Downlaod the file I've attached to this post -
regdel.zip (do NOT run it yet)
Download & launch
KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)
Select the following option -
delete on Reboot
Use your mouse to select all the filenames listed below & then right-click & select Copy
- C:\WINNT\agkhot.dll
C:\WINNT\system32\glqfw.dll
C:\WINNT\SYSTEM32\7r9e5u66.ini
C:\WINNT\SYSTEM32\fiz4
C:\WINNT\SYSTEM32\fiz6
C:\WINNT\SYSTEM32\Mgystzk1.xml
C:\WINNT\SYSTEM32\NewMgystzu1.xml
C:\WINNT\SYSTEM32\p9fg22ff.ini
C:\WINNT\SYSTEM32\_003827_.tmp.dll
C:\WINNT\system32\ykqwco.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\piwx.exe
C:\Documents and Settings\Courtney\Start Menu\Programs\Startup\piwx.exe
* Go to the File menu, and choose
Paste from Clipboard
* Click the
RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.
Quote:
|
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.
|
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * **
Next, please reboot your computer in
SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Uninstall the following programs, if present, using Control Panel->Add/Remove Programs:
- AdDestroyer
WildArcade
Winad Client
midaddle
Please note any other programs that you dont recognize in that list in your next response
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Form within
regdel.zip, doubleclick on
regdel.reg & allow it to merge into the registry.
Locate and delete the following files/folders, if present:
- C:\Documents and Settings\Courtney\Start Menu\Programs\AdDestroyer
C:\PROGRAM FILES\WildArcade
C:\PROGRAM FILES\Winad Client
C:\PROGRAM FILES\COMMON FILES\midaddle
C:\PROGRAM FILES\COMMON FILES\SQ
C:\WINNT\SYSTEM32\FLEOK
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Run
Cleanup! using the following configuration:
1. Click Options...
2. Set the slider to
Standard CleanUp!
3.
Uncheck the following:
- Delete Newsgroup cache
- Delete Newsgroup Subscriptions
- Scan local drives for temporary files
4. Click OK
5. Press the CleanUp! button to start the program. Reboot/logoff when prompted.
* CleanUp! will not create any backups!!
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
REBOOT TO NORMAL MODE
Perform an online scan with Internet Explorer with
Kaspersky WebScanner
Next Click on
Launch Kaspersky Anti-Virus Web Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click
Yes.
- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK
- Now under select a target to scan:Select My Computer
- This will program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
Copy and paste that information in your next post.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Download
Trend Micro™ Anti-Spyware (by clicking the "Scan and Clean your PC" button).
- Double-click the tmas-web-scan.exe icon
- It will say "Loading TrendMicro definitions".
- Click "Start Scan"
After it's done scanning, click "
Scan Results"
- Make sure all items found have a check next to them, then click "Clean Threats Now".
- Click Exit.
Reboot your computer. I then need you to
repeat the same procedure above again... using the TrendMicro tool. I need the log from the second scan/clean...NOT the first...as this will contain what’s left in the system.
It would produce a log called "
Antispyware.log", please double-click that log and copy the entire contents and paste them here.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
In your next post, please include fresh logs from:
- HiJackThis log
- Online Scans
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now
__________________
Question - what have you done for the community today?