Hello Socha_62,
Looks like it's you and me again.
Please copy this page to
Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out these instructions.
It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence.
***************************************************
Please
download SmitfraudFix (by
S!Ri) to your Desktop.
-----------------------
Download
AVG Anti Spyware
Use the link at the bottom of the page under
"AVG Anti-Spyware Free for Windows"

- Install AVG Anti Spyware
- Double-click the icon on Desktop to launch AVG
- On the top of the main screen click Shield
- Click the word active to change it to inactive
- On the top of the main screen click Update.
- Then click on Start Update. The update will start and a progress bar will show the updates being installed.
- Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
- Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
- Under "Reports"
- Select "Automatically generate report after every scan"
- Un-Select "Only if threats were found"
When you have finished updating,
EXIT AVG Anti Spyware. Do Not run a scan just yet, we will shortly.
***************************************************
Please reboot your computer in
Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Use the up arrow key to highlight Safe Mode and press Enter.
5)
Login with your usual account. Make sure to close any open browsers.
-----------------------------------
Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:
Seekmo Toolbar
-----------------------------------
Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist
(make sure you do not miss any)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll (file missing)
Click
'Fix Checked' and close HijackThis.
-----------------------------------
Go to
My Computer->
Tools->
Folder Options->
View tab:
* Under the Hidden files and folders heading:
*
select Show hidden files and folders.
*
Uncheck Hide protected operating system files (recommended) option.
*Also, make sure there is no checkmark beside
Hide file extensions for known file types.
* Click OK.
-----------------------------------
Using My Computer, navigate to and delete the following
Folder if it still exists.
C:\Program Files\Seekmo Programs
-----------------------------------
Double-click on
SmitfraudFix.exe to start the tool.
Select option
#2 - Clean by typing
2 and press
Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "
Registry cleaning - Do you want to clean the registry?" answer
Yes by typing
Y and hit
Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer
Yes to the question "
Replace infected file?" by typing
Y and hit
Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.
Reboot into Normal Windows.
The tool will create a log named
rapport.txt in the root of your drive, eg: Local Disk C:
(C:rapport.txt) or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
*WARNING* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp! or move them to a permanent location.
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "
Options..."
*Move the arrow down to "
Custom CleanUp!"
*Put a check next to the following:
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
- Click on the "Temporary Files" and uncheck the box for "Scan drives for file matching" if it's checked.
Click
OK
Press the
CleanUp! button to start the program.
Do NOT reboot/logoff when prompted.
______________________________
Next go to Control Panel click Display>Desktop>Customize Desktop>Web> Now,
Uncheck Everything and
delete if present:
· "Security Info"
· "Warning Message"
· "Security Desktop"
· "Warning Homepage"
· "Desktop Uninstall"
Also make sure the
'Lock desktop items' box is
unticked. Click OK, and then Click Apply, then OK.
______________________________
Empty the Recycle Bin by right-clicking the
Recycle Bin icon on your Desktop, and then clicking
Empty Recycle Bin.
______________________________
Close
ALL open Windows / Programs / Folders. Run
AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
- Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
- Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
- AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
Once the scan is complete do the following:
- If you have any infections you will prompted, **Please ensure it is set to Quarantine then select "Apply all actions"
- Next select the "Reports" icon at the top.
- Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
- Close AVG Anti-Spyware.
----------------------------------------------------
Reboot into Normal Mode.
----------------------------------------------------
Double-click on
SmitfraudFix.exe to start the tool.
Select option
#3 - Delete Trusted zone by typing
3 and press
Enter
Answer
Yes to the question "Restore Trusted Zone ?" by typing
Y and hit
Enter.
Note, if you use
SpywareBlaster and/or
IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________
Please run this online scan to search for any other files that may be lurking. It can take some time, so please be patient and allow it to run it's full course:
Perform an online scan with Internet Explorer with
Panda ActiveScan- Click on
located at the bottom of the page.
- A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
- Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting

- If it finds any malware, it will offer you a report.
- Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
- Click on
then click 
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
______________________________
Then post the following logs in your next reply...
c:\rapport.txt
AVG A/S log
Panda log
Hijackthis log