Help to remove this file

Hi, My sister's computer every time when running Internet Explorer 7, I noticed a short message appear on the 1st line of IE tool bar, Virus is now ATTACKING your system from MAnz_Shidah. I scanned with antivirus/anti-spyware but could not fine any affected files.

Windows Security 292 This topic was started by ,


data/avatar/default/avatar21.webp

11 Posts
Location -
Joined 2005-03-04
Hi,
 
My sister's computer every time when running Internet Explorer 7, I noticed a short message appear on the 1st line of IE tool bar, " Virus is now ATTACKING your system from MAnz_Shidah".
I scanned with antivirus/anti-spyware but could not fine any affected files.
 
The only 2 log files I found on HijackThis were:
 
a) HKLM\..\run:[manz_shidah_virus]wscript.exe
C:\windows\system\manz_shidah.js
 
HKCU\software\microsoft\internet explorer\main, Windows
title = Virus is Attacking your system
 
I also noticed there were a Jscript file = Manz_shidah and HTML document = Attach your system appeared on all harddisk partitions which were not be able to delete.
 
Please help, thanks

Participate on our website and join the conversation

You have already an account on our website? Use the link below to login.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This topic is archived. New comments cannot be posted and votes cannot be cast.

Responses to this topic


data/avatar/default/avatar06.webp

320 Posts
Location -
Joined 2004-12-09
Hijackthis can remove the registry entries and if you go into the misc tools section of Hijackthis you can select files to remove at reboot.

data/avatar/default/avatar23.webp

1 Posts
Location -
Joined 2008-07-07
Hello,
When I download programs from the internet fresh download keeps popping up and asks me to register. It won't let me download anything. I removed it in the controll panel and used an antivirus program to unistall it. It went away for a few days then it came back and I can't find it on my computer.
 
Pease help, thanks