View Single Post
Old 07-31-2006, 01:13 PM   #6 (permalink)
Vikesrock8411
Analyst, Security Team
 
Vikesrock8411's Avatar
 
Join Date: Jun 2005
Posts: 3,065
OS: Windows XP


Download KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)

Launch KillBox.exe & select the following options:
  • delete on Reboot
Select all the filenames below & then right-click & select Copy

  • C:\dfndref_7.exe
    C:\drsmartload.exe
    C:\drsmartload1.exe
    C:\drsmartload45a7i.exe
    C:\drsmartload46a7i.exe
    C:\drsmartload849a7i.exe
    C:\Installer3.exe
    C:\kybrdef_7.exe
    C:\MTE3NDI6ODoxNg.exe
    C:\ucmoreiex.exe
    C:\warebundlenewer.exe
    C:\WINDOWS\system32\w07029be.dll
    C:\WINDOWS\system32\mmvece13.dll
    C:\WINDOWS\SysWOW64\mmvece13.dll
    C:\WINDOWS\SysWOW64\w07029be.dll
    C:\WINDOWS\winlogon.exe
* Go to the File menu, and choose Paste from Clipboard
* Click the RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click No at the 'Pending Operations prompt'.

Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:WindowsSystem32 Directory.
http://www.ascentive.com/support/new...b/MSWINSCK.OCX

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
__________________
Vikesrock8411 is offline