We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

DriveCleaner - why?

2456

Comments

  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    no, you should be able to run both in safe mode ??

    try this first

    http://www.virusvault.co.uk/fusionbb/showtopic.php?tid/81/

    How to remove Smitfraud Trojans

    Credits: S!Ri

    You can download the "Plain Text Smitfraud Instructions" by right-clicking the attachment at the foot of this page and choosing "Save as" or "Save link as" depending on your browser.


    step1.gif Download SmitfraudFix by S!Ri from either of these mirrors to your desktop:

    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    http://siri.geekstogo.com/SmitfraudFix.zip

    Right click SmitfraudFix.zip and Extract (unzip) the SmitfraudFix folder inside to your desktop.


    step2.gif Open the SmitfraudFix folder and double-click smitfraudfix.cmd

    Folder.jpg


    Select option #1 - Search by typing 1 and press "Enter".

    cmd246.gif


    A text file will appear
    Save this report somewhere convenient


    step3.gif After saving the Option 1 log file, please restart your computer in Safe Mode by doing the following:


    Once in Safe Mode, open the SmitfraudFix folder on your desktop and double-click smitfraudfix.cmd again.

    Select option #2 - Clean by typing 2 and pressing "Enter" to delete the infected files.

    You will then receive the following prompt:

    "Registry cleaning - Do you want to clean the registry ? (y/n)"

    Type Y for yes and press "Enter" to remove the Desktop background and clean the associated registry keys for this infection.

    The tool will then check if the file wininet.dll is infected.

    You may be prompted to replace the infected file with another copy from your machine (if found):

    "Replace infected file ? (y/n)"

    Type Y for yes and press "Enter" to restore a clean copy of the file on your machine.

    Restart your computer to complete the removal process.

    A log file of the fix can be found at the root of your system drive, usually at C:\rapport.txt
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    browntoa thank you for being patient. I got as far as registry cleaning, but when I clicked y/enter a message came up saying administrator cant open registry (or something similar). btw, I ran the avg spyware on ordinary anyway, but did no good! the bl**y drivecleaner thing is still there!
    cheers
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I take it you have an adminstrator user profile ??

    try logging on to the admin user that appears when you log on to safe mode
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    Good evening Browntoa

    I've just logged onto safemode using administrator, and the smitfraud folder isn't on the desktp! I checked back in ordinary mode and tried to copy it across, but it won't work. How can I get the folder there? It's there when I log on as homeuser, but administrator won't let me proceed.
    Thank you
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    save te file to a location you know , my documents or soemthing, then navigate to the file to run it

    can you run spybot or anything from Admin ??
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    I'm not sure if spybot was there, I'll check when I go to safemode. Do i have to shut down for 30 secs every time I use safemode? Can I open my docs from safemode then?
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    yes, you can navigate like normal but you cannot access the internet etc

    no need to wait 30 seconds
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    Do I need to unplug? the plug is only JUST in my reach behind the desk!!
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    no need to unplug
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    Well, I got as far as clean registry again, no admin message so I did that right (!) but then after I clicked enter nothing happened. It seemed like everything froze. Shut down and started again, still wouldn't do it. I did get a strange little window saying it was checking for space on c drive, but i got rid of that. I'm following these instructions really carefully. Can you help any more browntoa? please? btw spybot wasn't on desktop, avg was. i think i saw spybot somewhere whilst i was looking for the smitfraud.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.1K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245.1K Work, Benefits & Business
  • 600.7K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 258.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.