Thread: spyware attack
View Single Post
Old 11-20-2008, 12:35 PM   #11
scotfan

Advanced Member
 
scotfan's Avatar
 
Join Date:
Mar 2008
Location:
Scotland
Posts:
191
Shouts:
0
Thanks:
108

Rep Power:
scotfan is on a distinguished road
Default

Do not try online banking or using cards online until fixed, most trojans have keyloggers.

This was the original post from bleepingcomputer:
I am at my wits end. Tried Spy Bot, Ad-Aware, Zone Alarm, Norton Anti-Virus and nothing is helping with the hijacked homepage, pop-ups and System Alert: Trojan-Spy.Win32@mx with the yellow triangle warning sign on the bar. Can some one help, please?!


Try this:
Download SmitfraudFix.exe from here and save it to your desktop

http://www.bleepingcomputer.com/files/smitfraudfix.php

You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".


The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows.


No guarantees that this will fix the problem but I do think its your best bet (it worked for the guy who sent in the question)

Good luck
scotfan is offline   Reply With Quote
The Following User Says Thank You to scotfan For This Useful Post:
BigBadSi (11-20-2008)