Basically copies a file to your computer, then changes your registry to re-direct your internet explorer start page, and then deletes itself after it's made the changes.
This is probably included in some web site that you visit often.
Quote:
|
Upon opening an affected page on a vulnerable machine, Shinwow.F creates the following file: c:\331983981.dat. The trojan then executes Regedit.exe and uses the newly created dat file to modify the follwing registry entries:
|
,which is why you are getting the reinfection after you remove it.
If you have not already done so, you may need to update your virus definitions for the virus scanner you are using.
When you run it. Make sure you boot up in windows 'SAFE' mode.
And you have Windows System Restore Disabled.
Then run the Virus Scanner and let it repair/delete the files.
If that is not working for you, as you have said.
You may need to manually remove the files, and the associated registry entries.
Here are links to both the Trojens you have.
http://www3.ca.com/securityadvisor/v....aspx?id=36651
http://www3.ca.com/securityadvisor/p...x?id=453089160
If all else fails, then you will probably need to get a program called
HijackThis and find a step by step guid on cleaning the entire system of the trojen.