Smiley face trogen

Microsoft Windows xp home edition sp2b
December 23, 2009 at 01:25:58
Specs: Windows XP
My husband downloaded what he thought was a dvd player which turned out to be a Smiley trogen. We have tried to get rid of it but the computer will not start in safe mode and it will not go any further. You cant click on anything to open up program, such as control panel. We dont know what to do, is there anyone that can help please.

See More: Smiley face trogen

Report •

December 23, 2009 at 04:39:40
You may need to download these to a usb drive or cd and run it on the infected computer but first try to run it from the infected computer.

Please download Rkill from the following link.


Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. This link will help you disable them:

Click on This Link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)

A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.

Please download exeHelper to your desktop.
Double-click on to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Please run RSIT.exe by random/random and post its logs.

Download random's system information tool (RSIT) by random/random from the following link and save it to your desktop.


1. Double click on RSIT.exe to launch program.
2.(Vista Users Only) Right click on the RSIT.exe icon and select "Run as Administrator" to run the program.
3. Click Continue at the disclaimer screen.
4. Your firewall may alert you that RSIT is requesting Internet access. Please allow it.
5.Once it has finished, two logs will open: log.txt<-- this will be maximized and info.txt<-- this will be minimized. Both logs will be located at C:\RSIT.exe.

Report •

December 23, 2009 at 12:18:14
I downloaded Rkill onto cd but it doesnt work. The cd player will
not work now. We can only go to the start up screen and then
we cant go anywhere. We try to click on the start menue but it
will not open up. Nothing opens up. It freezers. The mouse
works but nothing else does. Is there anyway i can get to the
safe mode. I have tried to do this but it will not start up in safe
mode either. When i bought my computer new 3 months ago, i
never got a back up running system, so i cant even remove it all
to put it back on. Not sure what to do.

Report •

December 23, 2009 at 12:45:07
Do not try to get into safe mode through msconfig, it will lock up the computer most likely.

The usb ports are probably working so if you have a jump drive (usb storage device), or can borrow one, you may be able to get in that way. If you do have the jump drive download "exeHelper" and run it first.

Report •

Related Solutions

December 23, 2009 at 18:28:03
Thanks for your help. We have tried without success, what you
have suggested. I rang Microsoft and they say to take it to a
Technician. We cant use windows at all, the virus is stopping
us from useing it or downloading what we need to get rid of it.
Thanks for trying to help. your awesome.

Report •

December 23, 2009 at 18:59:32
Sorry we couldn't be of more help.

Report •

December 25, 2009 at 12:19:07
Is there anyway that we can remove everything off our computer and not have to take it too a Tech. We bought this computer 4 months ago. We never got any back up cds. Just wondering as it cost so much to get comps fixed.

Report •

Ask Question