Please help with Win32 and other malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by klix, Jul 3, 2007.

  1. klix

    klix Private E-2

    About two months ago, out of nowhere, my computer showed a blue screen saying something like 'Windows had to shut down to prevent damage...Beginning dump of physical memory'. After rebooting and seeing pop-ups, it was obvious I had a problem. I had AVG free at the time and ran it. It said I had tons of malware which it attempted to heal, some of which contained 'win32'. So I looked that up and found out it was pretty vicious for someone my caliber. Still I ran AVG Free and Ad-Aware SE, but it just kept coming back. I ran Windows OneCare a couple of times, and TrendMicro, but then I found this site.
    I tried to go through the instructions on RUN ME FIRST as best I could, but the problem's still on my computer. I ran GetRunKey and ShowNew before I was supposed to, but I erased those log files. I ran the programs again when I should have, so I hope that isn't much trouble - sorry. Also, when I ran BitDefender, as it neared the end of the scan, Internet Explorer would develop an error and stop responding, so I could never get a log of that (although I could see there were problems as I checked it periodically).

    One final thing, which may or not be related to these problems, whenever I've started up my computer began this, the wireless internet stops working and I have to go into Wireless Zero Connection and press 'Start' manually, and then allow Windows to control wireless connections. This is very annoying, so if you could help me fix that in this process, I would be additionally grateful.
    Please, any help would be greatly appreciated,
    Matt
     

    Attached Files:

  2. klix

    klix Private E-2

    The other files you'll need.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The problem with your wireless connection will probably have to be taken to the Networking or Hardware Forum; however, let's fix you malware first and see what happens.

    First goto Add/Remove programs and uninstall the below. If you don't find these or they will not uninstall, please tell me when you return
    Think-Adz Search Assistant removal
    Viewpoint Media Player
    WildTangent Web Driver

    If these all uninstall properly some items I list further down to fix may no longer appear. That's okay! Just continue.

    What is in the below folders all created on June 5 th?
    C:\{00000CCB-0000-0000-CB31-88DBF628B8C9}
    C:\{000043EB-0000-0000-A8E9-1949716B6B48}
    C:\{000043DD-0000-0000-930A-E1BCEA84432E}
    C:\{80001679-0000-0000-AE83-BD8F9909747F}
    C:\{80001600-0000-0000-9EC2-62F558EC94F1}


    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\windows\system32\prdsregk.exe
    C:\WINDOWS\system32\kwinsqdt.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [{0D-D1-18-8C-ZN}] C:\windows\system32\prdsregk.exe SKY004
    O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinsqdt.exe SKY004
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\prdsregk.exe
    O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\kwinsqdt.exe

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. klix

    klix Private E-2

    During this session (my computer's been on for an hour and a half now), I haven't had any problems - no pop-ups and no blue screen - so things are improving a great deal so far.
    When I tried to uninstall Think Adz, it was unsuccessful (but it did disappear from the add/remove programs list). Viewpoint and WildTangent were successfully uninstalled.
    I will upload the contents of the folders you asked me to in other posts.
    What with my very basic computer knowledge, I thought I'd mention something I noticed while in HJT Process Manager, since I don't know if it's important or not. There were two of what looked like the exact same svchosts in the same location - C:\WINDOWS\system32\svchost.exe.
    Since you asked for 'new' GetRunKey, ShowNew, and HJT logs, I ran those programs and have attached the new logfiles - I hope that's what you needed.
    One more thing. About CCleaner: What exactly does it do? and Is it safe (and useful) to use even after I clear up this malware problem?
    (Actually, if it's appropriate now, I'd also like to know what are the best methods of malware defense/detection overall, so I can use them in the future to prevent problems like this?)
    Thanks for the help; let me know what I should do next.
    Matt
     

    Attached Files:

  5. klix

    klix Private E-2

    You asked what was in each of these folders:
    C:\{00000CCB-0000-0000-CB31-88DBF628B8C9}
    C:\{000043DD-0000-0000-930A-E1BCEA84432E}
    C:\{000043EB-0000-0000-A8E9-1949716B6B48}
    C:\{80001600-0000-0000-9EC2-62F558EC94F1}
    C:\{80001679-0000-0000-AE83-BD8F9909747F}
    I tried to upload them so you could check them out for yourself, but it returned saying 'Invalid Upload'. In all five folders, there is the same three files:
    DATA.CAB
    Manifest.qrm
    Manifest.ini
    This is maybe too detailed, but I wanted to include everything just in case. All were created on 6/5/07. All files in the first and last two folders were created at 10:51AM that day, the ones in the second and third were created at 11:00AM. DATA.CAB sizes, in KB: 535, 30.1, 87.1, 637, 287. Both manifest files in all folders were the same size: 4.97KB, 1.03KB, 926B, 1.54KB, 1.94KB.

    For some reason, I couldn't upload Avenger.txt. Whenever I tried this came up:
    Upload Errors
    avenger.txt:
    Attachment in Progress. Can be deleted here.
    Please let me know what else I can do.
     
  6. klix

    klix Private E-2

    I was just wondering if you'd decided that I was now malware free. It's been 10 days since my last post; I know you may be swamped with others to help, but I just want some closure on this thing.
    Thanks
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that! Some how you slipped down off out radar without noticing that you posted a new message.

    It is normal to see multiple svchost.exe processes from the system32 folder running. You will often see any number of them. I have 5 running right now.

    Yes you should keep it. It is actually not a malware scanning tool. It is actually a drive cleaning/system optimization/privacy tool. With a few additional features (like registry cleaning, uninstall utility...etc) which you can check out.

    My final instructions will include a link for you to follow.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete those folders. They appear to be part of WinFixer.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay a new infection showed up. It is possible that the other infections were masking it from being seen before now. We will need to use Avenger again but first I have a couple other things for you to do.

    Uninstall CounterSpy since we are finished with this trial program now. Let me know if you get an error when trying to uninstall. If you do, then reinstall it, reboot, and then uninstall it.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger.



    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!
     
  10. klix

    klix Private E-2

    Thanks for getting back to me so quickly after my last reply (and sorry I couldn't do this sooner - I was away from my computer the last few days).
    Anyway, CounterSpy uninstalled successfully. Everything else went smoothly, except when I rebooted one time, an error message popped up titled 'MS Visual C++ Runtime Library'. It said LogitechDesktopManager.exe requested Runtime to terminate it in an unusual way. I don't know if this means anything to what we're doing here, but I thought I'd mention it.
    One last thing (sorry, but I'm very curious and like to learn things so I know what's going on): what is WinFixer? Was that part of the Win32 malware problem I had?
    Thanks.
     

    Attached Files:

  11. klix

    klix Private E-2

    Here is my latest HJT.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot comment on win32 malware since that is not a complete malware name. There are probably more than a thousand infections that use the word win32 in their names.

    Rather that rewrite a description of WinFixer, here is a reasonable description: http://en.wikipedia.org/wiki/WinFixer


    You have one more file to delete. Delete the below file:
    C:\WINDOWS\system32\drivers\vwu^guqr.sys

    Then attach a new log from ShowNew so I can be sure nothing else popped up.

    How is everything working now?
     
  13. klix

    klix Private E-2

    Everything is working great - no pop-ups, no blue screen, nothing. Thank you for all the help; I hope this problem is gone now.
     

    Attached Files:

  14. klix

    klix Private E-2

    Can you tell me how I might have gotten this problem? How did I happen to download it? (Because I don't remember downloading any antivirus or other such program besides AVG and Ad-Aware SE Personal.)
    The article you linked me said WinFixer tells you that you have problems which you actually don't. Does that mean I didn't have any variation of this Win32 thing it said I had? And (if you can tell easily), what caused my computer to show that blue screen to 'prevent further damage'?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I really cannot say exactly how you got it, but yes it was due to some site you accessed or something you downloaded/installed or clicked on.

    It was not WinFixer telling you that you had problems. You said AVG was reporting the problems. And again without the specific Win32 Trojan name I cannot say anything more since as I already stated, there are thousands of these. There are also many many things that can cause blue screens. Some can be cause by various malware and some are just problems within the Windows OS.


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds