<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Virus posing as security software - can't kill in Operating System - Microsoft</title>
    <link>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933210#M7766</link>
    <description>Smitfraudfix  will probably fix the problem but it is NOT a McAfee program.  It's from a guy in France who goes by S!R1.  I use it all of the time over on the DELL Hijackthis forum.&lt;BR /&gt;&lt;BR /&gt;Bleepingcomputer has a nice writeup on how to use it (as part of a tutorial on how to kill a similar infection).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.bleepingcomputer.com/forums/topic70074.html" target="_blank"&gt;http://www.bleepingcomputer.com/forums/topic70074.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It usually creates a log file at C:\rapport.txt.  Would not hurt to check it to see if complains of any files it can't fix.  &lt;BR /&gt;&lt;BR /&gt;When you finish with SmitFraudFix get Hijackthis.exe from&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://tomcoyote.org/hjt/hjt199//HijackThis.exe" target="_blank"&gt;http://tomcoyote.org/hjt/hjt199//HijackThis.exe&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;(above is the direct download link.  If you want to see the site you are getting it from:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://tomcoyote.org/hjt" target="_blank"&gt;http://tomcoyote.org/hjt&lt;/A&gt;&lt;BR /&gt;)&lt;BR /&gt;&lt;BR /&gt;Save it to your desktop with a new name like Richard.exe  then run it.  Select the top option (Scan and Save Log) then when notepad comes up with the log, copy the text and paste it in your next Reply.  Let me check it to make sure you got it all.  Lately a lot of the smitfraud style infections are combined with a vundo infection which likes to give you popups and I expect can also invite its friends in.  It also hides if it sees a program named Hijackthis running.&lt;BR /&gt;&lt;BR /&gt;Ron&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 26 Jan 2007 10:57:57 GMT</pubDate>
    <dc:creator>Ron Kinner</dc:creator>
    <dc:date>2007-01-26T10:57:57Z</dc:date>
    <item>
      <title>Virus posing as security software - can't kill</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933207#M7763</link>
      <description>Have had this guy stuck on my MSEI browser for several weeks now. Can't get it to go away. Reported it to McGaffy &amp;amp; US Gov dept of Security - no reponse. HP &amp;amp; MGaffy scans don't find anything wrong...!&lt;BR /&gt;&lt;BR /&gt;Every time I click home key on browser it takes me back to the below listed un-welcome security advertising page.  My browser shows Goggle as my assigned home page, but still "defaults" to 'asecureboard' screen page anyway.&lt;BR /&gt;&lt;BR /&gt;Any clues as to how to kill this thing?  Seems to come from Rumania...?&lt;BR /&gt;&lt;BR /&gt;This is culprit:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://asecureboard.com" target="_blank"&gt;http://asecureboard.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt; Regards,&lt;BR /&gt;&lt;BR /&gt;   Richard Anderson&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Jan 2007 01:08:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933207#M7763</guid>
      <dc:creator>king144</dc:creator>
      <dc:date>2007-01-26T01:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Virus posing as security software - can't kill</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933208#M7764</link>
      <description>hi Richard,&lt;BR /&gt;&lt;BR /&gt;can you try to verify your registry?&lt;BR /&gt;&lt;BR /&gt;Windows Registry Editor Version 5.00&lt;BR /&gt;&lt;BR /&gt;[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]&lt;BR /&gt;"Start Page"="&lt;A href="http://www.google.com/" target="_blank"&gt;http://www.google.com/&lt;/A&gt;"&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;kind regards&lt;BR /&gt;yogeeraj</description>
      <pubDate>Fri, 26 Jan 2007 04:26:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933208#M7764</guid>
      <dc:creator>Yogeeraj_1</dc:creator>
      <dc:date>2007-01-26T04:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Virus posing as security software - can't kill</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933209#M7765</link>
      <description>Hi,&lt;BR /&gt;and welcome to the forums !&lt;BR /&gt;&lt;BR /&gt;McAffee has the solution:&lt;BR /&gt;&lt;A href="http://forums.mcafeehelp.com/viewtopic.php?t=101014" target="_blank"&gt;http://forums.mcafeehelp.com/viewtopic.php?t=101014&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;And many others returned by web search.&lt;BR /&gt;&lt;BR /&gt;Please also read:&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/helptips.do?#33" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/helptips.do?#33&lt;/A&gt; on how to reward any useful answers given to your questions.</description>
      <pubDate>Fri, 26 Jan 2007 04:53:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933209#M7765</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2007-01-26T04:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Virus posing as security software - can't kill</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933210#M7766</link>
      <description>Smitfraudfix  will probably fix the problem but it is NOT a McAfee program.  It's from a guy in France who goes by S!R1.  I use it all of the time over on the DELL Hijackthis forum.&lt;BR /&gt;&lt;BR /&gt;Bleepingcomputer has a nice writeup on how to use it (as part of a tutorial on how to kill a similar infection).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.bleepingcomputer.com/forums/topic70074.html" target="_blank"&gt;http://www.bleepingcomputer.com/forums/topic70074.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;It usually creates a log file at C:\rapport.txt.  Would not hurt to check it to see if complains of any files it can't fix.  &lt;BR /&gt;&lt;BR /&gt;When you finish with SmitFraudFix get Hijackthis.exe from&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://tomcoyote.org/hjt/hjt199//HijackThis.exe" target="_blank"&gt;http://tomcoyote.org/hjt/hjt199//HijackThis.exe&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;(above is the direct download link.  If you want to see the site you are getting it from:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://tomcoyote.org/hjt" target="_blank"&gt;http://tomcoyote.org/hjt&lt;/A&gt;&lt;BR /&gt;)&lt;BR /&gt;&lt;BR /&gt;Save it to your desktop with a new name like Richard.exe  then run it.  Select the top option (Scan and Save Log) then when notepad comes up with the log, copy the text and paste it in your next Reply.  Let me check it to make sure you got it all.  Lately a lot of the smitfraud style infections are combined with a vundo infection which likes to give you popups and I expect can also invite its friends in.  It also hides if it sees a program named Hijackthis running.&lt;BR /&gt;&lt;BR /&gt;Ron&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Jan 2007 10:57:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933210#M7766</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2007-01-26T10:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Virus posing as security software - can't kill</title>
      <link>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933211#M7767</link>
      <description>&lt;BR /&gt; Holy Bat Goop!  It's gone!!!&lt;BR /&gt;&lt;BR /&gt; Thanks fellers!&lt;BR /&gt;&lt;BR /&gt; Only residual damage was Desktop background had to be reset. Downloaded suggested scan tool - found nothing I recognize as suspicious, so left things alone...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;  -Richard&lt;BR /&gt;   Washougal, WA</description>
      <pubDate>Sat, 27 Jan 2007 00:28:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-microsoft/virus-posing-as-security-software-can-t-kill/m-p/3933211#M7767</guid>
      <dc:creator>king144</dc:creator>
      <dc:date>2007-01-27T00:28:44Z</dc:date>
    </item>
  </channel>
</rss>

