- I need you to copy and paste the full list below into a Notepad file and save it to your Desktop as Fixup. (This list will be used later on).
c:\windows\system32\scujrfm.exe
C:\WINDOWS\System32\UMKZAM.EXE
C:\WINDOWS\System32\OHIXBHO.DLL
C:\WINDOWS\System32\OPKMQ.DLL
C:\WINDOWS\System32\SUPDATE.DLL
C:\WINDOWS\System32\ATIUPD~1.EXE
C:\WINDOWS\System32\DRNAQRD.EXE
C:\WINDOWS\System32\REDIT.CPL
C:\WINDOWS\System32\06WU29RD.EXE
C:\WINDOWS\System32\CALSDR.EXE
C:\WINDOWS\System32\CQEKOH.EXE
C:\WINDOWS\System32\EARE.EXE
C:\WINDOWS\System32\OFBBSGM.EXE
C:\WINDOWS\System32\WINUPDT.EXE
C:\WINDOWS\System32\AUNPS2.DLL
C:\WINDOWS\System32\BH.DLL
C:\WINDOWS\System32\SUPDATE.DLL
C:\WINDOWS\NAIL.EXE
C:\WINDOWS\SATMAT.EXE
C:\WINDOWS\INFAMOUS.EXE
C:\WINDOWS\POLALL1T.EXE
C:\WINDOWS\POLMX3.EXE
C:\WINDOWS\TDTB.EXE
C:\WINDOWS\UNSTSA2.EXE
C:\WINDOWS\2_0_1B~1.DLL
C:\WINDOWS\WSEM218.DLL
Documents and Settings\All Users\Start Menu\Programs\Startup\rpka.exe
C:\WINDOWS\SYSTEM32\aejyhyh.exe
C:\WINDOWS\SYSTEM32\mc-58-12-0000093.exe
C:\WINDOWS\SYSTEM32\setup_silent_25207.exe
C:\WINDOWS\SYSTEM32\setup_silent_26222.exe
C:\WINDOWS\SYSTEM32\SHAgentNew.dll
C:\WINDOWS\SYSTEM32\supdate.dll
C:\WINDOWS\SYSTEM32\wbauy.dat
C:\WINDOWS\SYSTEM32\winupdt.exe
C:\WINDOWS\SYSTEM32\eliteamm32.exe
C:\WINDOWS\SYSTEM32\eliteehn32.exe
C:\WINDOWS\SYSTEM32\elitepls32.exe
C:\WINDOWS\SYSTEM32\elitewjn32.exe
C:\WINDOWS\SYSTEM32\protect.exe
C:\WINDOWS\SYSTEM32\Dwapilib.tlb
C:\WINDOWS\2_0_1browserhelper2.dll
C:\WINDOWS\del.tmp
C:\WINDOWS\Key2.txt
C:\WINDOWS\splaocjox.exe
- Please download the Killbox by Option^Explicit and save it to your Desktop.
- Run Killbox.exe.
- Select "Delete on Reboot and
End Explorer Shell While Killing file
- Open the Notepad file where you saved the list of files earlier, and copy the file names below to the clipboard by highlighting ALL of them then press CTRL + C
- Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
- Scan with hijackthis and put a checkmark beside the following the following:
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\umkzam.exe reg_run
Click Fix checked and EXIT HJT.
- Click the red-and-white "Delete File" button in Killbox. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt. If your computer does not restart automatically, please restart it manually.
- Post a new hijackthis log and a new Qoologig log
Trevuren
Edited by Trevuren, 30 June 2005 - 10:14 AM.