HELP... With W32.Myzor.FK@yf

Discussion in 'Windows - Virus and spyware problems' started by O38marvin, Sep 12, 2006.

  1. O38marvin

    O38marvin Member

    Joined:
    Sep 12, 2006
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Hello Everyone.... I know that is problem has come up alot that I've seen, but I don't know anything about the computer. I've tried but I don't know what to do. Can someone please help me....
     
  2. O38marvin

    O38marvin Member

    Joined:
    Sep 12, 2006
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Of course the problem is the

    W32.Myzor.FK@yf

    message whenever I go online.......Please Please Help....
     
  3. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26

    Download http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Extract the content (a folder named SmitfraudFix) to your Desktop.


    Copy these instructions to NotePad for reading while in Safe Mode

    Reboot your computer in Safe Mode by doing the following :

    * Restart your computer
    * After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    * Instead of Windows loading as normal, a menu with options should appear;
    * Select the first option, to run Windows in Safe Mode, then press "Enter".
    * Choose your usual account.

    Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

    A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.

    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    Warning: running option #2 on a non infected computer will remove your Desktop background.



    Post the C:\rapport.txt and a new HJT log in your next reply.
     
  4. O38marvin

    O38marvin Member

    Joined:
    Sep 12, 2006
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Ok this is what came up..... What does it mean

    SmitFraudFix v2.87

    Scan done at 22:00:52.43, Tue 09/12/2006
    Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
    C:\Program Files\Media-Codec\ Deleted
    C:\Program Files\Virus-Burst\ Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

     
  5. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    That is the malware removed from your computer. Download hijackthis
    .Do a system scan and save a logfile. copy paste that log here to see if anything remains.
     
  6. nzhuhu

    nzhuhu Guest

    Thank you
     

Share This Page