Blind Dragon
Posts: 3,774 +4
I still see some remnants of zlob.downloader/ we already removed some of this but just to be sure
Avenger by Swandog
Download to your Desktop this self-extracting ZIP archive FixPolicies.exe
• Double-click FixPolicies.exe
• Click the Install button on the bottom toolbar of the box that will open.
• The program will create a new Folder called FixPolicies
• Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
• A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.
The instructions given in this thread are for the use of pbjam only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Avenger by Swandog
- Download Avenger by Swandog and unzip it to your Desktop.
Note: This program must be run from an account with Administrator priviledges.
- Open the Avenger folder and double click Avenger.exe to launch the programme.
- Copy the text in the code box below and Paste it into the Input script here: box.
Code:
Files to delete:
C:\WINDOWS\fmsxwqs.exe
C:\WINDOWS\altvxvm.dll
C:\WINDOWS\bokpkov.dll
C:\WINDOWS\drnpfdxxsn.dll
C:\WINDOWS\etlrlws.dll
C:\WINDOWS\Installer\WinRom.dll
C:\WINDOWS\Installer\zip.dll
C:\WINDOWS\System32\msram.dll
C:\Program Files\antiviirus.exe
C:\Program Files\tmp0.exe
Registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antiviirus
- Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
- Ensure the following:
- Scan for Rootkits is checked.
- Automatically disable any rootkits found is Unchecked.
- Press the Execute key.
- Avenger will now process the script you've pasted (this may involve more than one re-boot), when finished it will produce a log file.
- Attach the log back here please. (it can also be found at C:\avenger.txt)
Download to your Desktop this self-extracting ZIP archive FixPolicies.exe
• Double-click FixPolicies.exe
• Click the Install button on the bottom toolbar of the box that will open.
• The program will create a new Folder called FixPolicies
• Double-click to Open the new Folder, and then double-click the file named Fix_Policies.cmd
• A black box will briefly appear and then close. This will enable your Control Panel, Task Manager and stop any Administrative warnings.
The instructions given in this thread are for the use of pbjam only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.