| |
Antivirus World Forum
Re: Can not Rid my "Downloader - YH" or "nipt.exe"
Posted By: Nemo In Response To: Re: Can not Rid my "Downloader - YH" or "nipt.exe" (Tim)
Date: Sunday, 10 April 2005, at 3:29 a.m.
Hey everyone,
I just cleaned a winxp system with this trojan on it.
Here is the manual process I used:
1) Download cwshredder & hijackthis2) Turn off System Restore
3) Boot into safe-mode with command prompt
4) Login as Administrator
5) Re-write permission on the downloader-yh file.
cacls filename.exe /G administrator:F
(mine was c:\windows\system32\knzalv.exe)6) Delete the downloader-yh file.
del filename.exe
(If this doesn't work use your OS cd and boot into the recovery console to delete it.)7) Delete the prefetch version
(c:\windows\prefetch)8) Delete everything in
C:\Documents and Settings\User\Local Settings\Temp
[del *.* in that directory]9) Delete everything in
C:\Documents and Settings\User\Local Settings\Temporary Internet Files10) Reboot into safe-mode
11) Run command "msinfo32"
Look at "Software Environment"->"Startup Programs"
Find where the file was launched (Registry versus Startup sub-menu) and delete them
[Mine was in
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]12) Run cwsshredder (fix IE problems)
[Mine reinstalled itself after running IE]13) Run hijackthis (check only the options related to your filename.exe for your downloader-yh virus)
14) run a virus scan program (mcafee picked up the trojan initially but couldn't delete it. this is just a sanity check)
[I also ran SpyBot, and Adware]15) Reboot into normal user mode
16) Run cwsshredder and hijackthis again... make sure todo this before running IE!
[This will probably need to be ran for each user on the computer]17) Turn on System Restore
I hope this helps everyone out. It was a real pain to get rid of.
Good luck,
~Nemo
| |
Antivirus World Forum is maintained by Administrator with WebBBS 5.12.