do i need to worry about these exe files?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ajs, Nov 21, 2008.

  1. ajs

    ajs Private First Class

    after running msconfig i discovered that I have a startup item called NvCpl. It reticked itself after I had disabled all. I then had a look at my running processes to see if it was there. It isn't. I did see one process called wdfmrg.exe. Do i need to do anything about these? If so WHAT?

    Any help greatly appreciated

    S
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One is you NVIDIA Compatible Display driver and the other is probably malware.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. ajs

    ajs Private First Class

    ran everything on the readme. logs attached. wdfmrg.exe is still running as a process in task manager. spybot had 3 problems in include files, malware.sbi, trojans.sbi and trojansC.sbi. It found w32/sdbot-zn and deleted it. Not sure if I need to do anything else?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Still need the C:\MGLogs.zip from running the C:\MGTools.exe.
     
  5. ajs

    ajs Private First Class

    Attached now.
    When I started up this morning I got a message saying engine error loading driver 1060.
    It also said I had no firewall turned on. When I tried to get to windows firewall it said" due to an unidentified problem, cannot display windows firewall settings." I have outpost firewall turned on.
    System restore appears to be on again though - I was not able to turn it on before - error said windows couldnt access one or more drive.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware.....

    Windows firewall often does not detect other firewalls.

    The error code you got, has it happened again after a reboot?

    What problems are you still having?

    In the meantime:

    Please disable the guest account in user accounts.

    Also Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.
     
  7. ajs

    ajs Private First Class

    yes, still getting the1060 driver error at startup. only other problem i have is that outlook 2007 will not start up normally. i posted this issue in software help forum but havent been able to solve it. wdfmrg.exe is still running in processes, Is this something I should be concerned about? There are a whole load of other processes running after I ran the scans from the read me page. is this normal?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    wdfmrg.exe --> is not in any of your logs, so please give me a screen shot of what processes are running that you are concerned about.

    Also re-run SAS and MBAM and attach those logs.
     
  9. ajs

    ajs Private First Class

    processes screens attached. I am running the re scans now and will post them asap. Thanks
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Lets try doing this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    RenV::
    
    KILLALL::
    
    
    Drivers::
    wdfmrg
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Attach that log also.
     
  11. ajs

    ajs Private First Class

    logs attached.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry...had to look at my own system before I realized it is a file for you Windows Media Player 10......not malware. :) :-o

    The driver error and the Outlook issues should be addressed in the appropriate forum -> software or drivers.

    I think we can do our final clean up now:

     
  13. ajs

    ajs Private First Class

    Thanks Tim. All done. The wdfmgr.exe is still running in processes. Processlibrary.com has it down as W32/Sdbot-ZN Worm and says this about it:
    wdfmrg.exe is a process which is registered as the TROJ_SUA.A worm. This virus is distributed via the Internet through e-mail and comes in the form of an e-mail message, in the hopes that you open its hostile attachment. The worm has its own SMTP engine which means it gathers E-mails from your local computer and re-distributes itself. In worst cases this worm can allow attackers to access your computer, stealing passwords and personal data. This process is a security risk and should be removed from your system.

    Do I end the process or will it take more to remove it?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes there are tons of links on the web that call it a virus....you can remove it by removing both your WMP10 programs. It is a codec I believe that allows you to convert wmp to mp3 players.
     
  15. ajs

    ajs Private First Class

    In that case I'll just leave it. Thanks again for all of your help. :)
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds