Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
Go to start > run and copy and paste next command in the field:
sc delete "SmartFinder_Uninstall"
Click ok
Use Add/Remove Programs and remove if listed: RazeSpyware
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
Close ALL windows and browsers except HijackThis and click "Fix checked"
Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.
Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.
When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.
C:\WINDOWS\System32\xxxdialer.exe
C:\WINDOWS\System32\popups.exe
C:\Program Files\RazeSpyware\RazeSpyware.exe
C:\Program Files\RazeSpyware\RazeSpyware_monitor.exe
C:\WINDOWS\System32\winapi32.dll
C:\WINDOWS\System32\shell386.exe
C:\Documents and Settings\suhail\Desktop\SFUninstaller.exe
Return to Killbox, go to the File menu and select Paste from Clipboard.
Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually
Restart your computer.
"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 12:53:47 PM, on 1/26/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
WOW dude. You are a genius!!!!!!!!!! Everything is almost perfect. My only problem is that I get these pop-ups once in a while. Thank you very much for your help!!!!!!!!!!!!!!!!
Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete. IMPORTANT: make sure to set the export range to ALL
Click "Start"> "Run"> type in Regedit tap Enter Key
Make sure "My Computer" is highlighted
Click "Edit"> "Find"
Type in keylogger32 tap Enter Key.
If found:
Right Click on the file and select "Delete"
Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.
Do the same for this file: porntrojan
Close Regedit.
Empty Recycle Bin
Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Logfile of HijackThis v1.99.1
Scan saved at 11:43:51 AM, on 1/27/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
The next step in this process is to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection. Click here: http://www.microsoft.com/windowsxp/downloa…p1/default.mspx
Apply the update, reboot, and post a fresh Hijack This log.
(DO NOT INSTALL SP2)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.