I’ve just been searching Yahoo! for winwea32.dll, and yes, it does seem to resist KillBox.
http://www.2-spyware.com/forum/topic609.html
However, it doesn’t seem to be able to resist The Avenger!
http://forums.afterdawn.com/thread_view.cfm/352205
We need to adapt -kemisti-'s advice to suit you.
1. Please download http://swandog46.geekstogo.com/avenger.zip The Avenger by Swandog46 to your Desktop.
[]Click on Avenger.zip to open the file[]Extract avenger.exe to your desktop
-
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Quote: Files to delete:
C:\WINDOWS\system32\tfvf.dll
C:\WINDOWS\system32\765b3a5.exe
C:\WINDOWS\system32\c903ca1d.exe
C:\Documents and Settings\Mones\Local Settings\Application Data\765b3a5.exe
C:\Documents and Settings\Mones\Local Settings\Application Data\c903ca1d.exe
C:\WINDOWS\SYSTEM32\winwea32.dll
C:\WINDOWS\system32\cmd.dll
C:\WINDOWS\system32\notepad.dll
C:\WINDOWS\system32\wuauclt.dll
Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
- Now, start The Avenger program by clicking on its icon on your desktop.
[] Under “Script file to execute” choose “Input Script Manually”.
[]Now click on the Magnifying Glass icon which will open a new window titled “View/edit script”
[] Paste the text copied to clipboard into this window by pressing (Ctrl+V).
[] Click Done
[] Now click on the ]Green Light to begin execution of the script
[] Answer “Yes” twice when prompted.
- The Avenger will automatically do the following:
[*]It will Restart your computer. ( In cases where the code to execute contains “Drivers to Unload”, The Avenger will actually restart your system twice].)
[*]On reboot, it will briefly open a black command window on your desktop, this is normal.
[*]After the restart, it creates a log file] that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
[*] The Avenger will also have [u]backed up all the files, etc., that you asked it to delete], and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
- Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log ] by using Add/Reply
Post a fresh HJT log.
In your case, you will need to enter only the following:
[s]Quote:[/s] Files to delete:
C:\WINDOWS\SYSTEM32\winwea32.dll
Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
EDIT: Removed ‘Quote’ above as it was cut and pasted by mistake. The Avenger interprets text before commands as comments, so it will not have affected the running of the application.