When I run IE or firefox to visit some websites, some of them return connect time out message, I use "netstat" command to check the computer’s network connection, I found a lots of connection with "ns1.thepicturehut.net" or ‘ns1.helpupdated.net’ was establish. I had never visited thepicturehut.net or helpupdated.net, I also found a process named emule.exe, I have never install this program, My computer was infected with unknown virus? How to resolve this problem?
According to your describing, we think your computer was infected by W32.Changeup, this virus can install a well-known file-sharing program named Emule. When the worm is executed, this installation can be executed automatically.
after the installation, the W32.Changeup virus creates thousands of copies of itself with different file name in the Emule file-sharing folder,
All files were named .zip file, each zip file contains a legitimate setup.exe file. But in fact the file is a copy of the W32.Changeup virus.
This virus could steal your personal information and send your private information to remote hackers, please run free avast anti-virus to scan this threatens on your computer, and then run wise pc doctor to fix the related error of W32.Changeup virus.
How to get rid of W32.Changeup virus automatically?
You will need to download and burn into CDROM several programs on clean PC or copy them to USB Disk to remove virus. Here is the instruction:
Step A: copy the below programs to USB disk (you can use an MP3 player) or Burn them to CD:
- Avast Pro Antispyware software(free of charge) .Please download with this Download Link.
Step B: Restart your computer. At this point you need to gently Press the F8 key repeatedly when you find the startup menu, Select the option “Safe Mode with Networking” by using the arrow key, then press Enter key on your keyboard , and your computer will start into Windows Safe Mode.
Step C: Now you need to install Avast Pro Antispyware on your computer, When the program is installed， your need update its database to the latest, then reboot your computer to make the program fully functional, Go Step B to reboot your computer into Safe Mode and do a complete scan for your computer .
(1)In case you have some problems running Avast Pro Antispyware, you may rename the downloaded file name to explorer.exe or iexplore.exe. After that double click the download file and follow the install steps.
(2) Please make file extension show before renaming download file.
Step D: After finish the full scan, click "Show Results" and be sure that the important data aren’t removed and infected. Select or ignore the scan result and click "Remove Selected" button to get rid of the virus and malwares. Avast Pro Antispyware will give you a report to indicate all operations for this scan. It can be saved as you want. Restart your computer and the Avast Pro Antispyware will get rid of all virus or malwares which are detected before.
Step E: How to erase bad registry? Please install Wise PC Doctor– the best PC cleaner can easily fix your broken registry values and restore registry values.
Why Wise PC Doctor should be used?
As we all know, virus, Trojans and Malwares make the computer breakdown by destroying and modifying the registry values so that the computer will not run normally.
After the virus, Trojans and Malwares are removed, the registry remains to be destroyed or modified, therefore the computer’s system still has some problems. That’s why you really need to fix the registry. Furthermore, some virus, Malwares and Trojans leave many dll data in the registry and this may cause damaged DLL errors and also have an effect on the computer’s system performance.
In any other case Uninstall or install software may make your registry database fragmented, with corrupted, harmful and obsolete files. Do a complete scan for your computer by Wise PC Doctor at this moment.
Step F: Run Wise PC Doctor to repair your computer:
1. Install Wise PC Doctor.
2. Click "One-Click Fix", do a complete scan for your computer.
3. Click “Repair All” then fix all detected problems.