Hi,
You may print or save this Webpage to refer it while you are offline.
Download Ewido and install it. Run it, in the main screen, click "Update" and click "Start Update". After the update process, exit from Ewido.
Download CCleaner and install it. Do not run it now. Download KillBox and extract it to a folder.
Next, right-click on this link , click "Save file as" (or "Save target as") and save the file on Desktop with default filename (default name will be smitfraud.reg).
Make Windows to show all files:-
Go to Start > My Computer.
Go to Tools menu, click Folder Options. Uncheck Hide protected operating system files. Then, click to select the option Show hidden files and folders. Click Apply and then click OK to exit.
Reboot in Safe Mode:-
Restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter.
Uninstall this Software from Add/Remove Programs in Control Panel:-
WildTangent (There can be multiple WildTangent entries, remove them all!)
Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=presario&pf=desktop
F3 - REG:win.ini: run=C:\WINDOWS\inet20006\services.exe
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [alij] C:\WINDOWS\system32\run959.exe dummy
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20006\services.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20006\services.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.
Exit from HijackThis. Delete these folders:-
C:\Program Files\WildTangent
C:\Windows\wt
Run CCleaner, click "Options" button and here go to "Advanced" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours". Click OK to exit from the Options. Finally click "Run Cleaner" and click "OK" to continue cleaning.
Run Ewido, click on the "Scanner" button in the left menu, then click on the "Complete System Scan" button.
If ewido finds anything, it will pop up a notification. You can select "Clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
Double-click on the SmitFraud.REG file and click "Yes" to merge it to Registry.
Run Killbox.exe. First click on Tools>Delete Temp Files. A box will open with a list of all user profiles. Check the following boxes at a minimum for each profile by clicking on the drop down and checking the boxes that are enabled. Some will not apply and those boxes will not be available to check. Make sure you do this for all the profiles listed.
Temporary Internet Files
Temp Files
XP Prefetch
If you want to clean your cookies, history, and list of recent files run you may check those boxes as well.
Then, check on the Button titled "Delete Selected Temp Files". Exit by clicking the Button titled "Exit(Save Settings)".
Once back into the main Killbox program. Check the following boxes:-
Delete on Reboot
Highlight all the entries in the quote box below and then Copy them.
C:\WINDOWS\inet20006\services.exe
C:\winstall.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\spoolsrv32.exe
C:\WINDOWS\system32\run959.exe
Then in Killbox click File > Paste from Clipboard
At this point the "All Files" button should be enabled so you can click it. Click the "All Files" button.
Then click theRed X button and for the confirmation message that will appear, you will need to click "Yes". A second message will ask to Reboot now? you will need to click "Yes" to allow the reboot.
Note: Killbox will let you know if a file does not exist.
If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until the last one at which time you click yes to allow the reboot.
Reboot to Normal Mode. Run HijackThis again, click Do a System scan and save log, and post the fresh log along with the Ewido log.