(Don't worry if you don't have the same symptoms. Just run Smitfraudfix and come back. It creates a log at C:\rapport.txt. Please post that in your reply.)
Please then reboot your computer in
Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
In Safe Mode, right click the SDFix.zip folder and choose Extract All,
Open the extracted folder and double click RunThis.bat to start the script.
Type Y to begin the script.
It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
RKinner
2 Intern
•
5.9K Posts
0
January 30th, 2007 12:00
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels88.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\srpjgilg.dll",setvm
O4 - HKCU\..\Run: [nodht] C:\WINDOWS\system32\rbsosi.exe reg_run
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
but they probably won't go away easily. Each one pretty much needs its own removal tool. Let's start with the easy ones and see how they do.
Get lspfix from here
http://cexx.org/LSPFix.exe
Save it to your desktop then run it. Click on I know What I am Doing then find all instances of
newdotnet6_38.dll
in the left Pane then highlight and click on the arrow to move it to the right pane. Then Click on FINISH.
Please then reboot your computer in Safe Mode by doing the following :
Ron