W32/Spybot.Worm
Date: 10/25/05
(IT Professionals) Keywords: google
Does anyone have any experience removing this from a Windows 2000 system w/o rebooting into Safe Mode? We are running SAV corporate 8.x on most of the systems in our network, and it is not able to remove MSAOL32dll.exe from the system. I am also unable to kill the process from the task manager.
I've been to SARC.com and done google searches for it, and haven't found any way to remove it other than rebooting the system into safe mode. Unfortunately, I have two servers that take miracles to reboot (they control our entire floor) that have been infected.
x-posted to it_admin
EDIT: got it covered. pokemone recommended "process explorer" from sysinternals. It allowed me to kill the process and SAV took over from there.
Source: http://community.livejournal.com/itprofessionals/27726.html