I have tried Adaware, Spybot, Trojan Hunter, Avast, AVG, Hijack This and none of them have been able to catch this little bugger. I'll post it in two part as there's a limit on characters here.

part II

Any help would be appreciated.

Sorry, I don't see an edit button and it looks as if I had to split it up into 3 parts. This is the second part, the second post is the third piece.

You have a Trojan. Possibly click here

Ewido should be worth a try. Download it from click here . Update it and run a scan.

if xp have you run the scans with system restore disabled and also possibly in safe mode?


Ok, so after a very educational walk through from a friend lastnight I have been able to overcome this and I wanted to post so hopefully I could help some others from the knowledge I've gained.

Ok, so basically these types of viruses inbed themselves and cause a false alert telling you that you have a virus and then you click on the flashing icon in your tray and it takes you to a website that you can there buy their $50 miracle to cure your virus.

My friend told me to bring up my task manager by pressing ctrl+alt+del and send him the list of processes that I had running that had me as the user (He said that most required windows programs will have 'system' listed as the user). The two files that came up for this virus were pmsngr.exe and pmmon.exe - Fortunately he had enough knowledge of the basic programs that should be running he was able to pick those out. When I did a search for the files by pressing start, then search, looking in all files and folders, I then found where they were located.

For mine in particular, it placed itself under c:\Program Files\IntCodec

Of course it wouldn't let me delete the whole thing. My solution to this was to reboot into safe mode, go into the Program Files folder delete the IntCodec folder, and then empty my garbage can.

After this for further clean up, you'll want to delete the registry entries. Do this by pressing start, then choosing run. Type in regedit and then hit enter. This will bring up your registry keys. To do a search, press F3 and type in the name of the file. I had to close out and repeat process for each file, as when I hit F3 again it would look for the same file, though this can be handy, too as it seems the registry keys like to hide in several places. Repeat this process until all files are deleted. Also do a search for the name of the virus, in my case, I did a search on 'secret' and crush'. Basically as it was explained to me, the registry key's purpose is to tell the file which contains the virus what to do, where to go, ect., and it also has a way to conect to the internet and update or replace the virus files if deleted, this is why it's important to delete the registry keys as well. Once this is done, reboot. You should be good to go. He did tell me also, that if it comes back to repeat this process as sometimes you may miss a file, or registry, and to continue until it's gone. It's been 24 hours *crosses fingers* and no return to the 2 every two minute pop up.

I hope this has been a simple enough write up for my fellow average user to understand and fight against this type of thing without wasting hours and hours of precious time such as I had to to learn about and destroy this thing.

One final reminder, I forgot to mention, make sure you empty your trash can from the registry keys before your final reboot. You don't want those little buggers coming back from the dirty grave... lol

