View Single Post
Old 08-21-2005, 10:07 PM   #8 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,324
OS: N/A


Launch KillBox.exe & select the following options:
  • delete on Reboot
  • end Explorer shell while killing file
  • unregister dlll before deleting * if it's not grayed out
Select all the filenames below & then click on Notepad's 'Edit' menu & select Copy
  • C:\WINDOWS\dinst.exe
    C:\WINDOWS\DOWNLOADED PROGRAM FILES\MediaGatewayX.dll
    C:\WINDOWS\SYSTEM\UpdInst.exe
    C:\WINDOWS\SYSTEM\n9058rq5.exe
    C:\WINDOWS\Start Menu\Programs\Disabled Startup Items\utrt.exe
    C:\WINDOWS\Downloaded Program Files\CONFLICT.1\installer_MARKETING32.exe
    C:\WINDOWS\Downloaded Program Files\installer_MARKETING32.exe
    C:\WINDOWS\gvwvv.dat
    C:\WINDOWS\fgfggsk.dll
    C:\WINDOWS\setup_silent_26223.exe
    C:\WINDOWS\ru.exe
    C:\WINDOWS\xodooar.exe
    C:\WINDOWS\banner.dll
    C:\WINDOWS\xdsddp.exe
    C:\Program Files\Common Files\SYSTEM\Mapi\1033\95\MTE2NzY6ODoxNg.exe
    C:\Program Files\WAV to MP3 Encoder\mm332.exe
    C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7395.TMP\ProxyStub .dll
    C:\Program Files\Yahoo!\YPSR\Quarantine\ppq73B5.TMP
    C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8002.TMP
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050819175611.zip
    c:\windows\invitessk.exe
    c:\windows\rbebb.dll
    c:\windows\SYSTEM\Dwapilib.tlb
    c:\windows\SYSTEM\n9058rq5.ini
    c:\windows\SYSTEM\msfmg5cg.ini
    c:\windows\SYSTEM\n9058rq5.exe
    c:\windows\SYSTEM\kegbtdvr.exe
    c:\windows\SYSTEM\qttexl.exe
* Go to the File menu, and choose Paste from Clipboard
* Verify that the filenames you pasted are found there from the dropdown menu next to Full Path of File to Delete field.
* Click the RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.

Reboot to Safe Mode

Run CleanUp

Run WinPFind

Post WinPFind & HJT logs
__________________

Question - what have you done for the community today?
sUBs is offline