
![]() ![]() |
Sep 5 2007, 06:55 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 1 Joined: 5-September 07 Member No.: 72,673 Operating System: Windows XP |
This post has been edited by Omi23: Sep 5 2007, 07:00 PM
Attached File(s)
|
|
|
|
Sep 7 2007, 04:48 PM
Post
#2
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,143 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 RC |
Hi Omni23 and welcome to the forums.
My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
Okay let's get on with the fix. Definitely looks like Smitfruad. When you post back make sure to include a HijackThis log next time. Thanks Please copy the fix to Notepad/Word, or print it, because you won't always have internet access! Step 1: Download AVG Anti-Spyware Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder. http://www.ewido.net/en/download/
AVG Anti-Spyware manual updates. Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update. IMPORTANT! Do not scan yet with AVG Anti-Spyware! We will do this later. Step 2: Boot into Safe Mode Reboot your computer in Safe Mode.
Double-click on SmitfraudFix.exe Select option #2 - Clean by typing 2 and press Enter. Wait for the tool to complete and disk cleanup to finish. You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter. The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter. A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode. The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply. Step 4: Delete Temporary files Navigate to C:\Windows\Temp Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin. Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin. Clean out your Temporary Internet files. Proceed like this: Quit Internet Explorer, all browsers and quit any instances of Windows Explorer. For Internet Explorer 7
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin. Step 5: Run AVG Anti-Spyware Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
It'll automatically switch to Normal Mode. Step 7: Post logs Please post:
|
|
|
|
Sep 14 2007, 06:43 PM
Post
#3
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,143 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 RC |
Hi,
How are you making out here? Let me know. Thanks, Dave |
|
|
|
Sep 19 2007, 05:40 PM
Post
#4
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,143 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 RC |
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
23 | cklenertz | 363 | Today, 02:15 PM Last post by: Tomk |
|||
![]() |
2 | Havoc | 66 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | Ticker | 307 | Yesterday, 03:59 PM Last post by: LDTate |
|||
![]() |
2 | valhuse | 91 | Yesterday, 03:59 PM Last post by: LDTate |
|||
|
Time is now: 21st November 2009 - 04:14 PM |