Trojan infection
Oscar writes in with a virus question.
Q. I just recently upgraded a lot of my security center but for some reason this page keeps coming up whenever I double click on my Internet explorer and I cannot seem to figure out how to get rid of it this is a link of what appears http://theuptodatesafety.com and it also appears with a separate warning window asking me to download the latest virus protection and I have no need for that because I have my own anti virus program
A. It looks like you have a Trojan infection. You may have the ZLOB Trojan. ZLOB Trojan is an advertising Trojan that installs secretly and generates pop-ups on the infected computer. These pop-ups claim that the your computer is infected and recommend installing their illegitimate software to remove the infection. It will also pop-up fake virus or spyware infection alerts.
To remove the Trojan you need to do the following:
1. Make sure your virus protection is up to date.
2. Disable System Restore by right clicking on My Computer, going to the System Restore tab and checking the Turn off System Restore on all drives box.
3. Boot into Safe Mode (optional but recommended)
4. Run a full system scan and remove all references to ZLOB
5. Delete values from the registry. You should back up the registry before making any changes to it. You may or may not have all of the entries in your registry.
Click Start then Run.
Type regedit
Click OK.
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
In the right pane, delete the value:
"Shell" = "Explorer.exe, msmsgs.exe"
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"MSN Messenger" = "%System%\msmsgs.exe"
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
In the right pane, delete the value:
"uuid" = "[random characters]"
Navigate to the following subkey:
HKEY_LOCAL_MACHINE\ Software\Microsoft\Windows\CurrentVersion\policies\explorer\Run
In the right pane, delete the value:
"notepad.exe" = "msmsgs.exe"
Exit the Registry Editor, restart your computer and enable System Restore.
Related question
All Questions |