Is this occurring only in Safe Mode or all the time?
Have you tried System Restore to see if that helps?
You may have what's called the "Vundo" trojan. It's a nasty little P.O.S. if ya know what I mean.
Quote:
Discovered: November 20, 2004Updated: March 17, 2010 10:38:59 PMType: TrojanInfection Length: VariesSystems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Vista, Windows XP Trojan.Vundo is a Trojan horse that downloads files and displays pop-up advertisements. It is known to be distributed through spam email, peer-to-peer file sharing, drive-by downloads, and by other malware.
Infection
Trojan.Vundo, also known as VirtuMonde, VirtuMundo, and MS Juan, typically arrives by way of spam email or is hoisted onto the user’s computer by a drive-by download that exploits a browser vulnerability. The Trojan may also be downloaded via file-sharing networks, with the malicious executables having been given innocuous names to trick users into running them.
Trojan.Vundo may also be downloaded by other malware. The mass-mailing worms W32.Ackantta.B@mm and W32.Ackantta.C@mm are known to download variants of this threat family on to compromised computers. Increased levels of infection of these worms has been seen to result in an increase in the number of Trojan.Vundo infections.
Functionality
Trojan.Vundo was designed as a means for displaying advertisements on the compromised computer. The Trojan includes functionality to display pop-ups and is additionally capable of injecting advertisements into search results.
The advertisements and pop-ups that are displayed include those for fraudulent or misleading applications; intrusive pop-ups, fake scan results, and so-called alerts that masquerade as being from legitimate security software appear on the desktops of compromised computers in an attempt to frighten users into clicking buttons for 'further information'. The advertisements generally link to sites offering non-functional (or occasionally outright harmful) programs that purport to be capable of ridding the computer of non-existent malware in return for a fee payable by credit card.
Advertisements for adult Web sites and services may also be displayed by the threat.
In order to make it more difficult to remove, Trojan.Vundo also lowers security settings, prevents access to certain Web sites, and disables certain system software. Some variants attempt to disable antivirus programs.
Recent Trojan.Vundo variants have more sophisticated features and payloads, including rootkit functionality, the capability to download misleading applications by exploiting local vulnerabilities, and extensions that encrypt files in order to extort money from the user.
|
Download and use the free version of Malwarebyte's Anti-Malware and see if that cures it. IF possible try to run it in safe mode.
I've never had this virus or trojan but the users I know who have been infected by it says it a little difficult to get rid of.
Sometimes persistent virus, spyware or malware processes will not allow a security software to run or to effect a complete removal of the infection, since these processes are themselves up and running on your Windows computer.
RKill is a easy to use tool that kills known processes that stop the use of normal anti-malware applications.
RKill just kills processes, imports a Registry file that removes incorrect file associations and fixes policies that stop us from using certain tools. Then it kills Explorer.exe so it will restart and enable some of the Registry changes. When done, RKill will then create a log listing all processes that were terminated while the program was running.
After running , it will display a log which will show the malware processes it has killed.
Now you should not reboot your computer as any malware processes that are set to start automatically, will just start up again.
Instead, after running RKill you should scan your computer using your malware removal tool of choice.
This will ensure a more complete removal of the malware which may have infected your Windows computer.
For download link & details visit
BleepingComputer.