Credit to FoolishTech :
Author of
D7, a
free PC technician's multi-tool.
www.FoolishIT.com
****************************************
For anyone else following the thread, here’s my removal procedure for now which has been working for me:
1. Fire up D7, click the D7 menu > IFEO Modifier. Find and select the rogue executable(s) in the drop down list. (e.g. 123587654:12987432.exe, but could be others in addition - I'm seeing a new variant this morning that doesn't use ADS...) Hit the CREATE button. Now it won’t be able to execute itself and stop you from standard removal.
2. DO NOT DELETE THE MALWARE YET. SIMPLY REBOOT THE PC. (When the PC reboots you’ll note the malicious EXE is no longer running.)
3. Use TDSSKiller and cure anything it finds. Alternately, there are a few specific tools for this that may be useful to add to your flash drive: I have not yet used them, but note that neither tool does step 7 below, so don’t skip that final step!
http://anywhere.webrootcloudav.com/antizeroaccess.exe and
http://www.malwarecity.com/community...ds&showfile=34
4. REBOOT AGAIN.
NOTE: I haven't seen this infection in the MBR yet, but who knows, a new variant may come out and infect this... so now would be a good time to FIXMBR. currently this step isn't necessary however.
5. Open D7, goto Tweaks tab > NTFS Junctions. Scan the Windows directory. When found, you should see one junction probably named $NtUninstallKB32069$ or similar. Highlight the directory, click Destroy Junction. When prompted, delete the directory underneath - unless you wish to visually inspect it. Now the malware is really gone.
6. Follow up with the usual scans as if it were a normal infection. Don't forget to delete the random numbers directory containing the ADS in %windir% (e.g. 123587654) if it exists, and the other rogue EXEs you created an IFEO for.
7. Run the Repair Permissions function on D7’s malware or repair tab. This fixes all of the ACL problems caused by the malware, should fix the antivirus (confirm it), and also MSSE installation or any other Installer error 2203’s that would otherwise occur. __________________