Trojan Removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cubbiefanshaun, Apr 15, 2006.

  1. cubbiefanshaun

    cubbiefanshaun Private E-2

    Hello all, first post to the board and amazed the help it offers. I went through the Read me first step for step, but keep getting the same thing over and over again. Upon looking at what adaware kept finding and the warning from windows defender upon startup, it is the trojan winsync. I downloaded the tools FindQool, RKFiles, and WinPFind, and have attached the appropriate logs. Also attached it the HJT text file and bdscan.txt. Panda Active Scan would not run because of an error on the web page. Any help on ridding my computer of this annoying pest would greatly be appreciated.
     

    Attached Files:

  2. cubbiefanshaun

    cubbiefanshaun Private E-2

    The attached WinPFind file is attached below.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's get started by fixing your Look2Me infection. Run the below and attach the requested log:

    Look2Me VX2 Removal

    Then also attach a new HJT log.
     
  4. cubbiefanshaun

    cubbiefanshaun Private E-2

    Ran the programs and attached the files.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Program Files\??crosoft.NET\ntvdm.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
    O4 - HKLM\..\Run: [w03fa3e7.dll] RUNDLL32.EXE w03fa3e7.dll,I2 00032296003fa3e7
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\woqkwi.exe reg_run
    O4 - HKCU\..\Run: [Aora] "C:\DOCUME~1\SHAUNA~1\APPLIC~1\CROSOF~1.NET\winword.exe" -vt yazr
    O4 - HKCU\..\Run: [Czypht] C:\Program Files\??crosoft.NET\ntvdm.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
    O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\??crosoft.NET <--- the whole folder
    C:\Documents and Settings\SHAUNA~1\Applications Data\CROSOF~1.NET <--- the whole folder
    C:\WINDOWS\system32\w03fa3e7.dll
    C:\WINDOWS\system32\woqkwi.exe
    C:\WINDOWS\system32\dmonwv.dll
    C:\Program Files\PartyPoker
    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. cubbiefanshaun

    cubbiefanshaun Private E-2

    OK, followed everything step for step. I ran into a problem when I was deleting the objects out of the system32 folder in safe mode. The first file w03fa3e7.dll was not in the folder, the second woqkwi.exe was there, but after attempting to delete, the "could not delete" error would pop up and then the file would disappear and I never could locate it again. The last one dmonwv.dll would not allow me to delete saying the file was in use like before. I checked the processes and didn't see anything out of the ordinary. Anyway, I went ahead and ran the hijack this and notice the winsync was back on the log. So, that is where it stands as of now. I attached the hijack file for you to look at. Thanks for all the help on this matter!

    Shaun
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As per the READ & RUN ME directions, you must not use Spybot's Teatimer. It will get in the way of fixes. Ity was not running in you first HJT log but it is now. Please disable it, Also, uninstall Windows Defender while we work on this.

    Where did the below two items come from? What have you been installing/downloading?

    1) O4 - Startup: Resume Windows Update Installation.lnk = C:\WINDOWS\Windows Update Setup Files\ie6setup.exe
    2) Also look in Add/Remove programs and uninstall MatrixScreenSaver if found. Read the below about this program:
    http://www.bleepingcomputer.com/startups/mss.exe-2702.html


    After disabling Teatimer and uninstalling MatrixScreenSaver, and Windows Defender, attach a new HJT log.
     
  8. cubbiefanshaun

    cubbiefanshaun Private E-2

    Ok, uninstalled windows defender and disabled teatimer in spybot. Checked in add/remove programs and did not find matrixscreensaver, but you will still notice in the hijack log. As far as the programs trying to install, I was not attempting to download/install anything. I am actually communicating through another computer with my laptop(infected) next to me transfering hijack files. The only solution I can think of as to where they came from is when I was booting to normal mode I had the wrong box checked from msconfig which was selective start. Also, a dvd decoder upgrade window pops up now after startup and a window stating "Setup has detected a newer version of Internet Explorer already installed on this system. Setup cannot continue." Anyway, the updated hijack log is attached, and hopefully no more kinks will pop up, thanks again for all the help!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is due to this line:

    O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async

    which comes from this: http://support.microsoft.com/default.aspx?scid=kb;en;306331

    You probably do not need this unless you knowingly did this for some reason. So I'm going to include it in a list of things to fix below.

    That is due to one of the items I was questioning.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\WINDOWS\system32\dvdupgrd.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [MatrixScreenSaver] C:\DOCUME~1\SHAUNA~1\LOCALS~1\Temp\mss.exe
    O4 - HKLM\..\Run: [DVDUpgrade] DVDUpgrd.exe /async
    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\woqkwi.exe reg_run <--- this will probably come back! We need to locate some other hidden files.
    O4 - Startup: Resume Windows Update Installation.lnk = C:\WINDOWS\Windows Update Setup Files\ie6setup.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Documents and Settings\SHAUNA~1\Local Settings\Temp <--- it would be best to delete all files in this folder. Only ones from the current date may be denied since Windows will be using them.
    C:\WINDOWS\system32\woqkwi.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Now run the below procedure and attach the requested logs so we can work up a full fix for the WinSync problem:

    Qoologic/Winsync/Kavsvc
     
  10. cubbiefanshaun

    cubbiefanshaun Private E-2

    Here we go, did all the steps you requested and attached the appropriate logs. Only thing was the woqkwi.exe file was not there to delete. Other than that, everything went smooth. I have not connected it to the internet yet, thinking that would affect what has already been done. If I need to connect to see how things are going, please let me know. I will not connect until I hear from you. Anyway, the files are attached and look forward to the next step.

    Thanks!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later to run it.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click OK.

    Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.

    C:\dialler.exe
    C:\WINDOWS\SYSTEM32\FY20.DLL
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\system32\pygvp.dat
    C:\WINDOWS\system32\woqkwi.exe
    C:\WINDOWS\system32\fbvcfsc.exe
    C:\WINDOWS\system32\eusaeoa.dll
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\xqwi.exe


    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself. However BOOT INTO SAFE MODE during this reboot and do not run anything but what I request. DO NOT open any browsers!

    Please run HijackThis and click Scan and select the following line (if may not be there just continue to the next steps if it is already gone) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\woqkwi.exe reg_run


    Now exit HJT
    Run Windows Explorer and double check to make sure the below files are all deleted (some we already got with killbox):
    C:\dialler.exe
    C:\WINDOWS\SYSTEM32\FY20.DLL
    C:\WINDOWS\system32\dmonwv.dll
    C:\WINDOWS\system32\pygvp.dat
    C:\WINDOWS\system32\woqkwi.exe
    C:\WINDOWS\system32\fbvcfsc.exe
    C:\WINDOWS\system32\eusaeoa.dll
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\xqwi.exe

    Now reboot into normal mode and after reboot double check the same HJT entries I had you fix above and if any still remain, fix them again a second time.

    Now attach a new HJT log and a new log from FindQool

    Also tell me how things are working!
     
  12. cubbiefanshaun

    cubbiefanshaun Private E-2

    Attached are the files you requested. After running killbox and removing the listed files, nothing else was found when using windows explorer. I still have not connected this computer to the internet, is it ok to do so now to check things out? Just let me know and if there are any other steps I need to do.

    Thanks!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks good! But before you connect it to the internet you need to get an antivirus, an antisypware blocker and other tools, and a real firewall (a big must).

    Here is the order of what you should do BEFORE you connect to the internet

    • If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.
    • Use whatever PC you have been using to refer to the below link :
      • How to Protect yourself from malware!
    And from this the above link download and installed the below
    • AVG antivirus in step 2 - you will not be able to update online but updates can be download from AVG Anti-Virus Updates
    • Download and install ZoneAlarmFree firewall from step 2
    • Download and install SpwareBlaster and enable all protection - get updates and renable new protection later
    • from step 5 Download and install Spybot and skip the update process while installing since you are offline. But make sure you leave the SDhelper function enabled and DO NOT use Teatimer. Also immediately use the Immuninze feature.
    • from step 5 Download and install MS Windows Defender (unless you have another full time blocking program you purchased for this PC. Something like Spy Sweeper).
    • Download and install FireFox from step 7
    • Complete steps 6, 9 and 10
    Now reboot the PC and connect it to the internet and then immediately go back to the how to protect thread and run all other steps like steps 1 & 8 and get all updates for all programs.
     
  14. cubbiefanshaun

    cubbiefanshaun Private E-2

    WOOOOOOOHOOOOOOOO! Everything is running great! Thanks for all the help, I really really appreciate it. Installed all the programs and updated them and feel very good about the protection. Once again, thanks for all the help you provided! Major Geeks.com ROCKS!

    Shaun
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds