In the registry location
there is a key called
with a value of
that i picked up from somewhere as part of the surfsidekick virus
When i change or delete this registry value it immediately changes back to "repairs303169590.dll"
I have tried to delete this file with Unlocker, killbox, deleteReboot, and hijackthis (via the delete on reboot) with no success. Unlocker fails because the "F:\WINDOWS\system32\repairs303169590.dll" file is locked by the [System Process] process (as well as every other process). Delete on reboot fails because "AppInit_DLLs" loads before the other boot commands are run.
I have tried writing a dos batch file that continuously loops and merges an empty string to the AppInit_DLLs value and while running it (or several instances of it) cold rebooting or regular rebooting. None of these things have worked.
Does anyone know how to delete a file like this (or have any ideas about it)?