Hi gtaplin and welcome to TSF
Sorry for the delay getting to you, the forum has been really busy and all our helpers are volunteers.
Please print out or copy this page to
Notepad in order to assist you while carrying out the following instructions. This page will not be available to you at some points during the fix. Please read the instructions carefully before you begin and if you have any questions then post them here before continuing.
This process is not instant and may take several posts. Please ensure you continue with the instructions until you are told you are clear. Lack of symptons does not mean lack of malware.
Please make sure you close all other windows including browsers when carrying out the fix. It is important you carry out the instructions in the exact order stated.
-------------------------------------------------------
Downloads
Please download
SmitfraudFix (by
S!Ri) to your Desktop. We will use this later
Please download
ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only We will use this later
Download
AVG Anti Spyware
- Install AVG Anti Spyware
- Double-click the icon on Desktop to launch AVG
- On the top of the main screen click Shield
- Click the word active to change it to inactive
- On the top of the main screen click Update.
- Then click on Start Update. The update will start and a progress bar will show the updates being installed.
- Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
- Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
- Under "Reports"
- Select "Do not automatically generate report after every scan"
When you have finished updating,
EXIT AVG Anti Spyware. Do Not run a scan just yet, we will shortly.
-------------------------------------------------------
Show Hidden Files/Folders
Go to
My Computer >Tools >Folder Options >View tab and
select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside
Hide file extensions for known file types. Click OK.
-------------------------------------------------------
Safe Mode
Boot to
Safe Mode (by repeatedly tapping F8 until the menu appears)
-------------------------------------------------------
Fixes and Deletions
Scan with HijackThis and check the following entries (If they still exist) (make sure not to miss any)
O2 - BHO: MSVPS System - {31E3F653-ED88-4355-B83E-FB263CD355E3} - C:\WINDOWS\popnetnpr.dll
O3 - Toolbar: The jokwmp - {9E004C23-5424-4C79-BAFE-C2B3460ECB56} - C:\WINDOWS\jokwmp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\sol748.txt
O21 - SSODL: rmvgor - {77706740-2C2B-42BD-AAAE-C511A9235890} - C:\WINDOWS\rmvgor.dll
O21 - SSODL: sapnet - {436B4056-B5CE-421C-BB42-2D4DCC5BF162} - C:\WINDOWS\sapnet.dll
Remember to close all other windows and click Fix Checked
Delete the following
Files (if it still exists)
C:\WINDOWS\popnetnpr.dll
C:\WINDOWS\jokwmp.dll
C:\WINDOWS\rmvgor.dll
C:\WINDOWS\sapnet.dll
C:\WINDOWS\system32\sol748.txt
-------------------------------------------------------
Tools and Scanners
Double-click on
SmitfraudFix.exe to start the tool.
Select option
#2 - Clean by typing
2 and press
Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "
Registry cleaning - Do you want to clean the registry?" answer
Yes by typing
Y and hit
Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer
Yes to the question "
Replace infected file?" by typing
Y and hit
Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.
Reboot back into Safe Mode.
The tool will create a log named
rapport.txt in the root of your drive, eg: Local Disk C:
(C:\rapport.txt) or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
-------------------------------------------------------
- Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser- Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser- Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click
Exit on the Main menu to close the program.
For
Technical Support, double-click the e-mail address located at the bottom of each menu.
-------------------------------------------------------
Next go to Control Panel click
Display>Desktop>Customize Desktop>Web> Now,
Uncheck Everything and
delete if present:
- "Security Info"
- "Warning Message"
- "Security Desktop"
- "Warning Homepage"
- "Desktop Uninstall"
Empty the Recycle Bin by right-clicking the
Recycle Bin icon on your Desktop, and then clicking
Empty Recycle Bin.
-------------------------------------------------------
Run
AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click on the Scan tab
- Click Complete System Scan to begin scanning.
Once the scan is complete do the following:
- If you have any infections you will prompted, then select "Apply all actions"
- Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).
-------------------------------------------------------
Normal Mode
Reboot to Normal Mode
-------------------------------------------------------
Double-click on
SmitfraudFix.exe to start the tool.
Select option
#3 - Delete Trusted zone by typing
3 and press
Enter
Answer
Yes to the question "Restore Trusted Zone ?" by typing
Y and hit
Enter.
Note, if you use
SpywareBlaster and/or
IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
-------------------------------------------------------
1. Download
combofix to your desktop
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
-------------------------------------------------------
Run a new scan with dss.exe using the following procedure:
Click Start>Select 'Run' - then copy/paste the following text into the run box & click OK
"%userprofile%\desktop\dss.exe" /config
Click on
"Check All"
Click Scan!
When finished, it shall produce
main.txt and
extra.txt for you. Post those here in your next reply.
-------------------------------------------------------
Required Logs
C:\rapport.txt
AVG AntiSpyware report
C:\combofix.txt
main.txt
extra.txt (attached)