trojan server.execrash

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by jagguy, May 15, 2007.

  1. jagguy

    jagguy Private First Class

    My pc is crashing a few times aday.
    I had the abast VS detect a trojan a few days ago and i though that fixed the problem.
    I get a error with services.exe and the popup says with red pic the pc will reboot.

    Now i have p4 2.0ghz winxp 512 mb ram and hd 30g with 5 g left.

    It usually crashes with internet browsing (normal sites and nothing dodgy), and no other windows open.

    ps i was told to post here so i am not double posting to annoy people.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. jagguy

    jagguy Private First Class

    avg spyware and counter spy are both trials which have expired on my pc.
    What do i do in this case as it seems a little pointless running these?
     
  4. jagguy

    jagguy Private First Class

    I keep getting a trojan horse in my temp folder (every minute)and it keeps appearing. I am deleting with avast but new ones keep coming in same folder, where is it coming from. A program called yazzle appeared in common folder and i deleted it.

    I ran ccleaner,avast,spybot,adaware,smitfraud.
    I need to try online scanners and getkey etc but surely these things should have picked this up by now?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not true! AVG Antispyware will still scan and remove. It just will not block anymore. Use it but uninstall CounterSpy since it is worthless after the trial period.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you want help, you need to follow my instructions and attach all the requested logs! It's rather simple. No logs, no help! Sorry but we are not magicians. We need info and that is what the steps in the READ ME give us.
     
  7. jagguy

    jagguy Private First Class

    I cant run the online scanners as they take 8-16 hrs to run, eg bitdefender

    AVG came up with 2 high threats and spybot got rid of some but I am getting a avast popup for virus detection every 60 sec! I have a trojan win32:alphabet virus that avast,avg,adaware,spybot,ccleaner,smitfraud can't get rid of but it is so obviously there.

    I will run the getkey and the other program but it looks like my pc really needs a format and install again and attach logs but the time it takes to work this all out i believe i could reinstalled my software (i appreciate the help so far).
    Anyway I am off to get a dvd-rw to save my stuff on.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it but it's your choice. Read thru the below list of things that most people forget to consider with a reinstall.

    A new install involves more than you may think. Especially to get back to a level of where you system is at. You have to consider all of the below:
    • you have to backup all you own data, settings, configurations etc and first you have to know what/where all of these are. And you have to have the medium (burnable media, second hard drive, tape drive [yuck] )
    • then you must make sure you have the necessary disks to reinstall not just your OS but all other software you use especially protection before going online
    • then fdisk, format, reinstall the OS
    • now reinstall all your software especially protection
    • get online (requires some setup and config that novices have problems with)
    • download updates for OS
    • download updates for protection software
    • download updates for all other software
    • tweak all software back the way you like it. Including Desktop settings, icons etc.
    • create all the folders that you use for everything in your normally routines
    • re-load from your backups to get data back, to get settings, Favorites,.....etc back
    • now over the next two weeks you will realize that you forgot to backup some stuff and also you will keep finding something else that you need to reinstall.
     
  9. jagguy

    jagguy Private First Class

    Hi,
    My pc sometimes has to do boot up with the blue screen security check often as well.

    Now i didn't post hijack this as that seems to be a problem if i havent done the online scanners properly.
    The bitdefender was run on a few folders eg doc and settings but it still had 12 hours to go. I have a wireless connection and line sometimes drops so the length it takes was just not practical and pandascan i didn't do.

    I did do
    avast scan
    adaware
    spybot s&d
    ccleaner
    avg
    smitfraud
    bitdefender 'partially'

    I couldn't get avg log as the pc crashed but redid avg again on major folders and other options. I did get the critical errors found as listed before it crashed eg doc and settings, windows, and many more i did avg on until clean.

    i have the log for runkey and shownew and get hijack this if required.
    I have this trojan poup about every 60 sec
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't know what you mean! What blue screen security check are you referring too?

    If you cannot run the online scans, you still need to attach the HijackThis log but make sure you install it and rename it exactly as we requested.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you purchase Spyware Nuker XT? Hope not!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a bunch of infections! Three very obvious ones are Virtumonde, WinLogonHook, and Troj/DwnLdr-GUH

    First goto Add/Remove programs and uninstall Outerinfo


    Please run the below tool multiple times until it comes up not finding anything.

    Virtumonde aka Trojan Vundo Removal

    Then attach the log from VundoFix and also new logs from ShowNew and HJT so we can continue with more manual removal steps which will more than likely be necessary.
     
  13. jagguy

    jagguy Private First Class

    Hi,

    How do you get time to do all this and where did you learn about the virus removing? I appreciate your help for sure.

    I ran vundofix 4 times and still i get dll's to delete but i still get a trojan popup every 60sec from avast. These dll's to delete from vundofix are they system files i am deleting with this as don't i need them?

    I mat still need a few more vundofix runs but i doubt it will get rid of the major trojan problem i have.

    Anyway my latest logs are these.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Simple! I never sleep! :D It takes a lot of time and you need to have a lot of experience with all of the Windows operating systems in order to be able to effectively work these malware issues. You need to be able to quickly distinguish between good/required files, definitely bad files, and then add a third group called questionable files which means you need to figure out whether they are bad or not.

    Depending on your technical abilities and background, you could pickup a lot by reading and studying several dozen threads per week and learning the tools and special removal procedures.



    Continue by downloading two tools we will need

    - ProcessExplorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe
    properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill
    button.
    cbxyvuv.dll
    efebc.dll
    khfcyxy.dll
    tuvwvuu.dll
    winexz32.dll
    xcjfrxrw.dll
    ydwctscl.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    cbxyvuv.dll
    efebc.dll
    khfcyxy.dll
    tuvwvuu.dll
    winexz32.dll
    xcjfrxrw.dll
    ydwctscl.dll

    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    cbxyvuv.dll
    efebc.dll
    khfcyxy.dll
    tuvwvuu.dll
    winexz32.dll
    xcjfrxrw.dll
    ydwctscl.dll

    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\avp.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {26934EF7-FDD9-4865-A003-FC96C00E38E8} - C:\WINDOWS\system32\cbxyvuv.dll (file missing)
    O2 - BHO: (no name) - {3C4784CE-43E0-4AE1-9E11-B00FEC18EFAD} - C:\WINDOWS\system32\cbabc.dll (file missing)
    O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\xcjfrxrw.dll
    O2 - BHO: (no name) - {A8ACF25E-C583-4325-A374-06FDFCBB0D1C} - C:\WINDOWS\system32\byvtq.dll (file missing)
    O2 - BHO: (no name) - {C004A8DA-623A-4409-B6ED-F3E3DA367792} - C:\WINDOWS\system32\tuvwvuu.dll
    O2 - BHO: (no name) - {F4CDC73D-A912-4843-930D-B933763E1CC8} - C:\WINDOWS\system32\opnml.dll (file missing)
    O2 - BHO: (no name) - {F65CECC6-9B45-4C26-92C9-8592A7E0E678} - C:\WINDOWS\system32\tuvtt.dll (file missing)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
    O4 - HKLM\..\Run: [avp] C:\WINDOWS\system32\avp.exe
    O4 - HKLM\..\Run: [SManager] smanager.7.exe
    O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\ydwctscl.dll",realset
    O20 - Winlogon Notify: cbxyvuv - cbxyvuv.dll (file missing)
    O20 - Winlogon Notify: tuvwvuu - C:\WINDOWS\SYSTEM32\tuvwvuu.dll
    O20 - Winlogon Notify: winexz32 - winexz32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as"
    type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp
      Files.
    • Then after it deletes the files click the Exit (Save Settings)
      button.
    NOTE: Pocket Killbox will only list the added files it is able to find on
    the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing

    • CTRL + C (or, after highlighting, right-click and choose copy):
    C:\pvdsjfp.exe
    C:\WINDOWS\retadpu1000272.exe
    C:\WINDOWS\system32\avp.exe
    C:\WINDOWS\system32\cbxyvuv.dll
    C:\WINDOWS\system32\efebc.dll
    C:\WINDOWS\system32\khfcyxy.dll
    C:\WINDOWS\system32\smanager.7.exe
    C:\WINDOWS\system32\tuvwvuu.dll
    C:\WINDOWS\system32\winexz32.dll
    C:\WINDOWS\system32\xcjfrxrw.dll
    C:\WINDOWS\system32\ydwctscl.dll
    C:\WINDOWS\system32\cbefe.bak1
    C:\WINDOWS\system32\cbefe.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue
    (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot, use Windows Explorer to look for the below list of files we were having Pocket Killbox delete. If you find any of them, delete them.

    Now please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  15. jagguy

    jagguy Private First Class

    Hi,

    The popup has stopped so thanks much for that. Have i deleted systems files though as given above? You sure seem to know your stuff!
    I can't believe it has worked so far and my pc seems normal.

    After reboot, use Windows Explorer to look for the below list of files we were having Pocket Killbox delete. If you find any of them, delete them?

    what files as none are given below
     
  16. jagguy

    jagguy Private First Class

    Hi,
    When running shownew.bat my pc is rebooting . It didn't crash before I ran all the above programs and nor does it crash with runkey.bat?
    I tried to reinstall shownew and again it still crashes; I am sure i followed the above instructions and didn't delete the wrong files.

    The trojan appears gone though, so that is fantastic.

    Here is runkey and hjt
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The word below should have been above! I wanted you to refer to the list of files given to delete with Killbox. The current wave of infections going around are interferring with Killbox's ability to delete them all.

    You are still infected and this could be why ShowNew will not run. Reboot into safe mode now and delete any of the below files you find. NOTE: some you will not be allowed to delete since they will be in use, run ProcessExplorer like before and look for any of the DLLs to be attach to winlogon.exe, explorer.exe, and iexplorer.exe and kill the instances seen like before. After doing that, then try to delete the files that would not delete. Let me know the final results of what would not delete.

    C:\pvdsjfp.exe
    C:\WINDOWS\retadpu1000272.exe
    C:\WINDOWS\system32\avp.exe
    C:\WINDOWS\system32\cbxyvuv.dll
    C:\WINDOWS\system32\cqcykirk.dll
    C:\WINDOWS\system32\efebc.dll
    C:\WINDOWS\system32\encovkeq.dll
    C:\WINDOWS\system32\khfcyxy.dll
    C:\WINDOWS\system32\smanager.7.exe
    C:\WINDOWS\system32\sstus.dll
    C:\WINDOWS\system32\tuvwvuu.dll
    C:\WINDOWS\system32\winexz32.dll
    C:\WINDOWS\system32\xcjfrxrw.dll
    C:\WINDOWS\system32\ydwctscl.dll
    C:\WINDOWS\system32\cbefe.bak1
    C:\WINDOWS\system32\cbefe.ini

    Also while in safe mode, run HJT and fix any of the below lines that appear:
    O2 - BHO: (no name) - {37184FED-BFDD-43C4-914F-D552E7636059} - C:\WINDOWS\system32\jkkhf.dll (file missing)
    O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\encovkeq.dll
    O2 - BHO: (no name) - {96B2E1C4-1E48-423D-BAE4-FB4D0C205FB2} - C:\WINDOWS\system32\sstus.dll
    O2 - BHO: (no name) - {CD02447D-39EB-495D-A30A-090CA12E8B2D} - C:\WINDOWS\system32\rqoll.dll (file missing)
    O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\cqcykirk.dll",realset
    O20 - Winlogon Notify: sstus - C:\WINDOWS\system32\sstus.dll


    Now see if ShowNew will run. If so, attach a new log and also a new HJT log.
     
  18. jagguy

    jagguy Private First Class

    Hi

    Here are the 3 logs as shownew worked. I searched those dll files manually to delete . My outlook express6 doesn't work as when sending /recieving messages it takes an eternity. I reintalled OE but i still fails to work and all the settings are correct.

    I didn't find any required dll's to delete.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not say search I said to use Windows Explorer to delete the files. Some of the files are still definitely there and some new ones were now added by the infection. Search will not find hidden files unless Search is properly configured. What we did in step 2 of the READ ME to enable viewing of hidden & system files and also file extensions only applies to using Windows Explorer not Search.


    Make sure that one and only one Internet Explorer browser is opened up

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of any of the below DLL files (if found) and then click the kill button.
    cqcykirk.dll
    oppmk.dll
    sstus.dll
    yayxv.dll

    After you have killed all instances of any of the above DLLs under winlogon click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on explorer.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    cqcykirk.dll
    oppmk.dll
    sstus.dll
    yayxv.dll


    After you have killed all instances of any of the above DLLs under Explorer click ok.
    (If you do not find these DLLS, just continue on.)

    Next double click on iexplore.exe and again click once on each instance of any of the below DLL files (if found) and then click the kill button.
    cqcykirk.dll
    oppmk.dll
    sstus.dll
    yayxv.dll


    After you have killed all instances of any of the above DLLs under iexplore click ok.
    (If you do not find these DLLS, just continue on.)

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {C4F4D8F2-7A94-4F57-BF54-A5CB32F93016} - C:\WINDOWS\system32\sstus.dll
    O20 - Winlogon Notify: sstus - C:\WINDOWS\system32\sstus.dll

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files
    it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and

    • choose copy):
    C:\WINDOWS\system32\cqcykirk.dll
    C:\WINDOWS\system32\oppmk.dll
    C:\WINDOWS\system32\sstus.dll
    C:\WINDOWS\system32\yayxv.dll
    C:\WINDOWS\system32\sutss.bak1
    C:\WINDOWS\system32\krikycqc.ini
    C:\WINDOWS\system32\sutss.ini
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot, use Windows Explorer (right click Start and select Explore) to look for the all of the above list of files we were having Pocket Killbox delete. If you find any of them, delete them. DO NOT USE Search. Use Windows Explorer and navigate to the C:\windows\system32 folder and look for each file. Then if found, right click on it and select Delete.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: May 19, 2007
  20. jagguy

    jagguy Private First Class

    ok let see what I have now.

    these did not appear in hjt
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - Default URLSearchHook is missing

    All stuff you said i have done.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you have not! I asked for three follow up logs and you did not attach them.
     
  22. jagguy

    jagguy Private First Class

    here are the logs
     

    Attached Files:

  23. jagguy

    jagguy Private First Class

    The system here is a little odd as i did attach the logs but they didn't appear so they were redone.
    My outlook express just doesn't work at all after another reinstall. It just hangs forever with message recieving.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is unlikely that this is due to malware. You need to check you settings for you email accounts and make sure they are all correct. Also you need to make sure you are not blocking Outlook Express in your firewall or anywhere else. Other than that, I suggest you start a thread in the Software Forum if you continue to have problems with OE.


    Your logs are clean! If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  25. jagguy

    jagguy Private First Class

    well what can i say job well done, I couldn't do it without you.

    q) why do i need to delete all the files eg VundoFix.exe file because i may need this again as well as shownew. You don't need to answer this as you have done enough already for me.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Because tools like these are constantly updating and you should always use the current versions that are online. They are small enough to just download when needed and that way you are sure to be using the proper version.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds