Friday, December 16, 2011

How do i get rid of the XP security desktop hijacking malware?

i have tried everything. malwarebytes' anti-malware, smitfraudfix, hijackthis, ccleaner. everything, and it's still there. what am i supposed to do? how do i get this off my computer? help please!|||try this.http://www.ehow.com/how_5044421_remove-d鈥?/a>





or follow this steps.http://www.techspot.com/vb/post645589-1.鈥?/a>|||This is a rogue antivirus program.


It pretends to be fake XP security center, because most people have windows XP. And they are idiots.





And by the way, if you cant download these you will have to buy a usb flash drive and have a friends computer.





P.S. Unplug your internet when you have the programs downloaded to prevent more spyware from downloading.





Download SmitFraud Fix.


Put it onto your desktop and run it.


If it does not run from your desktop, move it into the C:\ Drive and run it from there.


(Go to run and put in C:\ and drag it and run it from there.)


Once you have it running,





* Double-click SmitfraudFix.exe


* Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt





Now to clean.





* Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)





* Double-click SmitfraudFix.exe





* Select 2 and hit Enter to delete infect files.





* You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.


* The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.


* A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt





Also, process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user, so ignore the warnings and let the program continue.





Your computer shall be cleaned by now, but time to get some other antivirus programs so it doesn't happen again.





Keep SmitFraudFix just encase.


You're going to want firefox if you dont have it already.


It's so much better than internet explorer, safer and faster.





Ad-Aware. Detects most viruses I guess.





SpyBot S%26amp;D, will detect alot of rogue antivirus programs, spyware junk..





And a regular antivirus program. Free, and is really good.





And just encase you want regular protection..





All of this stuff is free





Hope this helped you clean out your computer.|||avast AV is garbage. Before you boot to safe mode you need to make sure you system is ready. Download AVG9.0 and Malwarebytes. Also get Hijackthis and Smitfraudfix. All of these are a must but read up on Hijackthis so you know what you are looking at and what to look for to find the hijacks. Also get regseeker and have it ready. Take the computer to Safemode and run Smitfraudfix. when the scans are done and you are back in safemode run AVG and Malwarebytes at the same time. Then run the Hijackthis to get rid of the BHOs and other common issues of Hijacks. After that run Regseeker on auto clean to clean out the left over infections.





once that is done run your defrag and reboot when its complete. this process will remove about 80% of infections. anything beyond that and you need to remove the HDD to gain further access.|||Here is how to fix this plague.





1. Do not panic


2. Right click on Desktop


3. Click on Properties


4. Select DeskTop tab


5.Click on Customize Desktop


6. Select the Web Tab


7. Uncheck the "Security" selection





To clean your PC:


These guys have downloaded an html file on you.


Go to the C:\Windows directory and find a file called


C:\windows\desktop.html.


It should have a recent date attached to it.


Delete it.





For More Information and help related to viruses malware or spyware issues visit http://antivirus.iyogi.net/|||Hey Antonio:


Please read this in its entirety before you proceed.


A lot of anti-spyware and anti-malware programs purport to be able to remove this particular malware, but as you obviously have discovered most of them do not work...


I was able to locate one source (http://malwaredisasters.blogspot.com/200鈥?/a> whereby you can manually go through your system registry and processes and terminate and/or remove each component. The source I found is a little vague so I will add the following to assist in your endeavors.





To terminate the processes as recommended in the "Countermeasures" portion of this source, simply hold down the "Ctrl" and "Alt" and "Delete" keys together to open Windows Task Manager. Click on the processes tab and end the processes that they describe.





As for registry changes, understand that changing you registry can result in your system not running at all and having to reinstall the entire operating system. As such, you may want to back-up your registry as described here: http://www.theeldergeek.com/windows_xp_r鈥?/a>





Finally, before you go and make any of these changes you may wish to ask your question at this site and the technicians there can give you step-by-step guidance. http://www.d-a-l.com/





Best of luck :-)|||To ward off any dubious activities and to combat viruses already present on a computer system, I suggest you take a look at:





http://www.pcthreat.com/removers.html





If your system has been infected, you will be informed as to which PC threat is prevalent on the system, and be provided with removal instructions accordingly.|||try to boot in safe mode (while system is booting keep pressing F8) then download avast anti virus (it helped others) and then schedule to run the virus scan at boot-up,

No comments:

Post a Comment