How to remove SpyHeal. |
![]() ![]() |
How to remove SpyHeal. |
Jul 13 2006, 11:41 AM
Post
#1
|
|
![]() Visiting Staff Posts: 6 OS: Windows XP |
SpyHeal ![]() Mirrored from http://forum.securitycadets.com/index.php?showtopic=232 Thanks also goes to Kimberly and Grinler QUOTE Symptons in HJT logs:- O4 - HKLM\..\Run: [SpyHeal] C:\Program Files\SpyHeal\SpyHeal.exe /h What you need to do:- First of all it would be a good idea to print this guide of as you will have to reboot into safe mode 1. You would need to manually remove this program which is very easy:
3. Extract the .zip file you just downloaded to your desktop. Right click on the file and select "Extract here" or "Extract all". The blow image is what you should see when extracted. 4. Please download Ewido to your Desktop or to your usual Download Folder. http://www.ewido.net/en/download/
Ewido manual updates. Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update. 5. Next step is to reboot into Safe Mode like so:
![]() 7. Please double-click on the SmitfraudFix.cmd file, as shown in the image above, to start the removal process. When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen. 8. You will now see a menu as shown in the image below. Press the number 2 on your keyboard and the press the enter key to choose the option Clean (safe mode recommended). ![]() The program will start cleaning your computer and go through a series of cleanup processes. When it is done, it will automatically start the Disk Cleanup program as shown by the image below. ![]() This program will remove all Temp, Temporary Internet Files, and other files that may be leftover files from this infection. This can take up to a few hours depending on your computer, so please be patient. When it is complete, it will close automatically. 9. When Disk Cleanup has finished, you will see an option asking Do you want to clean the registry? (y/n). At this screen press the Y button and then press the enter key. The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter. 10. When the last routine is finished, you will be presented with a red screen stating Computer will reboot now. Close all windows and applications. You should now press the spacebar on your computer. A counter will appear stating that the computer will reboot in 15 seconds. Do not cancel this countdown and allow your computer to reboot. Once the computer has rebooted, you may be presented with a Notepad screen containing a log of all the files removed from your computer. (Otherwise the tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.) 11. Go back into Safe Mode (Look at Step 5) 12. Navigate to C:\Windows\Temp Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin. Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin. Clean out your Temporary Internet files. Proceed like this:
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin. 13. Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
14. Open the SmitfraudFix folder and double-click smitfraudfix.cmd Select option #3 - Delete Trusted zone by typing 3 and press Enter. Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter. Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection. 14. You should be free of this program. However, if you still seem infected create a new post with the following information in the Malware Removal Forum.: Please post:
|
|
|
Jul 12 2007, 04:16 PM
Post
#2
|
|
![]() Site Administrator Posts: 16,818 From: 127.0.0.1 OS: Windows Vista Ultimate |
This topic has been left open to allow specific questions and comments related ONLY to this guide. It's NOT for posting HJT logs, links to your logs, or any other general malware help. Replies not following these rules will be deleted. Thanks for your cooperation.
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
12 / 71,765 | 10th August 2008 - 04:49 AM admin started - last by Essexboy |
|||||
![]() |
13 / 10,865 | 10th August 2008 - 06:30 PM admin started - last by Rorschach112 |
|||||
![]() |
48 / 36,379 | 1st August 2008 - 02:47 PM miekiemoes started - last by ShadowN |
|||||
![]() |
0 / 133 | 27th July 2008 - 06:19 PM charlieminxs started - last by charlieminxs |
|||||
![]() |
2 / 822 | 8th August 2008 - 08:58 AM joke blue started - last by Essexboy |
|||||
|
Time is now: 20th August 2008 - 12:11 PM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |