wgsdgsdgdsgsd.exe removal & Repair Safe Mode Operation

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by joliett, Dec 30, 2012.

  1. joliett

    joliett Private E-2

    I got hit by the virus wgsdgsdgdsgsd.exe three times in the last 3 weeks. It came from XXX sites, but since I am unafraid of viruses, I keep going back for more challenges. So I finally learned the easy way to get rid of this virus. If I had no Norton backups I would never have been able to figure it out.

    First off, my firewall caught the file, asked permission, and I prevented it from running. But the file was still present in Windows\system32 on my disk. I tried to delete it...I couldnt. I tried to end a possible linked process with WINDOWS TASK MANAGER (Ctrl-alt- del), but Task Manager wouldnt run. Humm...I also knew from past experience with this virus, that SAFE MODE would NOT run (Blue Screen of Death)- even after the virus was deleted.

    RogueKiller[/url"][/url] available here on MajorGeeks came to mind...Always have that file on your hard disk! IT FOUND THE VIRUS chain and deleted the process.

    BUT, the file wgsdgsdgdsgsd.exe was still in Windows\system32. BUT this time I could easily delete it! And double check check that it's not in your RecycleBin.
    Now, the trickiest part...SAFE MODE will still not work...even though the virus chain is gone. Previously I had to reformat and load my hours old backup, and once I swear even a long reformat didnt work - I couldnt get into SAFE MODE...just that blue screen after rebooting. I had to write zero's to the drive and reinstall my backup - which worked. Except I got that virus again twice more.

    Here is how to restore SAFE MODE operation again:
    Run regedit and scroll to
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot
    When you try booting into safe mode on the machine that has this key deleted, you will receive the BSOD.

    Go to THIS[/url] page and see how easy it is to repair the registry with a simple registry download fix...Make a backup of your registry key after your computer is repaired, so you will always have it available.

    ALSO, perhaps as a result of the virus, remnants was found in the JAVA cache with AVIRA
    To manually delete them go to:
    C:\documents and settings/user/local settings/Application Data/Sun/java/deployment/cache/6.0/
    either delete ALL the cache files - or scan that location with AVIRA from within Windows Explorer
    Voila...and that's it!!

    Here's a summary:
    SUMMARY:
    1. Dont allow wgsdgsdgdsgsd.exe with ZoneAlarm or your firewall
    2. Run RogueKiller
    3. Run ccleaner
    4. Navigate to c:\Windows\system32 -- SHIFT-DELETE wgsdgsdgdsgsd.exe
    5. Run AVIRA through IE on
    C:\documents and settings/user/local settings/Application Data/Sun/java/deployment/cache/6.0/
    6. Run SAFE BOOT...XP PRO from HERE[/url]
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to the Malware Removal Forum.

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. joliett

    joliett Private E-2

    The links in my post above didnt translate properly, so here they are again:

    RogueKiller is available here at MajorGeeks.
    The SAFE MODE repair information is available here

    I am not attaching any logs since I have successfully removed this virus. My post was to help another user in trouble.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds