Thread: closing .exe
View Single Post
Old 06-14-2006, 07:40 PM   #8 (permalink)
Buzz1927
Digaredd
 
Buzz1927's Avatar
 
Join Date: May 2005
Location: Melbourne AU
Posts: 6,674
Default

How did you get this stuff so quickly? I think you need an antivirus.

Save these instructions to a new Notepad document for use in safemode later.

1) Please download the
Killbox.
Unzip it to the desktop but do NOT run it yet.

2) Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.

3) Once in Safe Mode, please run Killbox.

4) Select "Delete on Reboot".

5) Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

D:\Program Files\??curity\explorer.exe
D:\PROGRA~2\WNSXS~1\ping.exe
D:\WINDOWS\system32\69878dfe.exe
D:\WINDOWS\system32\iexplore.dll
D:\WINDOWS\system32\ntvdm.dll
D:\WINDOWS\SYSTEM32\wineil32.dll


6) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

7) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

Run Hijackthis and select "Do a system scan only", place a check by the following entries.

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - D:\WINDOWS\winres.dll (file missing)
O4 - HKLM\..\Run: [69878dfe.exe] D:\WINDOWS\system32\69878dfe.exe
O4 - HKCU\..\Run: [69878dfe.exe] D:\Documents and Settings\Jarret M\Local Settings\Application Data\69878dfe.exe
O4 - HKCU\..\Run: [Sen] "D:\PROGRA~2\WNSXS~1\ping.exe" -vt yazr
O4 - HKCU\..\Run: [Wktpzav] D:\Program Files\??curity\explorer.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTick...cab?refid=5071
O20 - AppInit_DLLs: D:\WINDOWS\system32\iexplore.dll D:\WINDOWS\system32\ntvdm.dll
O20 - Winlogon Notify: wineil32 - D:\WINDOWS\SYSTEM32\wineil32.dll


Close all open windows and browsers, and hit "Fix Checked".

Then reboot and post a new Hijackthis log.
__________________
The Grim Reaper - Son of Glyndwr
"To Hell or Connacht" may you burn in Hell tonight!
Buzz1927 is offline   Reply With Quote