My active desktop and wml.exe??

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Xferla, Mar 27, 2008.

  1. Xferla

    Xferla Private E-2

    Hello.. I terribly apologize I'm posting something that is frequently posted around, I DID read this but since I barely understand anything about making logs or.. I don't even know where/what my Windows registry is.. I'm really stupid..
    But I still hope someone could help me figure out what my problem is and hopefully help me fix it.

    Okay, so, I want my active desktop back. I like adding small gif images over my wallpapers sometimes. Makes it cheery. But ever since for some reason some security warnings about some wml.exe started popping up, and an exclamation mark icon in my tray showed up saying I have malware and another screen showing up from time to time that always leads me to some site with some PC cleaner software or something, ..my active desktop won't work! I decided to see if its something in the running processes and terminate it but when I hit Ctrl+Alt+Del it said that Task manager is blocked by the administrator!?

    I ran AVG, Spyware Doctor and AdAware and removed/deleted/etc. anything it had caught. I restarted and tried to do my active desktop thing because things seemed normal.. (also, my Task Manager would open now.) but when I tried adding something and hit Apply, it didn't show up. I got worried and just as I was about to run more antivirus programs, those things with the wml exe and the Pc Cleaner started showing up again! I googled "wml.exe" and found out its malware. Is that why my active desktop won't work? I also saw that its supposed to be in C:\WINDOWS or C:\WINDOWS\system32 and decided to find it and delete it myself (first checking in Task Manager if it is in runing processes to terminate it because I won't be able to delete it if it running), but.. there wasn't any wml exe anywhere. I checked this page and looked it up under the other exe-s names it could be but there weren't any.
    So then..
    Okay, I'm almost done.. please excuse me, I'm really panicked. So, I downloaded that program and it found two things, C:\WINDOWS\system32\hwdsjori.exe and dwnrpofk.dll in C:\WINDOWS but since they want you to buy the program to do its work I had to uninstall it, terminate the exe and delete it manually and its dll too. Rebooted and was hoping I got rid of it and finally my active desktop would WORK.. but no.

    The stupid [​IMG]tray icon and tthe PC cleaner site started popping up again. I got the Spybot Search and Destroy or whatever it was and scanned and it.. well.. found a lot of things. Bad things! When it was done and I ran the Fix thing, the program.. got stuck and I had to terminate the exe. Next thing I tried was Reanimator. It got that exe from earlier and the dll again! And a lot of other things.. I let it change the registry values or delete everything I thought could be related and rebooted (with getting a scary blue screen between the XP logo loading and the welcome screen with DOS-like lines of commands that this and this and that files were deleted and those and those were rewritten.. that really scared me.. but afterwards it went away and windows started normally but I removed this Reanimator, just in case..).

    Now I don't have unnaturally high CPU usage percentage and weird exe-s, no tray icons or windows security malware messages or.. PC Cleaner pop-ups.. but I'm sure that thing is still somewhere there BECAUSE MY ACTIVE DESKTOP STILL DOESN'T WORK!!

    Okay. I'm done. Let aside I want my active desktop back, I want that malware gone... help? Please? I've been fighting this for 8 hours now... please?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Please follow the steps as they are laid out below and attach all the logs requested, once finished these steps, you may well still have the malware your describing above but with the logs, we will be able to work of from the data collected what malware fsmily it is, name/type of malware, then our malware experts will post some further tailored instructions for you to action.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds