View Single Post
Old 12-31-2004, 05:46 AM   #7 (permalink)
Pancake
Security Team (ret.)
 
Pancake's Avatar
 
Join Date: Nov 2003
Location: Victoria.Australia
Posts: 7,405
OS: XP Pro SP3


Copy Killbox to your Desktop and ensure you have version 2.0.0.76 or better.

From the Dllcompare log copy & paste each full path into the Killbox topmost box.
ie: a fullpath from our sample log would be
C:\WINDOWS\SYSTEM32\atwav.dll
C:\WINDOWS\SYSTEM32\darpsetu.dll
etc.

With the full path to the file name in the topmost textbox, click the option "Use Dummy" which will create a numbered dummy file instantly for you.

Click the Red X ...and for the confirmation message that will appear, you will need to click "Yes"
A second message will ask to Reboot now? you will need to click "No" (since you have not added all related files in yet)

Do this for every file you have matching the VX2 criteria, in the dllcompare log.

*in the sample file here, every file matches VX2 parameters and would be input into Killbox.


Quote:
ie: Top line in Killbox would have the path
D:\WINDOWS\SYSTEM32\tatwav.dll the bottom line would show a dummy file in user Temp directory
D:\Documents and Settings\User\Local Settings\Temp\kbdummy.1

Do this same step for every file in the dllcompare log that is listed below..

When you get to the last file in the Dllcompare log, also add in one additional file

C:\Windows\System32\Guard.tmp
*Be careful to include the correct path to the system32 folder, as drive letters & windows folder names change slightly from system to system
If this is an issue, click the [Browse] button in Killbox and navigate to the guard.tmp manually. (it will always be in the System32 directory, and may need to have File & Folder options to "unhide system files" enabled).. HOW TO SHOW FILES

On that last file, close all programs and Reboot your computer.
Pancake is offline