This infection is best if you follow all these instructions
* Please download the
Killbox by Option^Explicit.
[color=\"red\"]*In the event you already have Killbox, this is a new version that I need you to download[/color].
* Save it to your desktop or a folder
*Download and then Install
Ewido Trojan ScannerWhen installing, under "Additional Options"
Uncheck "Install background guard" and "Install scan via context menu".
When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We'll fix that later
From the main ewido screen, click on
Update in the left menu, then click the
Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
*Download and UNZIP to a folder or desktop
Fixdesktop.zip, so you now have Fixdesktop.reg extracted
*Download and UNZIP to a folder or desktop
StHome.zip so you now have STHome.reg extracted
[attachment=223:attachment]
Please Print this out or save these instructions to a Notepad file and save it to your Desktop or a folder
Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:
Security IGuard
Virtual Maid
Search MaidExit Add/Remove Programs.
[color=\"red\"]I need you to copy all of the Killbox file paths below and paste them into Notepad.[/color]* Please double-click
Killbox.exe to run it.
* Select "
Delete on Reboot".
* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C
[color=\"purple\"]Killbox file paths between dotted lines[/color]=========================================
C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\system32\hhk.dll
C:\Windows\System32\wldr.dll
C:\Windows\System32\helper.exe
C:\Windows\System32\intmon.exe
C:\Windows\System32\shnlog.exe
C:\Windows\System32\intmonp.exe
C:\Windows\System32\msmsgs.exe
C:\Windows\system32\msole32.exe
C:\Windows\System32\ole32vbs.exe==========================================
* Return to Killbox, go to the
File menu, and choose "
Paste from Clipboard".
* Click the red-and-white "
Delete File" button. Click "
Yes" at the Delete on Reboot prompt. Click "
No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.
[color=\"red\"]
While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.[/color]
[color=\"purple\"]
While in Safe Mode, please do the following:[/color]
Run Ewido, and run a full scan. Clean any infected files found, and save the log from the scan.
Next, please enable viewing of hidden files as follows:
1) Go to My Computer, and click on the "Tools" menu
2) Click "Folder options"
3) Select the "View" tab
4) Make sure "Show hidden files and folders" is selected
5) Make sure "Hide extensions for known file types" is unchecked
6) Make sure "Hide protected operating system files (recommended)" is unchecked
Delete the following folders, if they exist:
C:\Program Files\
Search Maid <-this folder
C:\Program Files\
Security IGuardC:\Program Files\
Virtual MaidC:\Program Files\
STLinksC:\Program Files\
STHomePageC:\Windows\System32\
Log FilesDouble Click on
Fixdesktop.reg and allow to merge to the registry
Double click on
STHome.reg and allow to merge
Restart back to Normal Mode
Do the following
1. Open the Control Panel.
2. Open Display Properties.
3. Click the Desktop tab.
4. Change your background>>You can change it back later if preferred
5. Click the Customize Desktop button.
6. Click the Web tab in the Desktop Items window.
7. Uncheck "Security" or Make sure all checkboxes in this window are un-checked.
OK your way out
Log off your user account and log back on again if anything unchecked
Your not running any Anti-Virus software
If yours is disabled, enable it now and update and run a full system scan
If you don't have your own
I recommend that you download and Install the free version of AVG 7
This will update for free for the life of the product
Go to this link
http://free.grisoft.com/doc/2/lng/us/tpl/v5Scroll down to
VG Free Edition installation files
File Version
avg70free_308a468.exe <-click this link
Save the Installer to desktop
Install AVG and restart the computer if prompted
Ensure AVG is right up to date and run a full system scan
Restart the computer again if anything is fixed
Post back a fresh hijackthis log and the Report from Ewidos when done