| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 72329 | 2006-09-08 12:28:00 | VIRUS Trojan.emcoder.g | chrissie28 (11111) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 483351 | 2006-09-08 12:28:00 | Please can someone help running windows 2000 professional find Trojan.emcoder.G c:program Files/PCODEC/pmmon.exe norton can't repair it. how can i get rid of it...........pleeeeeeeeeeeeez |
chrissie28 (11111) | ||
| 483352 | 2006-09-08 13:37:00 | try runnin the scan in safe mode...... | drcspy (146) | ||
| 483353 | 2006-09-08 14:10:00 | This thread is worth checking out: forums.pcworld.co.nz Cheers :) |
Renmoo (66) | ||
| 483354 | 2006-09-09 04:14:00 | Hi This should help... Download SmitfraudFix (by S!Ri) to your Desktop. siri.urz.free.fr Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop. Reboot your computer in Safe Mode. If the computer is running, shut down Windows, and then turn off the power. Wait 30 seconds, and then turn the computer on. Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again. Ensure that the Safe Mode option is selected. Press Enter. The computer then begins to start in Safe mode. Login on your usual account. Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool. Select option #2 - Clean by typing 2 and press Enter. Wait for the tool to complete and disk cleanup to finish. You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter. The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter. A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually.. The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with your next reply and a new HJT log. |
Pancake (6359) | ||
| 1 | |||||