Is this your anti-virus program? mks_vir_2007
I can't find much information about it.
Download SmitfraudFix (by S!Ri) to your Desktop. http://siri.urz.free.fr/Fix/SmitfraudFix.exe
Double Click SmitfraudFix.exe on your Desktop. A folder named SmitfraudFix will be created on your Desktop.
[external image: Posted Image]
______________________________
Next:
Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.
If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
Click the Update icon at the top and under Manual Update click the Start update button.
The program will either update or inform you that no update was available.
It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
Click the Shield icon at the top and under Resident shield is… click active. This should now
change to inactive.
Click the Update icon and untick the automatic update option.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act? - make sure that Quarantine is selected.
Under How to scan? - All checkboxes should be ticked.
Under Possibly unwanted software - All checkboxes should be ticked.
Under Reports - Select Do not automatically generate reports.
Under What to scan? - Select Scan every file.
Close all open windows. Do not run a scan yet.
______________________________
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
[external image: Posted Image]
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:
c:\rapport.txt
IMPORTANT: Do NOT run any other options until you are asked to do so!
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Warning:running option #2 on a non infected computer will remove your Desktop background.
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Reboot your computer in Safe Mode.
If the computer is running, shut down Windows, and then turn off the power.
Wait 30 seconds, and then turn the computer on.
Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
Ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
Login on your usual account.
______________________________
Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
[external image: Posted Image]
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
Clean out your Temporary Internet files. Proceed like this:
Quit Internet Explorer and quit any instances of Windows Explorer.
Click Start, click Control Panel, and then double-click Internet Options.
On the General tab, click Delete Files under Temporary Internet Files.
In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________
Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
Select the "Scanner" icon at the top and then the "Scan" tab
then click on "Complete System Scan".
ewido will now begin the scanning process, be patient this may take a little
time.
Let the program scan your computer.
When the scan has finished, follow the instructions below:
Make sure that Set all elements to: shows Quarantine
Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
When the program has finished, it will display the message All actions have been applied.
Then click the Save Scan Report button.
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in normal mode and copy the report back to this topic along with a new HijackThis log.
Please post:
1.c:\rapport.txt
2.AVG Anti-Spyware log
3.A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Hi
I started to do what you told me, but i saw some process begining that im affraid may can delete some files from my computer. the process is called "cleaning up the disk and its regular windows program that removes files that are not used for a very long time. there is many such files on my pc but they can not be removed. whats the risk that this program will not remove this file from my computer?? should i run it despite the risk or u got some another advise??
hey man
weird thing - i didnt completed the hole cleaning process, but this pop - up dissapeared - wow!!
there seems to be no other problems except for the fact that i still can not install this adobe flash player, and some damages done earlier have to be removed - but i would like to make sure that everything is ok, so can u tell me what to do to check the hole computer and find out is it finnaly clean??
TiA
sinobrody
weird thing - i didnt completed the hole cleaning process, but this pop - up dissapeared - wow!!
there seems to be no other problems except for the fact that i still can not install this adobe flash player, and some damages done earlier have to be removed - but i would like to make sure that everything is ok, so can u tell me what to do to check the hole computer and find out is it finnaly clean??
TiA
sinobrody
Please watch with what you post. We are a family site.
I would suggest you follow the instructions I posted.
Hi
So far i dont see any problems with the Pc so we may say its fixed.
I would like to thank you for all your help and advices.
If anything bad happens in the future with my Pc i will know where should i go.
thanks once again
bye