How do i get rid of w32.myzor.fk@yf when scans say there is no virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by frustrated1, Aug 14, 2006.

  1. frustrated1

    frustrated1 Private E-2

    yesterday I had a message saying i had iworm_attck_v122.02a and we used spybot and mcafee scan (which seemed to get rid of it)but today it says we have this w32.myzor.fk@yf which will not go away. What do you recommend?
    Our computer is a Hewlett Packard Pavilion Intel(R) Pentium(R) 4CPU 3.40GHz 0.99 GB of Ram it operates on Microsoft Windows XP Home Edition Version 2002 Service Pack 2... Please Help I really do not know what is going on and have never had this happen before....

    I read up on info and downloaded hijackthis to get a log file. Please tell me if you need this scan or what other information I need to provide

    Thankyou
     
  2. frustrated1

    frustrated1 Private E-2

    I forgot to attach these earlier. They are a hijackthis log and a smitfraud fix log. Please help.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not look like you actually used SmitFraudFix to FIX the problem.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    Tell me what your current status is now.
     
  4. frustrated1

    frustrated1 Private E-2

    I think it is all cleared up, when I just came online my comcast home page is back up and the infamous toolbar with adware is gone. Here is my rapport log to look at just incase there is something else I need to do.

    Thank you, thank you, thank you for getting back to me and letting me know exactly what to do.....
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. frustrated1

    frustrated1 Private E-2

    Thank you again. I will make sure to follow the prevention steps so this won't happen again.

    Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds