Hello and welcome to
TSF
I am sorry to inform you that your computer may have been compromised. If this system is used for online banking or has credit card information on it, all passwords should be changed immediately by using a different computer (not the infected one!) to make the changes. Banking and credit card institutions, if any, should be notified of the possible security breech. I suggest that you read
this article too.
Download
SDFix and save it to your Desktop.
Double click
SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Do not scan yet.
=============================================
Please download
Ccleaner and save it to your desktop.
Tutorial for CCleaner
During the installation be sure to UN-check the box for "Ccleaner Yahoo Toolbar" unless you want it Do not use it yet.
=============================================
Download
AVG Anti Spyware.
Use the link at the bottom of the page under
"AVG Anti-Spyware Free for Windows"
- Install AVG Anti Spyware
- Double-click the icon on Desktop to launch AVG
- On the top of the main screen click Shield
- Click the word active to change it to inactive
- On the top of the main screen click Update.
- Then click on Start Update. The update will start and a progress bar will show the updates being installed.
- Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
- Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
- Under "Reports"
- Select "Automatically generate report after every scan"
- Un-Select "Only if threats were found"
When you have finished updating,
EXIT AVG Anti Spyware. Do Not run a scan just yet, we will shortly.
============================================
Make sure that you can see hidden files
· Click
Start
· Open
My Computer
· Select the
Tools menu and click
Folder Options
· Select the
View Tab
· Under the Hidden files and folders heading select
Show hidden files and folders
· Uncheck the
Hide protected operating system files (recommended) option
· Click
Yes to confirm
· Click
OK
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer.
**
=============================================
- Close all open Explorer windows and browsers/email, etc
- Run HijackThis
- Click on the Scan button and when complete
- Put a check beside all of the items listed below
- Click on the "Fix Checked" button
- When completed, close the application.
O2 - BHO: (no name) - {F0C1CE1C-E30F-48E8-B67A-A98AB9BD4767} - C:\WINDOWS\system32\mfcsubsd.dll (file missing)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Windows] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\RunServices: [Windows] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\RunOnce: [Windows] C:\WINDOWS\scvhost.exe
Exit HijackThis.
=============================================
Reboot your computer in
Safe Mode using the
F8 method below.
a. If the computer is running,
shut down Windows, and then
turn off the power.
b. Wait
30 seconds, and then
turn the computer
on.
c. Start
tapping the
F8 key. The Windows
Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
d. Ensure that the
Safe Mode option is selected.
e. Press
Enter. The computer then begins to start in
Safe mode.
=============================================
In safe Mode, using Windows Explorer (right click Start, click on Explore), navigate to the following
file and
delete it:
Safe Mode
C:\WINDOWS
\scvhost.exe <=== make sure of the
exact spelling and DO NOT delete the similarly named legitimate file
svchost.exe which is usually in System32 folder.
==============================================
From Safe Mode run
Ccleaner- Click on Options,
- Select Advanced
- Now UNCHECK "Only delete files in Windows Temp folders older than 48 hours"
- Make sure the Cleaner block on the left is selected.
- Do not use the "Issues" block . It's meant for professionals.
- Choose the Windows tab.
- Check everything EXCEPT Advanced part of the Menu.
- Click on "Analyze". This process could take a while.
- If you don't want to loose your login passwords to certain sites, click on Options
- Select cookies and move the ones you want to keep to the "cookies to keep" section, by highlighting and using the arrows in the middle.
- Choose Run Cleaner.
When CCleaner shows how much has been removed, cleaning is finished. Click
Exit.
If you have more than one users,
run Ccleaner for every user
==============================================
Still in Safe Mode:
IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
- Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
- Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
- AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
Once the scan is complete do the following:
- If you have any infections you will prompted, **Please ensure it is set to Quarantine then select "Apply all actions"
- Next select the "Reports" icon at the top.
- Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
- Close AVG Anti-Spyware.
**AVG Anti-Spyware is compatible with most AV and anti-spyware products, and the free version will continue to be useful as a second anti-malware scanner.
===============================================
Still in Safe Mode:
- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot in Normal Mode.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as rom Safe Mode run SDFix.
]- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
- Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
- Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
===============================================
Perform an online scan with Internet Explorer with
Panda ActiveScan
- Click on
located at the bottom of the page.
- A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
- Enter your e-mail address, country, and state & click "Free Online Scan" * The download of the 8 MB Panda's ActiveX control will take place *
Begin the scan by selecting

- If it finds any malware, it will offer you a report.
- Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
- Click on
then click 
===============================================
Please post back:
Fresh HijackThis log
AVG Anti Spyware log
Panda Scan log
SD Report.txt