Try doing the following
I need you to download a couple tools
First, Download and save to your desktop
[color=\"red\"]SmitfraudFix[/color][/url] (by
S!Ri)
Extract the contents (a folder named
SmitfraudFix) to your Desktop.
We'll need this later
Download this file -
Combofix.exe and save it ONLY to your desktop
Don't run it yet
Reboot your computer in
Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual account.
In safe mode
Open the
SmitfraudFix folder and double-click
smitfraudfix.cmdSelect option #2 -
Clean by typing
2 and press "
Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing
Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if
wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing
Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process;
I'll need to see the log it generates later, by default it is located at
C:\rapport.txt============================================
If your computer was rebooted, afterwards return to Safe mode
If no reboot was required, remain in safe mode
Double click on
ComboFix.exe to run the program
Follow the prompts
normally this fix takes anywhere from 10 to 30 minutes
If the computer was rebooted by the fix
ComboFix will run again, then continue to create a log, this can take a few minutes
Let it run uninterrupted please
I'll need to see this log later
By default, it saves a copy of the log at this location>>C:\
combofix.txtNote:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Try and post back all the following
1. Post the log from combofix>>C:\ComboFix.txt
2. Post the log from Smitfraudfix>>C:\Rapport.txt
3. Try to run a fresh scan and save logfile with Hijackthis and post it's log