The last time I started a thread I had spyware.. I think that it has to do with this a lot.. It seem like with the last and this one, is caused by the security center alert. This time it is saying there is a Win32.Zafi.B but really I think it is a rouge program..(or however you would call it). I look around the net and found that this was a problem so I assume now that this is. It does give the option to enable protection yet lead to "Ultimate Fixer" and so on. I dont know why but somehow I guess the security is embbed (I think the word is) with bad stuff. I could have given it to the school res tech, but want to try to fix this to gain more knowledge. Hope someone can tell me something that will help.

Dani AI

Generated

Brief expert summary and next steps (expands on and )

The popup you describe (an alert naming “Win32.Zafi.B” and steering you toward “Ultimate Fixer”) is exactly the pattern used by fake‑security/“scareware” programs that impersonate the Windows Security Center to trick users into buying bogus software. (us.norton.com)
The specific label Win32.Zafi.B can appear inside those fake alerts even though the real Zafi family is an older worm; attackers reuse scary names to press the victim to install/purchase the rogue product. (2-spyware.com)

Practical, ordered actions (do these before paying or calling any number)

  • Disconnect the PC from the internet so the rogue tool cannot download more components or steal data. (Don’t run or pay for “Ultimate Fixer”.) (us.norton.com)
  • If possible, boot into Safe Mode (or use a clean USB to run a rescue environment) and run a thorough scan with a reputable on‑demand scanner or a rescue disk. If normal tools are blocked, use an offline rescue ISO (for example Kaspersky Rescue Disk) or a second‑opinion online scanner from a clean machine. (kaspersky.com)
  • Use an autorun/startup inspector to find and disable persistent startup items (many rogue cleaners add names that run at login). The Sysinternals Autoruns utility is the standard tool for that. (learn.microsoft.com)
  • Check Scheduled Tasks, the usual Run keys, the hosts file, and AppData and Program Files for folders named like “Ultimate Fixer” and remove/quarantine suspicious executables only after you have a clean backup of important files. (If tools refuse to run, helpers on removal forums can guide you through safe removal steps.)

If cleaners and offline rescue media don’t fully restore the system
Back up personal files only (scan the backups before reuse) and do a clean OS reinstall. Be aware: very advanced firmware/UEFI rootkits can survive a normal reinstall and require firmware reflashing or hardware replacement—this is rare but worth knowing if the machine keeps re‑infecting after a full wipe. (eset.com)

Notes and cautions

  • Do not enter payment or call numbers shown by the popup. (us.norton.com)
  • If unsure, capture a screenshot, export a short startup log (Autoruns) and post it to a trusted malware removal forum before running destructive tools.

Recommended Answers

All 3 Replies

Download Malwarebytes Antimalware and run it on your pc. It does a pretty good job of getting rid of the nasties.

Yea... That kind of been done with the last problem.. Yet there something that is keeping the problem going out.. I'm wondering if there something I should check. Like if there is a folder that would have everything that would be overlook maybe.

Have you run a scan in safe mode? Ususally I run CCleaner to get rid of all the temp files, run Malwarebytes Antimalware, and if that doesn't work, I run a full scan of Antimalware in safe mode.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.