Thursday, April 10, 2008

10-april-2008

Infection / hack cleanup.

yinhu.dll was a fun one. redeption42.exe lots of 6letters.3letters ones (tcfkwi.exe and .qwe) dcom.exe dcomserver.exe smss.exe in the windows directory (not win process).

Just a whole barrel o fun. in any case, the 'normal' process I use is try to delete the offending file right off. If it does not work, install 'unlocker', then cacls /d everyone so it cannot be reloaded then try to delete it agian. unlocker will pull up the process that has it, let it kill it (if possible). After a reboot, I can de-cacl it and delete it. It takes a while to do, but it works.