smitfraud removal...wiped out explorer.exe...HELP

Discussion in 'Malware Help (A Specialist Will Reply)' started by mamabear0917, Jan 19, 2007.

  1. mamabear0917

    mamabear0917 Private E-2

    I read the read me first and printed it out, I am on another computer. I ran smitfraud removal but I hit dump something or other first and now when I start my computer in ANY mode it says..Explorer.exe..unable to locate component WININET.dll. Reinstalling is recommended. When I hit the dump button I was in safe mode but apparently that did not help. Any suggestions would be greatly appreciated.
    :cry
     
  2. mamabear0917

    mamabear0917 Private E-2

    P.S. I can't post logs due to having the blue screen of death. I still am missing WININET.dll. Should I download and re-install...not sure what WININET.dll is. Any help is greatky appreciated.
    Mamabear
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You did not even tell us your Windows OS!

    Sometimes there are other copies of wininet.dll on your PC that can be used to restore from. You may find one in a folder name i386 but it may be a compressed form named wininet.dl_ The underscore is because it is compressed and would need to be expanded. You can also get a copy from your Windows CD. Or you may be able to use one downloaded from a site like below:

    http://www.dll-files.com/dllindex/dll-files.shtml?wininet

    The file belongs in c:\windows\system32 or c:\winnt\system32 depending on how you installed you Windows software and what OS you have too.
     
  4. mamabear0917

    mamabear0917 Private E-2

    I'm so sorry about that, I'm very flustered over this...My OS is Windows XP. I bought this computer at Circuit City and all the components were already installed. Not even sure if I received a Windows CD with the computer. I downloaded wininet.dll to a CD but it is zipped and won't install because I get a blue screen. When I hold down ctrl alt del I get the task manager and it shows all the running processes so I know the stuff is still there somewhere. Thank you again for your help!!:eek:
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to extract it from the ZIP file on another PC first. Then copy it into the C:\windows\system32 folder of your PC.

    You should check to see if you have a Windows XP boot CD and if not, tell Ciruit City you want one! You may need this CD to boot to the Recovery Console in order to fix your problem.
     
  6. mamabear0917

    mamabear0917 Private E-2

    Somehow, through the task manager we were able to restore windows and the icons. The message WININET.dll is no longer popping up. I am currently running the scans on the computer. I have a hijack this file, runtext files and smitrem files. I tried doing panda scan and kaspersky and the active x would download but neither would scan. Scanned using Ad-aware. I am no longer getting the balloon in the lower right hand corner saying my computer in infected. I wanted to update you on what has occurred before I post the logs. Spy Bot found PestTrap, Smitfraud.c, SpySheriff, Microsoft Windows.Active Desktop, Microsoft Windows.Explorer. When I rebooted in normal mode, Norton informed me that something was attempting to change my homepage from comcast.net to msn.com. I did not allow the change. I am at work and when I get home I will post the logs. Thank you so much for being patient with me.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must make sure that you run ALL the steps in the READ & RUN ME and also run them in the order written otherwise logs will give us incorrect information to prepare fixes from.
     
  8. mamabear0917

    mamabear0917 Private E-2

    okay, i ran the steps in order. I could not download CounterSpy or AVG Anti -Spyware. I could try to download those now if you would like. Followed all the steps, could not use Kaspersky or PandaActive Scan...activex issues, i'm not sure but it would download, kept saying it was already downloaded and nothing happened. Ran BitDefender and Ad-Aware (All steps to 6a done on both administrator and other user accounts). Spy Bot under administrator found no infection but under other user it found nothing but generated a log. BitDefender found infected files but could not delete under both accounts, Ad-aware found nothing under administrator account but a log was generated in other user account. I also have logs for runkeys.txt and newfiles.txt. I am afraid of moving further into step 6c because when I used SmitRem the last time WININET.dll disappeared. I will wait for further instructions on 6c. I read the downloading, installing and running hijackthis and I believe I did it right and I also have a log. I'm not sure which log you would like posted first. I'm not sure if I uploaded the right HJT file...very new to this. I followed the steps...I will try again. I will also give you runkeys and newfiles logs. Let me know what I did wrong and I'm sorry in advance for not being more computer knowledgable.confused P.S. Will disable and enable system restore now. Also, I thought I uninstalled SpyCatcher, but I didn't soo sorry in advance, but...it is stopping a suspicious program from accessing my computer. Suspicious program is
    C:\Windows\System32\xligfl254.dll. Any idea what it is, when I google it I get a lot of posts from other forums but no clear idea of what it is.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why not? If you could not download them before, why would you be able to download them now?

    We don't ask for Kaspersky to be run in the READ ME.


    We don't ask fro Ad-ware to be run in the READ ME! Where is the Bitdender log that was requested?

    Do you know for a fact that you have a SmitFraud or Zlob infection? If not, then you should not be running SmitRem anyway. And if you ran it previously, where is the log.


    We need the log from HijackThis to be attached not the executable program that you downloaded.

    You should not be touching system restore until your PC is free of malware and we did not say it was free of malware yet.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, you skipped step 2 of the READ ME. Please do it properly now.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds