packs security features and customization options for consistent and personalized security online or off.

Key features available ESET NOD32 Antivirus version 8:

Enhanced Exploit Blocker: Protects against attacks on w... Read more

Answer:ESET NOD32 Antivirus and ESET Smart Security 8.0.312.0

8.0.312.0

Updated: EULA, Country list, DetectAV engine
Fixed: Localization bugs
Fixed: Egui doesn't remember the size of window
Fixed: Scheduled tasks "on computer startup" don't work on Windows 8+
Fixed: First scan cannot be stopped from popup

 

5 more replies
Relevance 47.56%

New features - ESS:

Advanced memory scanner provides protection against obfuscated threats
Vulnerability shield protects your computer from network threats exploiting vulnerabilities in communication protocols
Exploit blocker protects browsers and other popular applications from threats exploiting vulnerabilities in these applications
Improved cleaning of rootkits ensures that even in case of infection with persistent malware, the system will be restored to a working malware-free state
Device control allows for controlling access to removable devices
Automatic first time scan cleans potential malware on the computer and improves performance of future scans

New features - ESET NOD32 AV:

Advanced memory scanner provides protection against obfuscated threats
Exploit blocker protects browsers and other popular applications from threats exploiting vulnerabilities in these applications
Improved cleaning of rootkits ensures that even in case of infection with persistent malware, the system will be restored to a working malware-free state
Device control allows for controlling access to removable devices
Automatic first time scan cleans potential malware on the computer and improves performance of future scans
Download:
ESS
-http://www.eset.com/us/download/home/detail/family/5/-

AV
-http://www.eset.com/us/download/home/detail/family/2/-
 

Answer:ESET Smart Security and ESET NOD32 AV 7.0 have been released

 

10 more replies
Relevance 47.56%

The 8.0.304 build is the same as .301 but has the latest modules already installed (e.g., the modules are listed in the "Installed components" window of the About ESET ... screen).Click to expand...

Source



http://www.eset.com/us/download/home/

ESET Smart Security 8 Live Installer
http://download.eset.com/special/live-installer/us/eset_smart_security_live_installer.exe
ESET NOD32 Antivirus 8 Live Installer
http://download.eset.com/special/live-installer/us/eset_nod32_antivirus_live_installer.exe
 

Answer:ESET Smart Security and ESET NOD32 AV Version 8.0.304

I'm running 8.0.304.1 since 2 weeks lol.
 

4 more replies
Relevance 47.56%

Hi! So, I've upgraded to Windows 8 RTM this weekend and I'm having this problem: Every time I boot the PC (shutdown or restart), the Num Lock key is off. Since my password uses numbers, and I'm pretty used to type it with Num Lock, I'd like to keep it always on. It was fine on Windows 7. Now, I've searched for it, and there is the "InitialKeyboardIndicators" key on regedit. I have changed values for all of them to "2", and it didn't work. My BIOS say to keep it always on. Is there anything else that I'm missing?

Answer:Num Lock always activated on lock screen

Netplwiz, or tap num lock before starting password entry.

Besides those, you can check to make sure keyboard is plugged in directly to motherboard instead of add-on card or something.

5 more replies
Relevance 46.74%

I am trying to restore my Mother's computer to a clean/working state. Any help is greatly appreciated. Thanks.
 

Answer:FBI Ransomware/White Screen

Hi and welcome to MalwareTips!

I'm Fiery and I would gladly assist you in removing the malware on your computer.

PLEASE NOTE: The first 3 posts of ALL new members require approval by mods/admins. Please be patient if you don't see your post immediately after submitting it.

Before we start:

Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
Malware removal can be dangerous. I cannot guarantee the safety of your system as malware can be unpredictable. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. Therefore, I would advise you to backup all your important files before we start.
Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
Some tools may be flagged by your antivirus as harmful. Rest assure that ALL the tools we use are safe, the detections are false positives.
The absence of symptoms does not mean your PC is fully disinfected.
If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.

<hr>
Download Farbar Recovery Scan Tool from the below link:
<ul><li>For 64 bit systems download <a title="External link" href="http://do... Read more

15 more replies
Relevance 46.74%

When I log into windows I get a white screen I can't click out of, I can't use safe boot
I've tried kaspersky rescue disc windows unlocked and that didn't work
If anyone could please help it would be greatly appreciate
 
I ran OST and FRST both from reatogo-x-pe

Answer:White screen/ ransomware on xp

Greetings petergriffen and to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.If you would allow me to call you by your first name I would prefer to do that.===================================================Ground Rules:First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter pr... Read more

33 more replies
Relevance 46.74%

Last night, while web browsing, all of a sudden I get a full screen ransomware type, with message on screen AND audio telling me I have to click on something and/or call them OR they will be forced to lock all the files on my computer 'to prevent the spread of the malicious files'. Before it even completed playing the audio, I just pulled the plug on the computer, removed the drive, and wiped it with another machine.

But in retrospect, what should I have done? The boot drive was only a 60GB SSD, I could have saved it if necessary so someone who knows more than I do could figure out what happened. Now, there's no way to figure out whether there was something installed a while ago, or it was a website I just visited? The only things that I had open at that point were tabs from youtube and the most recent thing that I had opened was a link off of a yahoo news page pretty much right before the ransomware screen popped up. . Assuming it was from that link, do I need to let yahoo know what I clicked on? I run malwarebytes every week, but this happened on a Friday so it's been five days since that scan. Also had Avast free version running, too.

No apparent infection anywhere, but just want to know how to proceed.
 

Answer:Ransomware screen with audio; what should I have done?

Kill the power and pull the drive and scan it from a known good machine in a drive caddy.

If you knew you had a good backup then wiping it would be OK too.
 

2 more replies
Relevance 46.74%

Working on a neighbors computer. They cannot do anything as soon as the computer is booted up in regular or safe mode a white screen pops up asking them to connect to the internet. If you connect the machine to the internet you are provided with a message that your computer is locked and you can play to unlock it. I have ran the FRST.exe application and have posted the log below but I'm not sure which items need fixing. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-07-2013Ran by SYSTEM on 14-07-2013 20:43:15Running from E:\Microsoft Windows XP (X86) OS Language: English(US)Internet Explorer Version 8Boot Mode: RecoveryThe current controlset is ControlSet001ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log.==================== Registry (Whitelisted) ==================HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [155648 2004-09-13] (Alps Electric Co., Ltd.)HKLM\...\Run: [EPSON Stylus CX3800 Series] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 "EPSON Stylus CX3800 Series" /O6 "USB001" /M "Stylus CX3800" [98304 2005-02-07] (SEIKO EPSON CORPORATION)HKLM\...\Run: [EPSON Stylus CX3800 Series (Copy 1)] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P35 "EPSON Stylus CX3800 Series (Copy 1)" /O6 "USB002" /M "Stylus CX3800" [98304 2005-02-07] (SEIKO EPSON CORPORATION)HKLM\...\Run: [Google Desktop Search] - "C:\Program Files\Google\Google Desktop ... Read more

Answer:White Screen Ransomware

Hello delixer I would like to welcome you to the Malware Removal section of the forum.Around here they call me Gringo and I will be glad to help you with your malware problems.Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!Please do not run any tools unless instructed to do so.We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same",... Read more

9 more replies
Relevance 46.74%

Does the Anti Thief System, Firewall and Anti-Spam make Smart Security a better way to go than the base NOD32? Alternatively, are there free Firewall and Anti-Spam programs one can add to their computer if purchasing NOD32? I don't have a laptop so would the Anti Thief component of the Smart Security really be of much use?
 

Answer:ESET NOD32 or ESET Smart Security?

I use ESET NOD32 along with Comodo Firewall, and rely on Gmail's spam filter. Works great so far.
 

3 more replies
Relevance 46.74%

So I won Eset in a giveaway, really excited, and trying to decide what computer to install on. On my main laptop, I am using CIS (proactive config, firewall-custom, small tweaks) and really like it. I am trying to decide whether to try Eset on main PC or on my brother's gaming PC (more advanced user than I am, so probably would be fine with Eset, but also more interested in games than AV toys )

If anyone is familiar with both- what are the key differences between Eset and Comodo? For example, It seems that Eset has built in exploit protection...but not sure on other key differences. Anything I would be giving up with Comodo (virtual kiosk, auto-sandbox, etc.)? Also, any experience with Eset and gaming?

Thanks everyone!
 

Answer:Differences Eset vs. CIS & how to get Eset license activated?

When you look closely at Comodo and ESET they have only slight differences... of which you are already aware.

ESET's real advantage is better surf protections and signatures whereas Comodo has the integrated auto-sandboxing feature.

Both have an anti-bot exploit feature... not really a complete anti-exploit capability like MBAE or HMPA.

Both have a gaming mode which suppresses alerts and notifications.

Performance-wise I see little difference between Comodo and ESET; both have acceptable system impact.

It is highly likely that if you enjoy using Comodo you will also enjoy ESET.
 

10 more replies
Relevance 46.33%

Recently, I stumbled on article from Bitdefender blog that claim they have released "a new vaccine tool which can protect against known and possible future versions of the CTB-Locker, Locky and TeslaCrypt crypto ransomware families"

Their previous vaccine/version seem to protected /appdata and several folder that have higher possibility infected by ransomware.

Has anyone tried this latest version of BD anti ransomware?

here is the link

It is also covered in softpedia news:




Vaccine for CTB-Locker, Locky and TeslaCrypt Ransomware Released
It's better to prevent than to pay the ransom
Mar 28, 2016 17:35 GMT By Catalin Cimpanu
Romanian security vendor Bitdefender has updated its vaunted anti-ransomware vaccine to add support for the latest versions of the CTB-Locker, Locky and TeslaCrypt ransomware families currently ravaging users all over the globe.

The Bitdefender Anti-Ransomware toolkit has been around for some years now, ever since crypto-ransomware started to become popular and users understood that once locked, recovering the files was almost impossible without paying the crook's ransom fee.

Luck also plays a role if the ransomware contains encryption flaws that allow security researchers such as Fabian Wosar to create decryptors for various variants. But these situations are very rare, and often found in smaller, newly appeared ransomware families, not older trialed and tested variants.

An anti-Locky vaccine is needed these days
... Read more

More replies
Relevance 46.33%

Ransom note;WhatHappenedWithMyFiles.rtf










 

Answer:New Ransomware: Matrix Ransomware - Ransom note;WhatHappenedWithMyFiles.rtf

A variant of the Matrix RW has been tested in MalwareHub in the past 15 days already. That's another RW that has upped the timed game.

Hey, remember this one?



 

1 more replies
Relevance 46.33%

I've been using Windows 10 for just over one year. For some reason the Lock Screen/Sign-in screen shows three users. All three are me in three iterations. I find also that when trying to save some excel and word documents I receive messages saying that i am not allowed to save to this folder or that folder. I am able to save to the desk top and then drag and drop the document into the folder that I need to place it in. I know that this must have something to do with "permissions". Not sure how to fix that. One of the accounts that shows up is the initial account that I created back when hotmail.com was around. Any ideas/advice on these issues? When i updated to Windows 10, pretty certain that i followed all of the instructions, although that has been over 1 year now. Thank you in advance...cheers and beers to all!

More replies
Relevance 46.33%

I've been using Windows 10 for just over one year. For some reason the Lock Screen/Sign-in screen shows three users. All three are me in three iterations. I find also that when trying to save some excel and word documents I receive messages saying that i am not allowed to save to this folder or that folder. I am able to save to the desk top and then drag and drop the document into the folder that I need to place it in. I know that this must have something to do with "permissions". Not sure how to fix that. One of the accounts that shows up is the initial account that I created back when hotmail.com was around. Any ideas/advice on these issues? When i updated to Windows 10, pretty certain that i followed all of the instructions, although that has been over 1 year now. Thank you in advance...cheers and beers to all!

More replies
Relevance 45.92%

Hi everyone. Not been on the forum for a while but need some help and figured this would be the best place to get it. Yesterday I experienced Ransom ware. I already had some removal instructions printed so followed those but I now have a black screen upon start-up.

What forum should I post onto please?

Answer:ransomware and black screen upon start-up

Here is fine

Please read this tutorial fully, and follow all steps.

99% of the time all issues can be resolved with problems starting windows with this tutorial.

Troubleshooting Windows 7 Failure to Boot

9 more replies
Relevance 45.92%

I did have the command prompt and the registry opened up but what do I do next? How do I run the dm_log if I can't see my desktop? Please help?

Answer:Black Screen after Ransomware Ad was shown

Hi sriddle,

Welcome to the 8forums.


   Note
Everything between quotes are commands, please type the commands WITHOUT quotes.
Everything between {} are variables, please type the word that is correct for you without the {}
In command prompt use the "cd C:\users\{username}\desktop" command to go to the folder of the desktop.
Type "dir" to get a list of everything in the desktop.
When you find the file you want to run type the command "dir {filename}.exe" and press enter to run it.
When the tool is finished, type the command "copy {filename} {location where you want to copy it to}"

16 more replies
Relevance 45.92%

Windows 7 Pro x64, Dell M4600 Laptop, GFI Vipre Anti-Virus, Windows Firewall
 
User called saying their computer screen had a message saying the PC was locked and would only be unlocked by paying for a unlock code. They knew this was not ligit, and asked for help.
 
I told them to shut down the machine and take if off the network.
 
When I got the machine, if I booted without a connection to a router ie. patch cord unplugged it went from the login screen to a white screen which I could not get around. Alt-F4 did nothing.
 
When I booted with internet access (back at my office I unplugged everything from my switch except my firewall and then plugged in this PC.... ) It went from the login screen to the desktop for a minute or so... then to the white screen.
 
The white screen was discouraging as I was hoping to at least see which varient of Ransomware this nasty thing was.
 
In either case Safe Mode was not accessible.
 
In checking various posts on ransom ware mention was made of various files being in certain locations.  So I removed the hard drive, connected it to an isolated PC, and was able to browse the drive.
 
I checked the desktop... there were no files with names that suggested how to unlock.
I checked the system folder to look for a *.sss file that would contain the names of files that were encrypted. Nothing with the suggested name or extension.
I tried to access my documents for the user... and that folder thr... Read more

Answer:Ransomware transitioned to White Screen

Hello Tomster2 Welcome to The Forums!!Around here they call me Gringo and I'll be glad to help you with your malware problems.Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!Please do not run any tools unless instructed to do so.We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at y... Read more

42 more replies
Relevance 45.92%

I have an x61t that when it locks for screen saver password and you have to CTRL ALT Delete the relog back on. the CAPS lock on the onscreen keyboard indicates on but it's not. 1. Log into the tablet.2. The screensaver would lock the tablet.3. Press Ctrl Alt Delete to get to the logon screen.4. The on screen keyboard would show the Caps Lock key as on but it wasn't. If they pressed the Caps Lock key it would then be on.5. The users don't press the Caps Lock key now, even though it is being displayed as on, and they can logon OK. I cannot recreate this problem on another X61tablet and this behaviour happens even when the notebook is in a docking station with an external keyboard.  anybody seen this error before?  

More replies
Relevance 45.92%

Hello,

I have a windows 7 64bit laptop that had a virus, obviously as it hid all the icons on the desktop and files. I ran unhide and malwarbytes and tdskiller and thought I got rid of it. But a new virus popped up a couple of days later, so I knew there had to be a rootkit that wasn't discovered before. When I ran eset's online virus scanner, I didn't clear the check mark and it removed the virus infected file. Unfortunately, I can't get back into it. I'm certain the registry thinks that file is required to start up. It boots, tries to repair, then boots and tries to repair.

I am able to get in using a Windows PE boot disk and I can get in using the windows 7 startup disk, but I have no idea what I'm looking for. The file that was removed as it shows in the Eset log is C:\Windows\system64\consrv.dll It says it's a Win64/sirefif.e trojan. The file is no longer in that directory. Eset cleaned by deleting - quarantined)

Thanks

Answer:Windows 7 64 bit eset removed consrv.dll, can't get to login screen

You can close this. I ended up fixing it myself.

Through Windows PE, I was able to load the hive from the laptop's system32\config directory. Windows 7 registry is a little confusing now. There appears to be couple of files named SYSTEM and one named SYSTEM.LOG2. The size of one of the files named SYSTEM is only 1K. The actual registry file is much larger. When loading an external hive, there is no CurrentControlSet, so I had to edit both ControlSet001 and ControlSet002

Open the registry to HKLM\ControlSet001\Control\SessionManager\Subsystems in the key Windows look for the string consrv:ConServerDllInitilization,2 That consrv is calling the consrv.dll virus file. If the consrv.dll file gets removed, you won't be able to get back into the OS. Change consrv to winsrv and reboot. Make sure to change both ControlSets.

2 more replies
Relevance 45.51%

A few weeks ago a ransomware screen popped up in my browser similar to this (but I think it was an FBI/CIA one):
 
http://www.bleepingcomputer.com/virus-removal/remove-australian-communications-and-media-authority-ransomware
 
After exiting the browser and restarting the computer I've never seen it again and haven't had any other indications of malware.I am seeking help to check if my computer is actually infected with malware and, if it is, to remove it.
 
The only other thing to note about the computer is that it has a tendency to freeze occasionally when switching between tabs in browser.
 
It is a Medion Akoya E6214 laptop running Windows 7 Home Edition 32 bit.
 
Any help would be much appreciated.
 
 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01
Ran by Daniel (administrator) on DANIEL-LAPTOP on 25-01-2015 16:29:12
Running from C:\Users\Daniel\Desktop
Loaded Profiles: Daniel (Available profiles: Daniel)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:... Read more

Answer:Checking for malware after ransomware screen in browser.

Hello and Welcome on board ,my Name is Machiavelli and I will assist you with your problem.If you booted into safe mode on your computer then print my instructions!I'm in the 'Malware Staff Team' and will provide you with advice:To remove Malware on a computer can be very complicated. Malware (malicious software) is able to hide and so I may not be able to find it so easily. In order to remove Malware from you Computer, you need to follow my instructions carefully. Don't be worried if you don't know what to do. just ask me! Please stay in contact with me until the problem is fixed.Below are a few tips:Removing Malware is usually very difficult.We need to search and analyse a lot of files. As this is done in our free time, please be patient especially if I don't answer every day!Please follow these instructionsIf you don't follow the instructions your computer may crash. If you fix your PC by yourself, this can be very risky!Please stay in contact with me until your problem is resolvedAs Malware may not be totally removed in one session or in one day, please stay in contact with me until the problem is resolved.Please don't run any other tools without consulting with me as this can complicate finding and removing all MalwareDon't run any tools while I'm fixing your PC. That is counter productive and again, will only complicate finding and removing all Malware!Read my post completelyIf you don't do so, you may make mistakes that could result in your System crashing by your own ... Read more

47 more replies
Relevance 45.51%

I have the Ransomware on my Windows 7, screen is locked!
 
I have a USB with HitmanPro, but since I used it about a year ago, I am no longer able.
 
Is there an alternative way to fix this?

Answer:Ransomware Screen Locked / HitmanPro Expired

Greetings and to BleepingComputer,
My name is xXToffeeXx, but feel free to call me Toffee if it is easier for you. I will be helping you with your malware problems.
 
A few points to cover before we start:
Do not run any tools without being instructed to as this makes my job much harder in trying to figure out what you have done.
Make sure to read my instructions fully before attempting a step.
If you have problems or questions with any of the steps, feel free to ask me. I will be happy to answer any questions you have.
Please follow the topic by clicking on the "Follow this topic" button, and make sure a tick is in the "receive notifications" and is set to "Instantly". Any replies should be made in this topic by clicking the "Reply to this topic" button.
Important information in my posts will often be in bold, make sure to take note of these.
I will attempt to reply as soon as possible, and normally within 24 hours of your reply. If this is not possible or I have a delay then I will let you know.
I will bump a topic after 3 days of no activity, and then will give you another 2 days to reply before a topic is closed. If you need more time than this please let me know.
Lets get going now
==========================
 
Hi 2013bcpc,FRST Scan from RECOVERY Environment on Vista, 7, and 8:
 On a clean machine, please download Farbar Recovery Scan Tool and save it to a flash drive.Note: You need to run the version compatible with your system. If you are not sure ... Read more

16 more replies
Relevance 45.51%

How do I bypass thdn remove this malware safely?Edit: Moved topic from Windows XP to the more appropriate forum. ~ Animal

Answer:DOJ ransomware program with non-bipassable blue screen

Welcome to Bleeping Computer and take a look here: http://www.bleepingcomputer.com/virus-removal/remove-department-of-justice-ransomware

1 more replies
Relevance 45.51%

Hello I have Windows 8.1  and a I got a Black Screen after Ransomware Ad was shown. I thought I had closed out of it but apparently it took. Now when I try to boot up my PC, it just goes to a black screen and I don't know where to go from there. Please help!

Answer:Windows 8.1 Black Screen after Ransomware Ad was shown

I do have the command prompt and was able to use regedit to get the registry. I tried to restore the computer but it said my computer is locked. Can anyone tell me how to unlock my computer?

4 more replies
Relevance 45.51%

The machine is a Latitude E6520 running Win7 Pro 32-bit.  I can't access anything on it.  I just get a white screen after logging in.

Answer:FBI Ransomware and now white screen in safe mode

Hello mudhustler, and welcome to the Malware Removal Forums! My name is bloopie and I'll be helping you with your problems as best I can! A few things to keep in mind while we are working together:If you have since resolved the original problem you were having, I would appreciate it if you let me know.If you are unsure about any of the steps just post what you can and I will guide you!Please tell me if you have your original Windows CD/DVD available.Please copy and paste all logs here unless otherwise instructed!Upon completing the steps below I will review your topic an do my best to resolve your issues.==========Now, let's see if we can get a log to work with. You will need the use of a removable flashdrive/thumbdrive for the next steps.Step Please download Farbar Recovery Scan Tool and save it to a flash drive.Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.Plug the flash drive into the infected PC.If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.If you are using Vista or Windows 7 enter System Recovery Options.To enter System Recovery Options from the Advanced Boot Options:Restart the computer.As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.Use the arro... Read more

14 more replies
Relevance 45.51%

I finally got the command prompt and was able to use regedit to pull up the registry. When I tried to restore the PC it says that my computer is locked. Can anyone help me please?

Answer:Windows 8.1 Black Screen after Ransomware Ad was shown

Greetings and to BleepingComputer,
My name is xXToffeeXx, but feel free to call me Toffee if it is easier for you. I will be helping you with your malware problems.
 
A few points to cover before we start:
Do not run any tools without being instructed to as this makes my job much harder in trying to figure out what you have done.
Make sure to read my instructions fully before attempting a step.
If you have problems or questions with any of the steps, feel free to ask me. I will be happy to answer any questions you have.
Please follow the topic by clicking on the "Follow this topic" button, and make sure a tick is in the "receive notifications" and is set to "Instantly". Any replies should be made in this topic by clicking the "Reply to this topic" button.
Important information in my posts will often be in bold, make sure to take note of these.
I will attempt to reply as soon as possible, and normally within 24 hours of your reply. If this is not possible or I have a delay then I will let you know.
I will bump a topic after 3 days of no activity, and then will give you another 2 days to reply before a topic is closed. If you need more time than this please let me know.
Let's get going now
==========================
 
Hi sdockery,
 FRST Scan from Safe Mode with Command PromptOn a clean machine, please download Farbar Recovery Scan Tool and save it to a flash drive.Note: You need to run the version compatible with your system. If you are not sure ... Read more

14 more replies
Relevance 45.51%

Hey guys,
 
My neighbor has gotten a virus that was a basic white screen that had "Send WMO to 84483832893829328" it reminds me of the FBI Ransomeware albeit much less sophisticated, i know two or three major trojan scripts just had their source code leaked so this may be some variation.
 
This is not the issue, the issue is that this malware/virus/trojan has somehow taken down the network,
 
For example  Computer A is infected yet Computers B/C can surf to bleepingcomputer.com and when i go to download "Rkill" it goes "page not found: server error" (never done this previously as you could presume) and the infected computer cannot make it out to the internet at all,
 
Also Computer B/C when you open CMD->Ipconfig and try to ping google at 8.8.8.8 i get no response, when i try to release/renew the connections it says "No adapter is currently in a ready state." Wtf is going on i've never seen this
 
has anyone seen anything like this? and/or has any tips? 
 
only 1 machine is infected per se, but the network is down on several other computers

Answer:White Screen FBI Like Ransomware, Also Attacked Network

Have they tried disconnecting the infected computer? And how is the network set up, just a modem/router with the computers connected to it?

1 more replies