This is probably a virus or worm which doesn't harm your computer system but only opens the link i.e. www.thenewspedia.com uncondinationably. Actually this is a browser hijacker effecting IE (Internet Explorer) and Firefox. It simply promotes thenewspedia by opening up the site randomly while you are browsing or opens up along with homepage even if you have no set it as your homepage.
As a browser hijacker, it takes controll over your browser so you should immediately remove it as to avoid future harms. So here's the removal steps:
REMOVAL
This is caused by a file named nissan.exe and here I have described 3 methods to remove it.
METHOD I:
Open registry editor by going to Start->run->regedit and hit enter.
Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon
you will see an entry named "taskman" with a value similar to "C:\RECYCLER\S-1-5-21-3028898713-081331...
Double click it and you'll see its path like C:\RECYCLER\S-1-5-21-3028898713-0813311981-684376638-1852\nissan.exe
This file is the cause of the mess as it tells windows to execute the file. So, you have to delete the key "taskman" but before that copy your path address (C:\RECYCLER\S-1-5-21-3028898713-0813311...\) except nissan.exe and navigate to the folder by pasting it in run. Now delete the key.
When you open the folder recycler folder nothing will be shown. This is because it is set to super hidden state. Use "attrib -h -s -r" command in run like start->run->[attrib -h -s -r C:\RECYCLER\S-1-5-21-3028898713-0813311981-684376638-1852\nissan.exe] to remove any attribute and then delete it.
Or alternatively, you can use "unlocker" to delete the folder. This is a free and handy utility to move or kill or delete files when locked by other windows services.
Download link:
http://ccollomb.free.fr/unlocker/#download
METHOD II:
Use malwarebytes anti-malware. This is a free tool for removing any malwares, worms, trojans, etc and is updated frequently so I would suggest trying www.malwarebytes.org and downloading their free anti-malware as you might have other worms too.
METHOD III:
You can use this direct removal tool too
http://www.prevx.com/filenames/X1371355467920112549-X1/NISSAN.EXE.html
If this helped you pls do comment.
my pleasure..
ReplyDeleteif you have any other problems then feel free to ask.
thanks =)
ReplyDeleteThis comment has been removed by the author.
ReplyDeleteTHANKS a LOT froM TaCOLaND !!
ReplyDeletepD :: u are a GooD Person ;)
pD2 :: i choose Opera ¡!
thanx
ReplyDelete@iim.vxk, i switch opera, mozilla n chrome.
Try, http://www.opera.com/browser/next/
opera beta 3, its cool with unlimited tabs
Thanx!
ReplyDeletewell tried EVERYTHING possible din work as even if we delete the key using spyware doctor or any antimalware ..it recreates itself...what WORKED..was TROJAN REMOVER 6.8.1 update it..u may use the 30 days version..it detects NISSAN.exe prevents it from running & renames it...use that option during scan..it works wonders...
ReplyDeletemy choice was "unlocker",,, unlock folder and delete, simple.
ReplyDeletei cannot change attrib to the folder!!
ReplyDeletei even use cmd, navigate to the folder but nothing happens.... unlock does not show the folder...
Thanks friends, I finally got rid of that pest, and also Troyan Remover worked fine removing that NISSAN.exe, :)
ReplyDeleteI tried Unlocker, nothing. Then I tried several others: Ad Aware, Reanimator, Trojan Remover. Still nothing... some of them didn't even recognice that there was something funny going on in the Register whilst they did scan it...
ReplyDeleteThen I came across Malwarebytes'Anti-Malware. It detected 33 (!) other trojans as well, none of wich the other programs detected. So, that program would be my recommendation. It removed this piece of crap of both my XP and Vista machines!
^^ yes malwarebytes sure does the job, here's an even faster one, give a shot to hazardshield, it even removes your messenger cookies.
ReplyDeleteI did the regedit you recommended and used unlocker. It was a huge pain, but finally it is fixed! Thank you for your help!
ReplyDeleteFunky stuff, Zoras. You are a gent and a scholar. Many thanks, M
ReplyDeletei want to know more about how this malware work where i will get this info. Thanks for this usefull info. and i quit surprise with this virus behavior. nice maware.
ReplyDeleteThanks man!
ReplyDeleteI used the Unlocker and the Malwarebytes.
But when I open the Registry, I still have the "Taskman" key with the same value (with .../nissan.exe) in the end. Does this right?
I am not very into IT, but I am very happy that I tried something myself. But, did I make a mistake or that's normal?
What do you think about AVG 8.5 Free Antivirus and Spyware Terminator in combination?
ReplyDeleteThanks in advance!
GRazie! Thank you!
ReplyDeleteThanks a lot my dear friend,,,,i used unlocker and deleted the entry....
ReplyDeleteThanks a lot... :)
i tried doing the steps that removes the atteributes but i still cant see the folder i need to delete.. pls help T_T
ReplyDelete^^ actually, recycler is a windows system file, so it's hidden. to view it open my computer and select tools menu -> Folder Options. There click on "Show hidden files and folders" and uncheck "Hide protected operating system files" and ok.
ReplyDeleteNow goto ur C drive and u'll see ur hidden files along with recycler. Then find "nissan.exe" and delete it.
Note: Don't delete recycler. It's a system file
@ about AVG 8.5 Free Antivirus and Spyware Terminator, add zone alarm to it.
ReplyDelete@"I am not very into IT" gr8 job! well u forgot to delete the registry key. just delete the "taskman" key from registry and ur done.
thanks 4 all the comments
..peace
I can't connect to microsoft website or any antivirus website, if i give a proxy adress in my browser. so no update is possible. can you help me?
ReplyDeleteThank you. Keybfr
Cheers, you did a great job!!! Greetings from the end of the world in Niger!
ReplyDeleteGrand merci! C'est fantastique!!! :-)
ReplyDeleteCheers,
From Senegal.
@KEYBFR
ReplyDeletehttp://zorasaroz.blogspot.com/2009/11/so-microsoft-uses-activex-and.html
help
ReplyDeletei using method II
i use quick scan on the malvare
but it can find the taskman .... nissan.exe
after finish scan
it found the injected
n told me restart pc
after restart pc no more problem
but after 2days
the problem come back again
how should i do ?
i blurring on method I
blurring start from paragraph 5
i copy the path address ....nissan.exe
but after that you say paste in at run there
but i paste nothing come out
copy your path address (C:\RECYCLER\S-1-5-21-3028898713-0813311...\) "except nissan.exe" and navigate to the folder by pasting it in run. Now delete the key.
ReplyDeleteUse "attrib -h -s -r" in cmd if its hidden.
Hi there,
ReplyDeletetried all 3 methods (well you have to pay to get a licence for the soft used in n°3, no way...), and I had no luck at all, the thing keeps coming back...
Please help. nissan is not getting deleted from the folder C:\RECYCLER\S-1-5-21-3162694132-5732335592-260337274-6296
ReplyDeleteWhat shall I do next? I tried eveything..restarted...closed all the programs to delete above file
I could not find nissan.exe in Recycler folder, "attrib" did not work for some reason. Went to safe mode, and situation was the same.
ReplyDeleteI eventually emptied recycle bin in safe mode and that seemed to solved the problem.
Ofcourse first I erased the key in registry.
Method 1 worked for me! (though the unlocker link mentioned here is dead)
ReplyDeleteI downloaded unlocker at www.scanwith.com/Unlocker_download using the mirror link.
thanks a lot for sharing this! you really made my day.
sorry it was: www.scanwith.com/Unlocker_download.htm
ReplyDeletebut is i use malware i have to deactivate antivirus?
ReplyDeleteif*
ReplyDeleteyou can also remove the virus using AVG 9 and best of all its free
ReplyDeletethank u, but i have avira antivirus, and i scaned but stil appears that, when i turn on computer or suddenly apears that site.
ReplyDeleteMethod 1 worked fine for me so far
ReplyDeleteJust Download Simple Remover
ReplyDelete1)Extract this exe in to the C drive root
2)Restart your winxp pc in safe mode with command prompt
3)run this utility
http://rapidshare.com/files/328310644/NissanRemover.rar
Sorry Link Changed
ReplyDeletehttp://rapidshare.com/files/328313480/NissanRemover.rar
Thanks a lot
ReplyDeleteIt do help me to clean the worm
Thanks a lot to all the ones who worked on this!!!
ReplyDeleteIt really started annoying me, the autostart ups!
Thaks, the file is gone and so is the struggle with the program... :D
@uploader i was really dumb that i didn't think of making the remover.. gud job
ReplyDeletei'll be sure to make one for n00bs. Ask me if u got any problemo.. ;-p
I used Zone Alarm, Malwarebyte and CCleaner as an alternative for registry and now he's gone thx dude about the tips!
ReplyDeleteNissanRemover did work, thanks a lot. Tried method 1, but i was deny to delete that nissan.exe file.
ReplyDeleteDear Zoras,
ReplyDeleteI really appreciate your kind advice in detail on this blog of you.
I did work with the method II, the unlocker program to delete the nissan folder in the RECYCLER. Now the file is gone and so is the struggle with this kind of browser hijacker.
Thanks and regards,
from Seoul in Korea
thanks a lot
ReplyDelete--Naresh
thanks a lot, your help is much appreciated.
ReplyDeleteMartin (France)
Hey there,
ReplyDeleteThis helped me..
Just to let who are reading here.. I downloaded and installed a C++ Resource Builder named Resource Builder 3.0 and that it how my computer was infected by this adware.
Anyways I guess as I have followed Zoras instructions, the adware is removed.
Thanks Zoras
ak
Hi there
ReplyDeleteHaving it removed is great. It took me several hours before I get to method II above. But clean also your USB keys! This malware replicate to USB using autorun.inf so everytime you connect your USB key, it is back (for some reasons, my avast does not block it entirely). Some hints:
. disable completely autorun
. on XP, stop working as administrator
Good luck
SD
I have the nissan.exe and will try these tips, thanks! I also have something called mic.exe and avast is not really doing anything about it! It's on my C drive as well as my USB sticks. HELP!
ReplyDeleteI got this file from another friend's pen drive.
ReplyDeleteAutoRun was disabled and opened using WinRar's browser. Was able to delete it from within WinRar, and booted from linux to scan for more malware on local NTFS drives.
Avast/AVG doesn't detect it. Kaspersky/NOD32/F-Secure does correct it though...
[I would Kill Explorer.exe if it wasn't needed]
Hello, I do not agree with the previous commentator - not so simple
ReplyDeleteEverything is very open with a very clear clarification of the challenges.
ReplyDeleteIt was truly informative. Your website is very helpful.
Many thanks for sharing!
my web page ... minecraft Giftcode
I was suggested this blog through my cousin. I'm now not sure whether this publish is written by means of him as no one else know such targeted about my trouble. You're wonderful!
ReplyDeleteThanks!
Feel free to visit my web blog - buy gems with coins dragonvale
We absolutely love your blog and find nearly all of your post's to be what precisely I'm looking for.
ReplyDeleteDoes one offer guest writers to write content for you personally?
I wouldn't mind producing a post or elaborating on a few of the subjects you write regarding here. Again, awesome web site!
Feel free to surf to my blog post ... food arts and crafts for kids
It's the best time to make some plans for the future and it is time to be happy. I have read this post and if I may I wish to recommend you some attention-grabbing issues or tips. Maybe you could write subsequent articles referring to this article. I desire to learn more things about it!
ReplyDeleteFeel free to visit my site - Fail Compilation 2012
certainly like your website but you have to check the spelling on several of your posts.
ReplyDeleteMany of them are rife with spelling problems and I find it very troublesome to
tell the truth on the other hand I will surely come again again.
Here is my web blog; videos of funny videos
What's up to every , for the reason that I am genuinely keen of reading this blog's post to be updated regularly.
ReplyDeleteIt carries pleasant stuff.
My web page; Refinance Appraisal
Link exchange is nothing else however it is only placing the other person's weblog link on your page at proper place and other person will also do same for you.
ReplyDeleteMy webpage - dragonvale computer game
Nice post. I was checking continuously this blog and I am impressed!
ReplyDeleteVery useful information specially the last part :) I care for
such info much. I was seeking this certain info for a long time.
Thank you and good luck.
Check out my blog: xbox 360 cheats
Hello everyone, it's my first visit at this site, and paragraph is in fact fruitful for me, keep up posting such posts.
ReplyDeleteFeel free to surf to my web blog; auto clicker for adfly
I really like what you guys are usually up too.
ReplyDeleteThis kind of clever work and exposure! Keep up the amazing works guys
I've you guys to blogroll.
Feel free to surf to my web page: Aimbot and Wallhack
You need to be a part of a contest for one of the most
ReplyDeleteuseful sites on the internet. I will recommend this site!
Visit my site: sharecash Downloader 2013
Hi there friends, its enormous piece of writing about tutoringand fully defined,
ReplyDeletekeep it up all the time.
Stop by my web-site: Free Playstation Network Cards
Genuinely no matter if someone doesn't be aware of after that its up to other users that they will assist, so here it takes place.
ReplyDeleteHere is my page: forgot my password
Sweet blog! I found it while surfing around on Yahoo News.
ReplyDeleteDo you have any suggestions on how to get listed in Yahoo News?
I've been trying for a while but I never seem to get there! Many thanks
Here is my website; google password hacking
We're a group of volunteers and opening a new scheme in our community. Your web site offered us with valuable information to work on. You've done a
ReplyDeleteformidable job and our whole community will be thankful to you.
my webpage - make extra cash
What i do not understood is in fact how you are not really a lot more smartly-liked than you may be right now.
ReplyDeleteYou are very intelligent. You recognize thus considerably when it comes to this topic, made me for my part consider it from numerous
varied angles. Its like women and men don't seem to be involved unless it's
one thing to do with Girl gaga! Your own stuffs nice. At all times maintain
it up!
My web site ... free Psn code
Hello to all, how is all, I think every one is getting more from this web page, and your views are
ReplyDeletepleasant designed for new people.
my website; play and get Minecraft for free
f9p88n8y01 t4n70y8t39 f0f32g9z85 d6o54a6j14 t4y94x5m90 b0m59i7b22
ReplyDelete