View Single Post
Old 07-10-2005, 08:00 PM   #9 (permalink)
MicroBell
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
 
MicroBell's Avatar
 
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7


Send a message via ICQ to MicroBell Send a message via MSN to MicroBell
When your as infected as you were...it takes several passes to clean out all these guys. Anyway...the MS03-014 and an MS03-030 are microsoft patches which can be obtained at the windows update page..

http://v4.windowsupdate.microsoft.com/en/default.asp

Lets do some more cleaning. Please reboot into safe mode.

Run KILL box. Paste the following locations into KILL BOX one at a time. Checkmark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot.


C:\WINDOWS\SYSTEM\UpdInst.exe
C:\WINDOWS\SYSTEM\retpdat32.xml
C:\WINDOWS\SYSTEM\sp32.xml
C:\WINDOWS\SYSTEM\adupdmanager.xml
C:\WINDOWS\SYSTEM\xmlparse.dll
C:\WINDOWS\SYSTEM\xmltok.dll
C:\WINDOWS\SYSTEM\exclean.exe
C:\WINDOWS\INF\ALCHEM.INF
C:\WINDOWS\INF\BIINI.INF
C:\WINDOWS\SYSTEM32\wosys32.dll
C:\WINDOWS\Application Data\tvmcwrd.dll
C:\WINDOWS\Application Data\tvmuknwrd.dll
C:\keys.ini


**Note** Also look for any of the following files and add them to the deletion process above.

alchem.cab
ALCHEM.EXE
alchem.inf
ALCHEM.INI


C:\WINDOWS\Application Data\ <-- in this folder add any file that begins with the letters tvm You want to delete any file that looks simular to those 2 listed in the above log.

Once you reboot....do another Panda scan and post it's log. Also post another Silentrunners log.
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!





Spyware/Adware Removal Tools
Hijackthis
Ad-aware SE
Spybot Search&Destroy
SpywareBlaster
CWShredder
MicroBell is offline