Hi CamwynF,
Before beginning the proposed fix, read this post completely. Any questions should be kindly asked before proceeding. Ensure that there are no open browsers when carrying out the procedures below. Save the following instructions in Notepad as this webpage would not be available when you're carrying out the fix.
It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.
--------------------------------------------------------------
- Please download SmitfraudFix to your Desktop. Do not run it yet. We will shortly
- Restart your computer in Safe Mode
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8
- Instead of Windows loading as normal, a menu should appear
- Use the up arrow key to highlight Safe Mode and press Enter.
- Login with your usual account
- Once you have logged in, a warning message will appear regarding starting windows in Safe mode, click OK and windows will load your desktop environment
Note: Some systems, this may be the F5 key, so try that if F8 doesn't work.
- Double-click on SmitfraudFix.exe to start the tool.
- Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
- You will be prompted : "Registry cleaning - Do you want to clean the registry?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot into Normal Windows.
- The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: (C:\rapport.txt) or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
- Next, go to Control Panel click Display>Desktop>Customize Desktop>Web> Now, Uncheck Everything and delete if present:
· "Security Info"
· "Warning Message"
· "Security Desktop"
· "Warning Homepage"
· "Desktop Uninstall"
Also make sure the 'Lock desktop items' box is unticked. Click OK, and then Click Apply, then OK.
- Restart your computer in Normal Mode
--------------------------------------------------------------
- Double-click on SmitfraudFix.exe to start the tool.
- Select option #3 - Delete Trusted zone by typing 3 and press Enter
- Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.
Note: if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
--------------------------------------------------------------
Delete your old copy of ComboFix and download a new copy.
- Download combofix.exe to your desktop.
- Disconnect from the internet....pull the plug!
- Disable your real time protection of your Anti-Virus. Exit the program via the SystemTray icon.
- Double click on combofix.exe & follow the prompts. Type "1" and press Enter to begin the scan.
- When finished, it shall produce a log for you ( C:\ComboFix.txt ). Post that log in your next reply.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
--------------------------------------------------------------
- Re-enable your Anti-Virus if it is not active...a reboot should have re-activated it.
- Re-establish an internet connection.
- Open HijackThis and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.
--------------------------------------------------------------
Please download
HijackThis. This program will help us determine if there are any spyware/malware on your computer. Double-click on the file you just downloaded. Click on the "
Install" button. It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Double click on HijackThis.exe to run the program.
1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Post the hijackthis.log file here. Do not fix anything in HijackThis since they may be harmless.
--------------------------------------------------------------
Please reply back with the following logs:
C:\rapport.txt
C:\ComboFix.txt
HiJackThis log