winsync & syncroad

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rpirrone, Oct 10, 2004.

  1. rpirrone

    rpirrone Private E-2

    I've got a twist on the Winsync.exe problems you guys have been dealing with. While browsing the net a few hours ago and running a McAfee firewall, it popped up saying it detected a trojan and the trojan had been deleted. Obviously this was not the case as winsync now infects my computer. End process tree is not working, but here's the kicker...I don't have a run option to get into the registry neither in safe mode or standard, nor do I have any programs listed under "add/remove programs" There are 44 processes running including eber.exe, addtp.exe, lsass.exe, atltt.exe, amongst others I've never heard of. The only folder I can get into is the My Computer folder. When I click on "Start/all programs", nothing comes up. None of the shortcuts on the desktop work either, as I was trying to get into McAfee and see if I could clean this off. Appreciate any help you guys have...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! As I indicated in the other thread where you posted:

    Please follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Try shutting down some of the processes you see running that you do not recognize, the following seem questionable: eber.exe, addtp.exe, atltt.exe
     
  3. rpirrone

    rpirrone Private E-2

    chaslang,
    After your first posting, I read the initial procedures and was only able to follow a couple steps due to the other problems. Let me begin by saying my system was full up until this trojan appeared today, so I'm not sure if I got something along with WinSync and SyncroAd or what. Specifically, following the steps in the link you sent,
    Step 1: Disabling system restore --- can't do it because there is no computer icon on my XP desktop.
    Step 2: Network security --- can't do it because the "run" option has been removed from my start menu
    Step 3: Enabling hidden files --- done
    Step 4 and subsequent steps: unable to download any programs to scan for viruses / spyware as buttons and options that I would normally have to open IE and do a search do not work

    What I have done in safe mode is manually find the WinSync folder and SyncroAd folders and removed the files. I have also gone into the registry editor (again not via Run/regedit, but via start/my computer/C/windows/regedit icon and removed the SyncroAd file there. Then I went into msconfig/startup tab and unchecked specific programs that should not be running.

    None of these things, with reboots have restored my lack of ability to run any programs on the desktop, nore have they restored the "run / find" options under the start menu.

    What else do you think I can try, and does this problem sound like a different trojan that you're familiar with?

    Thanks for the help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    1) To disable system restore you could have used a similar method to how you ran regedit.
    Click Start but where you see My Computer, right click on it and select Properties. Now Click the System Restore tab and Turn off System Restore.

    2) For the services isssue (which you probably do not need to do anyway since this does not sound like an HSA or about:blank hijack), you could just open a command prompt window by click Start and select Command Prompt. If you do not see the command prompt icon then click Start, All Programs, Accessories, and now Command Prompt. When that window opens, just type in "services.msc" (without quotes) and hit enter. But as I said you don't need this.

    Can you run Task Manager by hitting CTRL-ALT-DEL and look to see what processes are running? There are tools that can copy the whole list to a file but you say you cannot download anything. Look for the SyncroAd and/or WinSync. If found, select WinSync. Right click on it and choose "end process tree". Now look to see if the directories are back and delete them.

    Do you have HijackThis on the computer? If not can you get it there and do a scan with it and post the log?

    You may also want to try right clicking the Start button and select Properties. Then make sure Start menu is checked and click Customize. Then click Advanced in the new window that comes up. Turn back on any items you need that are disable (i.e. the Run command and anything else). See if this helps.
     
  5. rpirrone

    rpirrone Private E-2

    Chaslang,
    Amazingly, under the customize start menu you directed me to, "run" IS checked as a display option, yet something is inhibiting it from being displayed. Unfortunately, I don't have hijack this on that computer and since I can't add/remove programs or connect to the net, I can't think of any way to install it. I tried a McAfee re-install yesterday to see if I could get that running and clean off whatever trojan was dropped, but as soon as I pop the CD in the drive and double click on the install icon, nothing happens.
    The only options I am afforded right now are task manager and navigating through the my computer folder to delete files. This is how I was able to "end process tree" yesterday and to delete the WinSync and SyncroAd files that I could find in the C:\Windows folder. Internet access is also inhibited, so I can't do any of those free online scans.
    From what I can tell, it sounds to me like something in addition to WinSync and SyncroAd corrupted this machine and affected McAfee as well as every reboot is coupled with a error message saying to reinstall McAfee.
    Here's a list of the processes running, the odd ones being the four svchost.exe files and the ones listed as "local service" and "network service" under the "User" column, since this computer is not connected to the internet.

    Listed under "Local Service" as user: alg.exe, svchost.exe

    Listed under "Network Service" svchost.exe

    Listed under "Owner" as user: McVSEscn.exe, mcagent.exe, taskmgr.exe, tgcmd.exe, kbd.exe, hpmon05.exe, hpwuSchd.exe, hpqCmon.exe, hpsysdrv.exe, explorer.exe,

    Listed under "System" as user: OPXPApp.exe, McShield.exe, svchost.exe (listed twice), ScsiAccess.exe, omniServ.exe, MpfService.exe, mcvsrte.exe, KodakCCS.exe, spoolsv.exe, lsass.exe, services.exe, winlogon.exe, csrss.exe, smss.exe, system and system idle process

    If I can just restore some functionality to the system (i.e. being able to open McAfee, or re-install, or connect to the internet to do an online scan) then I think we might be on our way to fixing this thing, but right now, the system seems crippled.

    Thanks so much for all your help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HijackThis does not require an install. All you need to do is download it on another PC, extract the executable from the ZIP file, and copy it to a floppy (of CD - waste of a whole CD but there cheap) and then bring it to the problem PC and run it (if it lets it run).

    I would copy CWShredder (extracted executable file) and McAfee Avert Stinger to that floppy too. And run each of them. None require installs.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds