Please copy this set of instructions or print it out as you will not have internet access during the fix.Restart the computer in Safe Mode[*]When you see the BIOS screen, start pressing F8.
[*]A boot menu will appear shortly.
[*]Using the up down arrows, select Safe Mode and press the Enter key.
[*]Windows will now load.
[*]Log in to your usual account.
Once in Safe Mode, double-click on
SmitfraudFix.exe.
Press
2 and press
Enter to delete infected files.
You will be prompted: "Registry cleaning - Do you want to clean the registry ?"; press
Y and press
Enter in order to start cleaning the cleaning process. Your desktop will be gone for a while cleaning.
The tool will now check if
wininet.dll is infected. You may be prompted to replace the infected file (if found); press
Y and press
Enter.
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart manually into Normal mode.
A text file will appear onscreen, with results from the cleaning process; please copy and paste the contents of that report into your next reply.
The report can also be found at the root of the system drive, usually at
C:\rapport.txtNote to other users: Running option 2 on a clean machine will remove your desktop background.In your next reply, please post back a new HijackThis log and the contents of C:\rapport.txt.