ismini.exe
ishost.exe
issearch.exe
and another one, keep brining me to some crappy site for malware protection, and stupid crap, they are in system32 and prefetch, well they were, now if i hit home on my browser IE it takes me to another crappy page for malware removal crap to purchase, well i changed the homepage in tools, and tried it again, same crap. anyone help?
Go here and Download SmitFraudFix.zip to your desktop.
Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
Double-click smitfraudfix.cmd
Select 2 and hit Enter to delete infect files.
You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt
Then, download HijackThis, run a scan and post it's log along with the contents of rapport.txt.
Logfile of HijackThis v1.99.1 Scan saved at 12:23:00 AM, on 9/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan done at 0:17:30.13, Sat 09/10/2006
Run from C:\Documents and Settings\Chris\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
sorry to double post, but now everykey stroke is making a beeping noise through an internal speaker, so now when i'm typing it's sounding like i'm typing in morse code. does this have anything to do with the above logs and or issues, or is my laptop just trying to shit out on me?
edit > also i forgot to include that prior to my finding the ishost.exe and stuff that virus burst had some how been downloaded and installed, so i don't know if that makes a difference, i just un-installed it via the un-install virusburst option that it had in the program directory.