dwm.exe (and more) Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by cable101, Oct 6, 2010.

  1. cable101

    cable101 Private E-2

    I'm not much of a computer whiz, so I apologize in advance if I've screwed something up or I fail to make anything clear. But I've recently (within the past week) contracted some sort of Trojan that AVG and Malwarebytes can't seem to get rid of. I've always been able to handle these issues in the past, but this one is causing some issues. Here's what I know:

    AVG's scan brings up several infections and tells me it's cleaned them, but they're never actually gone.
    Malwarebytes won't run at all.
    dwm.exe is the only thing I find running in the Task Manager, and though I've managed to prevent it from starting by messing with msconfig, the problems persist.
    Initially I noticed the virus because Google search results would redirect me to other pages. I realized this was happening because it had put me on some proxy, which I disabled.
    On start-up, I get two error messages about Registry stuff. I haven't noted the specifics, but I can do that if necessary.
    Opening Firefox brings up a "[Javascript Application]" error telling me "TypeError: Components.classes[cid] is undefined". I click okay, and Firefox opens.
    Everything runs well enough for a while, except for one odd quirk: if I type a URL into my address bar, hitting Enter won't load the page - I have to manually click the Go button.
    Once my computer runs for a long enough period of time, things start getting worse. Firefox will close for no apparent reason, and will do so more and more rapidly each time I try to restart it. Eventually, it will refuse to load images and become almost unusable, at which point I restart my computer to start everything over again.
    Unfortunately, I can't shut down properly. Explorer.exe seems to close, but my desktop background just sits there and doesn't do anything further - I left it there overnight, and it never shut down. I have to press the power button myself.
    Occasionally, there will be problems with other programs, but it's mainly a case of things closing once my computer has been running for too long - I assume my memory is just getting eaten up over time.

    I can't seem to find any helpful information online, so I come to you guys. I have no idea how this all began, as I can't even think of anything I'd downloaded or installed at the time the problems started.

    I've tried to follow the instructions here as best I can, and I've attached the logs as instructed. No matter how much I uninstall/re-install/re-name Malwarebytes, it won't run. I get this message:
    mbam.exe - Unable To Locate Component
    This application has failed to start because MSVBM60.DLL was not found. Re-installing the application may fix this problem.

    The same message arose for "analyse.exe" in MGtools.exe, but apart from that message, the scan for that program appeared to run smoothly.

    Hopefully somebody can help me out with this one, because I'm stumped. Thanks in advance.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    dwm.exe is not malware. The process is Desktop Window Manager (DWM) it handles the graphical effects in windows.

    Also you should not be making use of MSConfig to control start up's. You should use a better alternative which is to use a start up manager.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  3. cable101

    cable101 Private E-2

    Well, that would be true, except I'm running XP. ;)
    (It's my understanding that dwm.exe is Desktop Windows Manager only in Vista/Windows 7, where there are actual animations to manage.)

    I know, it was just a way to prevent dwm.exe from running on start-up, not a permanent fix to my problems. I changed it back to normal for all of the logs and whatnot, as instructed.

    I've attached my log for TDSSKiller. Thanks for the timely assistance!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      dwm.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Also navigate to C:\MGTools\analyse.exe and right click and run as admin to run it. Do a system scan and save a log file to attach here.
     
    Last edited: Oct 7, 2010
  5. cable101

    cable101 Private E-2

    Well, this is embarrassing. SystemLook says dwm.exe is no longer on my computer:
    Which seems accurate, because it's no longer in any of the places I found it before. I guess one of the programs actually did manage to get rid of it!

    A few of the problems still persist, however, while others appear to have been cleared up:
    I can actually shut down now, and the messages that used to pop up on system start-up no longer appear.
    However, the odd address bar thing continues, and the Javascript error still pops up when I start Firefox. Not sure if I'll have the same system deterioration if my computer runs for long enough - I haven't left it on for very long over the past 24 hours.
    But perhaps most notably, something is definitely still screwing with my computer because I still can't run Malwarebytes or MGTools' analyse.exe - even running it as Administrator, like you instructed. I get the same message about not being able to locate MSVBM60.DLL.

    Thanks for the help you've provided so far!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are just missing the Visual Basic 6 Runtime libary. Download and install service pack 6 for visual basic 6.0.
     
  7. cable101

    cable101 Private E-2

    Wow, you're right. Ugh, five minutes of research and I could have found that out myself. I just assumed it was a case of malware preventing me from running antirvirus programs, rather than a simple problem like this. My apologies - I feel pretty dumb. :-o

    I'll run Malwarebytes and analyse.exe and copy the results here.
     
  8. cable101

    cable101 Private E-2

    Okay, here are the logs for Malwarebytes and HijackThis.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to use the update tab within malware bytes and once done, run another scan and fix anything it may find.

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:
    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50370

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:50370

    After clicking Fix exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    And tell us how things are running for you now. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds