This is installed by a Trojan. The only question is what type of Trojan? Since I don't know I will give you way to remove Smitfrauds and other types.
These two sites have programs that specialize in removing Smitfrauds. The are both very good.
http://www.internetinspiration.co.uk/roguefix.htm
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php
The programs listed below are the best at removing general Trojans and adware. The steps below the programs open your computer for proper removal from all areas of your computer.
Download and Update Ewido (now called the AVG Antispyware). Do not run:
http://www.ewido.net/en/download/...
Download AdAware SE and update. Do the setup. Do not run:
http://www.filehippo.com/download_ad-aware/
AdAware SE Setup:
1. Select "use custom scanning options" then select "customize". Make sure the following options are enabled: "scan within archives," "scan active processes," "scan registry," "deep scan registry," "scan my IE favorites for banned URLs," "scan my Hosts file."
2. Select the "tweak" option. Under "scanning engine," make sure "unload recognized processes and modules during scan" is enabled. Enable "scan registry for all users instead of current users."
3. Under "cleaning engine" turn on "always try to unload modules…," "during removal unload explorer and IE if necessary," "let windows remove files in use at next restart," and "delete quarantined items after restoring."
4. Use the "select drives and folders to scan" option to ensure that your entire hard drive is scanned (if you have more than one hard drive, scan all of them (of course, do not include floppy and CD/DVD).
TEMPORARILY SHOW HIDDEN FILES AND FOLDERS.
1. Click Start, and then click Control Panel.
2. Click Appearance and Themes, and then click Folder Options.
3. On the View tab, under Hidden files and folders, click "Show hidden files and folders", and clear(uncheck) the "Hide protected operating system files" check box.
IMPORTANT: Files are hidden by Windows for a very good reason. It is not wise to experiment with these files. Unfortunately, to successfully remove modern spyware we must turn this protection off temporarily. Please turn the protection back on when you have finished cleaning your system.
EMPTY INTERNET EXPLORER BROWSER CACHE:
1. On the Internet Explorer Tools menu, click Internet Options.
2. On the General tab, in the Temporary Internet Files section, click the Delete Files button. Select the Delete all offline content check box in the confirmation dialogue box that appears, click OK. Click OK again.
RESTART IN SAFE MODE:
To do this you need to hold down or repeatedly tap the F8 key while the computer is booting (when the computer is displaying a black screen with white text). When the boot menu appears, use your keyboard arrows to select "Safe Mode."
Safe Mode can look quite ugly. The color may look bad, and all of your desktop icons will be very large. This is normal.
START THE SCAN WITH YOUR ANTI-VIRUS PROGRAM.
When the scan and removal are completed REBOOT COMPUTER. This will restart you in normal mode. DON'T FORGET TO RESET HIDDEN FILES AND FOLDERS.
NEW RESTORE POINT.
The RESTORE POINTS may be infected with the Malware and cannot be used.
HERE'S HOW:
1. Click Start, and then click Control Panel.
2. Click Performance and Maintenance, click System, and then click on the System Restore tab.
3. Select the Turn Off System Restore check box, click Apply, then restart your computer.
4. Return to the System Restore Tab and turn System Restore back on.
TO SET A NEW RESTORE POINT:
1. Click the Start button.
2. Point to Programs, then navigate to Accessories, then System Tools, then click System Restore.
3. Choose Create a restore point, and then click Next.
4. In the Restore point description box, type a name for your restore point, and then click Next.
5. Click OK.
NOTE: If you are using Windows XP Service Pack 2 (SP2) and are unable to access the Internet after removing Malware, there is a command that may fix the problem. It works by resetting the winsock catalogue. Click on Start, then Run and type CMD in the box. Click OK. Type "netsh winsock reset" (no quotes)into the DOS window that appears.
2006-11-13 08:07:50
·
answer #1
·
answered by Anonymous
·
0⤊
0⤋
It's a Trojan calld "VIRUSBURST" you will have to format the hard drive I am sorry to say. I got a dose of it on 4/11/06 I tried everything. Just have a look and see have you a restore point, I think not Restore has been disabled.Check it out . Macafee left it in. I had Windows Defender and AVG running at the time, For different tasks one job for one and the other for the other as they conflict if doing the same thing. I found out what it was deleting it every where I found it but still persisted. I ran msconfig and deselected all startup items, On reboot there it was fresh as ever. I re enabled all startups. I installed Windows Live One Care from Microsoft Help And Support. When I ran that it dumped AVG and left Defender alone for obvious reasons. It found 4 instances trojans and put them into quarantine. And things got worse!!!!. On reboot and investigation I was dealing with different languages in different places Spanish mostly. I Searched from Search for VirusBurst and I found an email in my name but not me!?!? in My Documents/Settings. I had nothing to lose so I visited that address. It was then I was told by another Terrorist that it was VirusBurst and what it got up to. After the usual Free Scan I was toldI had to buy the fix. A no win situation. I wrote to Microsoft through Help and Support. I got a rapid reply. but no fix. I wrote twice more and got very good service from them, But no Fix. That was on 4/11/06 they might have fix by now because you are not the first. The best of luck.
2006-11-13 18:07:57
·
answer #2
·
answered by mailliam 6
·
0⤊
0⤋
Get some decent anti-spyware and anti-virus ware, i like Superantispyware and Avast both free, and run in safe mode.
2006-11-14 07:05:13
·
answer #3
·
answered by carol g 3
·
0⤊
0⤋
Click start then search type in what it says then when found right click and delete
2006-11-13 17:30:54
·
answer #6
·
answered by taxed till i die,and then some. 7
·
0⤊
1⤋
malware download a good antispyware update it and your antivirus and run them in safe mode
2006-11-13 15:53:18
·
answer #7
·
answered by spankdis 5
·
0⤊
0⤋