Scroll through the list of files in this folder and look for
rrtcany.dll. Right-click on
rrtcany.dll and select
rename. Rename the file to
rrtcany.dll.bad.
Look for the file
veklo.dll and rename the file to
veklo.dll.bad.
Look for the file
okkmtv.dll and rename the file to
okkmtv.dll.bad.
Look for the file
impgsje.dll and rename the file to
impgsje.dll.bad.
Look for the file
sacskza.dll and rename the file to
sacskza.dll.bad.
Look for the file
cfltygd.dll and rename the file to
cfltygd.dll.bad.
Look for the file
jbtazy.dll and rename the file to
jbtazy.dll.bad.
Look for the file
fmrmhc.dll and rename the file to
fmrmhc.dll.bad.
Look for the file
dcvwaah.dll and rename the file to
dcvwaah.dll.bad.
Look for the file
oebxpba.dll and rename the file to
oebxpba.dll.bad.
Look for the file
xxfgmy.dll and rename the file to
xxfgmy.dll.bad.
Look for the file
tpedvf.dll and rename the file to
tpedvf.dll.bad.
Look for the file
dbqlrij.dll and rename the file to
dbqlrij.dll.bad.
Look for the file
vcehaeb.dll and rename the file to
vcehaeb.dll.bad.
Look for the file
xqpauzx.dll and rename the file to
xqpauzx.dll.bad.
Look for the file
mlraakb.dll and rename the file to
mlraakb.dll.bad.
Look for the file
qrzsyr.dll and rename the file to
qrzsyr.dll.bad.
Note: Please rename any of the above files that you may find. If you do not find any of these files, then you should post a note about it in the
Am I Infected? forum.
After you rename the file, you can close the System32 folder window.
- Next, please reboot your computer into Safe Mode by doing the following:Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear
Select the first option, to run Windows in Safe Mode. - When you are at the logon prompt, log in as the same user which you had done the previous steps.When your computer has started in safe mode and you see the desktop, click on the Start Menu button.
Click on the Control Panel option.
Double-click on the Add or Remove Programs icon.
Find the entries for VirusBursters 6.2, Virus-Bursters 6.3 or VirusBurster 6.3 and double-click on it to uninstall them if found. Follow the prompts to uninstall the program, but do not allow it to reboot the computer if it asks.
When it has completed uninstalling you can close Add or Remove Programs and your Control Panel.
Delete the following files and folders (Do not be concerned if this folder does not exist):
C:\Windows\System32\rrtcany.dll
C:\Windows\System32\veklo.dll
C:\Program Files\VirusBursters\
C:\Program Files\Virus-Bursters\
C:\Program Files\VirusBurster\
C:\Windows\System32\okkmtv.dll.bad
C:\Windows\System32\impgsje.dll.bad
C:\Windows\System32\sacskza.dll.bad
C:\Windows\System32\jbtazy.dll.bad
C:\Windows\System32\cfltygd.dll.bad
C:\Windows\System32\fmrmhc.dll.bad
C:\Windows\System32\dcvwaah.dll.bad
C:\Windows\System32\oebxpba.dll.bad
C:\Windows\System32\xxfgmy.dll.bad
C:\Windows\System32\tpedvf.dll.bad
C:\Windows\System32\dbqlrij.dll.bad
C:\Windows\System32\vcehaeb.dll.bad
C:\Windows\System32\xqpauzx.dll.bad
C:\Windows\System32\mlraakb.dll.bad
C:\Windows\System32\qrzsyr.dll.bad
Close all open Windows.
Now, double-click on the SmitFraudfix icon that should be residing on your desktop.The icon will look like the one below:
When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen.
When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen.
You will now see a menu as shown in the image below. Press the number 2 on your keyboard and the press the enter key to choose the option Clean (safe mode recommended).
The program will start cleaning your computer and go through a series of cleanup processes. When it is done, it will automatically start the Disk Cleanup program as shown by the image below.
This program will remove all Temp, Temporary Internet Files, and other files that may be leftover files from this infection. This process can take up to a few hours depending on your computer, so please be patient. When it is complete, it will close automatically and you will should continue with step 25.
When Disk Cleanup is finished, you will be presented with an option asking Do you want to clean the registry ? (y/n). At this screen you should press the Y button on your keyboard and then press the enter key.
When this last routine is finished, you will be presented with a red screen stating Computer will reboot now. Close all applications. You should now press the spacebar on your computer. A counter will appear stating that the computer will reboot in 15 seconds. Do not cancel this countdown and allow your computer to reboot.
Once the computer has rebooted, you will be presented with a Notepad screen containing a log of all the files removed from your computer. Examine this log to see what files were found, and when you are done, close the Notepad screen. - We next perform an online scan with Panda to find any possible inactive remnants from this infection: Panda OnlineOnce you are on the Panda site click the Scan your PC button
A new window will open...click the Check Now button
Enter your Country
Enter your State/Province
Enter your e-mail address and click send
Select either Home User or Company
Click the big Scan Now button
If it wants to install an ActiveX component allow it
It will start downloading the files it requires for the scan (Note: It may take a few minutes) - When download is complete, click on Local Disks to start the scan
- When the online scan has been completed, let it remove what it finds, and then you can close Internet Explorer.
Your computer should now be free of the VirusBursters, Virus-Bursters, and VirusBurster infection