Please print the below instructions or copy them to Notepad.
Restart your computer and boot into Safe Mode (if you don't know how, go to
http://www.bleepingcomputer.com/foru...howtutorial=61 ). Make sure to close any internet browsers that may still be open.
Uninstall the following via the Add/Remove Panel (Start->Settings->Control Panel->Add/Remove Programs) if found:
FunWebProducts
MyWebSearch
Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one:
O1 - Hosts: 67.15.104.65 auto.search.msn.com
O1 - Hosts: 67.15.104.65 auto.search.msn.es
Locate the following Files/Folders and delete them if they exist (if no location given, just do a search for them):
C:\WINDOWS\SYSTEM32\ncompat.tlb
C:\PROGRAM FILES\FunWebProducts
C:\PROGRAM FILES\MyWebSearch
Restart and run a new HijackThis scan. Save the log file and post it here.
Download SmitfraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix.zip and extract the content (a folder named SmitfraudFix) to your desktop.
Open the SmitfraudFix folder. Double-click on smitfraudfix.cmd and select option #1 - Search by typing 1 and press 'Enter'. A text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply.
IMPORTANT: Do NOT run option #2 or any other option until you are directed to do so!
Note: process.exe is detected by some antivirus programs as a 'Risk Tool'. It is not a virus. If you get this detected, ignore it.