First off, download ATF Cleaner and delete all temporary files where malware can hide. Make sure you set your Windows Explorer to show all hidden system files before you run ATF.
Update your antivirus. If you do not have one, download and install AVG or Avast!. They are free.
Also install and update:
1. Ad-Aware SE
2. Spybot Search and Destroy
3. Windows Defender (free from Microsoft)
4. Microsoft Malware Remover (free also)
5. SpywareBlaster
6. Ewido
7. Google Toolbar
8. McAfee SiteAdvisor
9. Firewall like Comodo Personal Firewall or Sygate Personal Firewall
10. CWShredder - there are 2 versions. Make sure you install both the last Merijn version and the latest version from TrendMicro.
11. About:Buster
12. HijackThis
13. WinsockXPFix - to be used only when no matter what you do you still can't connect to the Internet.
14. Opera browser - use this instead of IE (Internet Explorer) unless you are updating Windows or doing online banking or visiting sites that refuses to render correctly in Opera.
15. SmithFraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php
Platforms supported: WinXP, Win2K
This tool removes Desktop Hijack malware:
Smitfraud
Win32.puper
AVGold
Security iGuard
Spyware Vanisher
quicknavigate.com
updateSearches.com
startsearches.net
Virtual Maid
SpySheriff
PSGuard
SpyAxe
WinHound
AlphaCleaner
AdwarePunisher
SpywareQuake
For info on how to use this utility and how to install it, go to the link above.
I would not suggest turning off System Restore while you're in the process of cleaning your system. Sometimes while getting rid of malware something unexpected can go wrong that you need to use one of those restore points. And if you turn System Restore off you have no restore points to go back to. Don't worry about viruses/malware in System Restore if there any. They can not harm your system because they are NOT ACTIVE while in a Restore Point. They will only become active if and when you use that particular infected restore point. The best time to clean the viruses in your restore points is when your system is running problem-free and no risk of messing up. All you have to do is turn the System Restore off, reboot, and viruses in there will be gone.
Download sites
Use these URLs to download the latest version (the file contains both English and French versions):
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
http://siri.geekstogo.com/SmitfraudFix.php
Mirrors: Alternate official download locations for Smitfraudfix.zip
http://siri.geekstogo.com/SmitfraudFix.zip
Zebulon.fr
Extract the content (a folder named SmitfraudFix) to your Desktop.
Next, reboot your computer in Safe Mode by rebooting the computer, & repeatedly tapping the F8 key as the PC starts. Choose "Safe Mode" from the options listed.
Once in Safe Mode, open the SmitfraudFix folder again & doubleclick "smitfraudfix.cmd".
Select option 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
Select option 2 - Clean by typing 2 and press "Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry?"
Answer "Yes" by typing Y and press Enter in order to remove the Desktop background & clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press Enter.
The tool may need to restart your PC to finish the cleaning process; if it doesn't, reboot it in Normal Mode.
Screenshots
http://siri.urz.free.fr/Fix/ScreenShot.php
Update all the above programs RIGHT AFTER YOU INSTALL THEM.
All the above are FREEWARE. All of them are easily Googleble.
Reboot to Safe Mode and run your antivirus, #1-4, 6, 10 (both versions) & 11.
Reboot in Normal Mode. Run HijackThis (or HJT for short). DO NOT REPAIR OR FIX anything that it will list in its scan log. Just copy the whole log.
Register for free at MCH Forums:
http://mycomputerheadaches.tz4.com
After you register, post your HJT scan log at the above site, specifically at the System Security Forum. Precede your posting with a detailed description of your problem. And use a descriptive subject line. For example:
WinXP: Yahoo Messenger infection
Be patient. OJ, our resident HJT expert, has a life outside of his cyberlife. So just wait until he responds. Do read all the postings at the Announcements Forum to follow what you need to do as an MCH member.
I strongly recommend that you back up the registry before making any changes to your Registry. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. For instructions on how to make a backup of the Windows registry:
How to back up Windows Registry
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/199762382617?OpenDocument&src=sec_doc_nam
Note: If the Registry Editor does not open, the worm has made changes to the registry that prevent it from running. To fix this, download and run the Tool to reset shell\open\command registry keys, which also fixes this problem:
http://www.symantec.com/security_response/writeup.jsp?docid=2004-050614-0532-99
Kill2Me
Current version: 1.11
Freeware
Platform supported: All Windows
http://www.spywareinfo.com/~merijn/downloads.html
A removal tool specifically for the Look2Me (L2M) varieties of adware parasite. This tool removes versions 115, 116, 117 118, 120, 121 and 122 (the most recent ones) on all Windows versions. Kill2Me comes as an EXE file that require no installation, although it needs some Visual Basic 6 libraries which should already be present in all modern Windows machines. Running Kill2Me is extremely straightforward and will not be covered in detail here; just make sure you're running its latest version, since it is constantly updated, & make sure that all of your Windows Explorer & IE windows are closed when you run it, or else it may not be able to fix everything that needs fixing.
Look2me can be difficult to remove, but they do offer their own removal tool located here.
Download links
http://www.majorgeeks.com/download4166.html
http://download.bleepingcomputer.com/Merijn/kill2me.zip
KL-Detector
Current version: v1.3
http://www.dewasoft.com/privacy/kldetector.htm
Freeware
Platform supported: For Win2000 and WinXP. Win95/98 & Me are not supported.
This is a unique program that is able to detect keylogging activity on your computer. It is designed to be able to detect ALL keyloggers. Use KL-Detector to find out whether your activity is being recorded without your knowledge.
Some quick facts about KL-Detector
It should work under Windows NT 3.51 SP3, Windows 2000, and Windows XP.
No installation is necessary.
It cannot detect hardware keylogger. Well, no software can.
It cannot remove the keylogger automatically. You have to do it by yourself.
It reports the log file. If there is a log file, there should be a keylogger.
It might be called anti-keylogger, but I don't like that name. It detects keylogger, hence the name is KL-Detector.
It was written by a hobbyist programmer. So when I say it's free, it's really free
How does KL-Detector work?
It works by scanning your local hard disk for any log file created during the monitoring process. Most keyloggers will eventually save the recorded data into a location in the hard disk. KL-Detector will inform you of such log file. This way, the program can detect all keyloggers, both known and unknown. Use KL-Detector to detect keylogger in public computer before you enter your password, credit card info, etc.
I have found a log file. What should I do?
Sometimes KL-Detector will give a false positive; that is, when a normal file is perceived as a log file. So please ensure that the reported file is a log file. If it is, that means a keylogger is installed on your system. Check the startup items and eliminate suspicious program. XP users: press Ctrl-Alt-Del and review all processes. Of course, adequate computer knowledge is required to remove the keylogger from your system...
You have the latest qoologic infection.
The bad thing about this infection is that we have to get all the files in one shot, ohterwise it respawns immediately.
1) Download http://www.bleepingcomputer.com/files/winpfind.php
Extract WinPFind.zip to your c:\ folder.
Reboot your computer into Safe Mode by tapping the F8 key just before Windows starts to load.
Then open c:\WinPFind and double-click on WinPFind.exe. When the program is open, click on the Start Scan button to scart scanning your computer. Be patient as this scan may take a while. When it is done, it will show a log and tell you the scan is completed. Reboot your computer back to normal mode and and post the contents of c:\WinPFind\WinPFind.txt as a reply to this topic.
2) Please download FindQool by LonnyRJones:
http://downloads.subratam.org/Lon/FindQool.zip
* Extract the files and place the FindQool folder in root. Usually C:\
* Open the folder and run Qlocate.bat.
* Post the contents of the txt.log which will open.
3) Download F-Secure Blacklight (blbeta.exe) to your C:\ drive.
- Open a command window. (Start>Run and type: cmd)
- Copy paste or type the following in the command window:
C:\blbeta.exe /expert
- Accept the user agreement.
- Click Scan.
After the scan finishes, click on Next, then Exit.
Our sister Yahoogroup is:
MCH Yahoogroup
http://mch.tz4.com