Hello
_net and welcome to
Malware Removal!
Before we begin to remove the malware on your computer, we need to move HijackThis from the Temp folder as it will get deleted at some stage and backups will be lost. We do not want that.
Click here to download HJTsetup.exe. Save it to your Desktop!
- Double click on the HJTsetup.exe icon on your desktop.
- By default it will install to C:\Program Files\Hijack This.
- Continue to click Next in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
- Put a check by Create a desktop icon then click Next again.
- Continue to follow the rest of the prompts from there.
- At the final dialogue box click Finish and it will launch Hijack This.
- You can close HijackThis
- Please use this HijackThis from now on.
_______________________________
There is a lot of work to do. Please take your time when working through the instructions. I suggest you read through them once and make sure you understand what you need to do.
Lets begin with the fix...
I don't see any indication of a Firewall in your HijackThis log. This may be because:
(1.) You are using Windows Firewall or a hardware Firewall.
(2.) You are using a Firewall of an unknown vendor.
(3.) You are using a Firewall, but it is disabled for unknown reasons
(4.) You don't use any firewall at all.
In the case you don't have a Firewall, please download
one from the list below -
They are Free!
Zone Alarm << I recommend this
Sunbelt Kerio PF
Outpost Firewall
Likewise, I don't see an Anti-Virus installed. Please download
one from the list below -
They are Free!
AVG Free Edition << I recommend this
AntiVir
avast! 4 Home Edition
_______________________________
Thanks for downloading SmitfraudFix and producing a log. It has found some infections, so lets get them removed.
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Next, please reboot your computer in
Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Select the first option, to run Windows in Safe Mode, then press "Enter".
- Choose your usual account.
Once in Safe Mode, double-click on
SmitfraudFix.exe
Select option #2 -
Clean by typing
2 and press "
Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing
Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if
wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing
Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at
C:\rapport.txt
Warning : running option #2 on a non infected computer will remove your Desktop background.
_______________________________
You also have a WareOut infection. Do the following to remove it...
Please download FixWareout from one of these sites and save it to your desktop:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe
- Double click Fixwareout.exe to run it.
- Click Next, then Install.
- Make sure Run fixit is checked and click Finish.
- The fix will begin; follow the prompts.
- You will be asked to reboot your computer; please do so.
- Your system may take longer than usual to load; this is normal.
- At the end of the fix, you may need to restart your computer again.
- A report.txt file will be created in the C:\fixwareout folder. Please keep it safe as I'll need to see it soon.
Now lets check some settings on your system.
(2000/XP) Only
- Click Start > Connect to > Show all connections.
- Right click on your default connection, usually local area connection for cable and dsl.
- Left click on Properties.
- Click the Networking tab.
- Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically.
- Press OK twice to get out of the properties screen and reboot if it asks. (That option might not be avaiable on some systems).
Next!
- Click Start > Run type cmd and hit OK.
- Type ipconfig /flushdns then hit enter, (Note: there is a space between ipconfig and /flushdns).
- Type exit hit enter.
_______________________________
I need to see another log from HijackThis.
- Run Hijackthis.
- Click on Open the Misc Tools section.
- Next click on Open uninstall manager.
- Press the Save list button.
- Save the file to your desktop, with the default name of uninstall_list
- Copy & Paste the entire contents of that file in your in your next post.
_______________________________
Please post the following...
1) Contents of C:\
rapport.txt
2) FixWareout report
3) Uninstall list
4) New HijackThis log