Remove AntiVirus Pro and Hijacking Malware

This post was written by admin on August 23, 2009
Posted Under: Removing Desktop Hijacking Malware,SmitFraudFix

Removing Antivirus Pro, Antivirus 2009, Antivirus 2010, Personal Defender 2009, Advanced Antivirus, Advanced Virus Remover,MS AntiSpyware 2009, Save Soldier and many other recent Desktop Hijacking malware and rogue applications can easily be done using SmitFraudFix.

You may want to print these instructions to follow them through.

  • Download and save SmitFraudFix.exe to your desktop.
  • Restart your computer in Safe Mode, keep tapping the F8 key as you reboot and use the Up and Down keyboard arrows to highlight Safe Mode and then press Enter. It will take a short while as Safe Mode launches. Once the desktop appears, double click on the SmitfraudFix.exe on your desktop.
  • A Command prompt window (cmd) will open and you will see a menu. Select option number 2, which is ‘Clean (safe mode recommended)’, and then press Enter to delete infected files.
  • SmitFraudFix will begin cleaning your computer and carry out a series of cleanup processes. When the process is over, it will automatically begin the Disk Cleanup program.
  • Once the Disk Cleanup program is complete, you will be prompted with ‘Do you want to clean the registry?’ Type Y and again hit Enter to remove the Desktop background and clean any registry keys that are associated with this infection.
  • The tool will then check to see if winnet.exe is infected. If it is you will be asked if you want to replace infected file? Type Y and again hit Enter to restore a clean file entry to the registry.
  • Once the registry has been cleaned the main menu will appear along with the Rapport.txt file, close the notepad file and press Q on your keyboard to quit the program.
  • Reboot your computer to complete the cleaning process and again boot into Safe Mode.
  • After reboot, a Notepad screen may appear containing a log of all the files removed from your computer. If it doesn’t appear, a file will be created called rapport.txt in the root of your drive, (Local Disk C:).
  • You then need to clean the Temp Folders.
  • Go to C:WindowsTemp, double click to open, click Edit and Select All, press Delete, and then click Yes to confirm that you want all the items to go to the Recycle Bin.
  • Go to C:Documents and Settings[Named User]temp, double click to open, click Edit, Select All, press Delete, and then click Yes to confirm that you want all the items to go to the Recycle Bin.
  • Go to C:Documents and Settings[Named User]Local SettingsTemp, double click to open then click Edit, then Select All, press Delete, and then click Yes to confirm that you want all the items to go to the Recycle Bin.
  • Reboot your computer back to normal mode. Go to Windows Update and download all critical updates.
  • If using Spybot Search & Destroy you will need to Immunize, and if using any Hosts File you will need to import them again.
  • If your homepage has been changed, go to Start > Control Panel > Internet Options > click on General > click Use Default under Home Page. Add your preferred default homepage and click Apply, then click OK. Open a new web browser to check that you have your preferred default homepage.

Download SmitFraudFix v2.423 here

Requirements:
Windows 2000 / XP / Vista

Related post:
TDSS, TDSServ and Other Rootkit Removal

AddThis Social Bookmark Button

WOT Logo

Surf Safer, Surf with WOT….Click Here

, , , , ,

Vote this page

topvotes.appspot.com

Add a Comment

required, use real name
required, will not be published
optional, your blog address

IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)

What is 13 + 13 ?
Please leave these two fields as-is:
CommentLuv badge
Please leave these two fields as-is:

Protected by Invisible Defender. Showed 403 to 11,628 bad guys.

Next Post:
Get Adobe Flash playerPlugin by wpburn.com wordpress themes