wat do i delete
14 min read
You will then need to extract the files.
To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "1" and then to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.
A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
IMPORTANT: Do NOT run any other options until you are asked to do so!
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Run HJT:
- Click Open the Misc Tools section.
- Click Open Uninstall Manager…
- Click Save list… and save it to your Desktop.
- Copy and paste the file uninstall_list.txt into your next reply.
Using capital letters in this way in a post is the equivalent of shouting and isn't going to endear you to too many people.ALSO I HAVE SOME SORT OF VIRUS THAT HAS AN ICON IN THE SYSTEM TRAY THAT WILL RANDOMLY POP UP A MESSAGE THAT SAYS CRITICAL SYSTEM ERROR YOUR SYSTEM HAS DETECTED VIRUS ACTIVITIES
DOWNLOAD ANTIMALWARE SOFTWARE TO FIX PARASITE PROGRAMS
WHEN I CLICK ON IT IT TAKES ME TO VIRUS BURST.COM
I GUESS BECAUSE VIRUS BURST ARE THE ONES THAT CREATED THE VIRUS
HOW DO I GET RID OF IT ???
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.
Preparation
1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.
* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -
Double click the avgas-setup file to begin installation and follow the prompts.ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:
Highly improved cleaning
Lower resource usage
Additional languages supported
All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.
When the program has been installed, and you click the Finish button, AVG A-S will open.
- Updating AVG Anti-Spyware:
By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following: - Click the Update icon at the top and under "Manual Update" - click the Start update button.
- Either AVG A-S will update or inform you that no update was available.
- If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
Once you have installed AVG A-S, double click ewido-signatures-full-current.exe to update it.
Disabling the Resident Shield:
- By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
(When the PC has been cleaned you can activate the shield again, if you wish.) - Click the Shield icon at the top and under "Resident shield is…" - click active.
- This should now change to inactive.
Changing Recommended Actions
- Click the Scanner icon at the top and then click the Settings Tab.
- Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.
2) Delete your old version and download a fresh copy of SmitfraudFix.zip by S!Ri from here and save it to your Desktop.
The fix is frequently updated and it is advisable to ensure that you have the latest version.
You will then need to extract the files.
To do this: Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish
Close the folder, you will need it later.
3) You will need to know how to boot into Safe Mode.
Instructions can be found here.
4) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **
5) Log off from the internet and disconnect your modem cable for the duration of the fix.
Removal
1) Boot into Safe Mode.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then to start the cleaning process.
- Wait for the tool to complete and disk cleanup to finish.
- You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then .
- The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then .
3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.
4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.
5) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.
6) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop… and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.
7) Empty the Recycle Bin.
8) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
- If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
- Click "Complete System Scan"
- While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
- When the scan has completed, any threats that AVG A-S has detected will be displayed.
- Click the Apply all actions button at the bottom.
- When AVG A-S has finished, it will display the message "All actions have been applied".
Saving a report:
- Click the Save Report button at the bottom left and the "Reports" window will open.
- The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
- You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
9) Reboot into Normal Mode.
10) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then .
* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *
Will you then post the following:
- A new HJT log,
- The AVG A-S log,
- The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:) - A description of how your PC is behaving.
Please go to Jotti's and click on the Browse… button at the top and navigate to the following file and then click on Submit:
C:\WINDOWS\system32\sxserv101.exe
When all the scans have been completed, please copy and paste the results into your next reply.
If this site is busy, try VirusTotal: Click the Browse … button at the top, navigate to the file and double click it and then click the Send button.
You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done. *
sc stop SXServ
sc delete SXServ
Save it to your Desktop with the following filename, including quotation marks: "filedelete.bat"
Simply double click filedelete.bat to run it and then you can delete it.
Run HJT and check that the following line has gone:
O23 - Service: SX Service (SXServ) - Unknown owner - C:\WINDOWS\system32\sxserv101.exe
As long as it has, you're done. I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:
Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.
The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!
Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI