instructions for manual removal of Dumarin / Dumarin.g / Dumaru-ak
1)Kill the following running processes (if they exist):
setupex.exe
svohost.exe
swchost.exe
svchost.exe (all instances)
2)Delete the following files (if they exist):
system32\setupex.exe
system32\svohost.exe
system32\swchost.exe
(!!do not delete system32\svchost !!)
3)Show hidden folders and from every user profile delete svchost.exe(if it exists):
c:\Documents and settings\%username%\Start Menu\Programs\startup\svchost.exe
(don't forget to remove it from the "Default User" profile also)
4)From the following registry location:
HKeyLocalMachine\Software\Microsoft\Windows\Current Control Set\Run\
Delete all keys that refer to any of the programs in step 1.
5)Modify the following registry location:
HKeyLocalMachine\Software\Microsoft\WindowsNT\Current Version\Winlogon
In the string value named "Shell", right-click and modify the value from:
[Explorer.exe c:\winnt\system32\svohost.exe]
to simply:
[Explorer.exe]
6)Open the system.ini file (start, run, sysedit). If there is an entry for
Shell= , it should only say:
Shell = Explorer.exe
If there is another executable listed afterwards, delete that part of the string.
(essentially the same as step 5)
On reboot, log in and check your profile for the svchost.exe file in
Start\programs\startup. If it is not there, the machine is clean.
John Richardson