illukka
Expert-Emeritus
ok, could you send me the files for closer examination:
RMAgentOutput.dll
C:\WINDOWS\SYSTEM32\ExMenu.dll
C:\WINDOWS\SYSTEM32\ExPMenu.dll
C:\WINDOWS\SYSTEM32\ExTab.dll
D:\WINDOWS\system32\cmd.ftp
zip them up, then send them as attachment to
illukka AT malware-research.co.uk
remove the spaces from the addy and replace AT with @
i'll take a look at them
put a link to this thread in your message so i know where its from
as for the malware files:
locate and delete these
D:\Documents and Settings\Savina\Desktop\pumpkinpatch01.exe<<--delete this file
D:\Documents and Settings\Savina\Desktop\wcfautumnwoods.exe<<--delete this file
D:\Documents and Settings\Savina\Desktop\wcfgoldenwoods.exe<<--delete this file
D:\Local Disk (F)\WINDOWS2\SYSTEM\Comet<<--delete this folder
D:\WINDOWS\system32\cmd.ftp<<--delete this file
for the malware registry entries mentioned in the mwaw log i suggest running a scan with spybot and adaware
allow spybot to fix reditems, and for adaware allow it to fix all critical items
RMAgentOutput.dll
C:\WINDOWS\SYSTEM32\ExMenu.dll
C:\WINDOWS\SYSTEM32\ExPMenu.dll
C:\WINDOWS\SYSTEM32\ExTab.dll
D:\WINDOWS\system32\cmd.ftp
zip them up, then send them as attachment to
illukka AT malware-research.co.uk
remove the spaces from the addy and replace AT with @

i'll take a look at them
put a link to this thread in your message so i know where its from

as for the malware files:
locate and delete these
D:\Documents and Settings\Savina\Desktop\pumpkinpatch01.exe<<--delete this file
D:\Documents and Settings\Savina\Desktop\wcfautumnwoods.exe<<--delete this file
D:\Documents and Settings\Savina\Desktop\wcfgoldenwoods.exe<<--delete this file
D:\Local Disk (F)\WINDOWS2\SYSTEM\Comet<<--delete this folder
D:\WINDOWS\system32\cmd.ftp<<--delete this file
for the malware registry entries mentioned in the mwaw log i suggest running a scan with spybot and adaware
allow spybot to fix reditems, and for adaware allow it to fix all critical items