dwdsregt.exe? Help?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Outlawstar15a2, Sep 24, 2006.

  1. Outlawstar15a2

    Outlawstar15a2 Corporal

    Ok, I recently recovered from a very bad virus infection I cleared away most of the malware and I'm currently doing mop up jobs with programs such as Ad Aware, Spybot, Ewido, and Avast. I had to use the HP system restore feature in order to get back into the OS once I did so I Immediatly did a scan wirth Avast and Ewido followed by Ad Aware and Spybot. My only remaining problem is this wierd startup entry called dwdsregt.exe ELT001. I did some research and it appears to be ad ware however I have taken no steps until I get confirmation. Also this morning I tested out safe mode to see if it still works as I was having problems with it before the system seems to run super fast in normal mode but slow like a snail in safe mode and I can't figure out why. I was wondering what I should do next I ran scans with all my anti malware software except windows defender I have to reinstall SP2 right now but I've been holding off till I see what you want me to do first. I feel uncomfortable installing SP2 with rogue entries in the startup list.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes dwdsregt.exe is related to ZenoSearch and should be removed. You could have other files and registry keys around related to this. In order for us to be able to provide you any real help on the malware status of your PC, you really need to run the READ & RUN ME sticky and attach the 5 logs requested in it.
     
  3. Outlawstar15a2

    Outlawstar15a2 Corporal

    Ok, will do. I'll start on it now.
     
  4. Outlawstar15a2

    Outlawstar15a2 Corporal

    I have a problem I installed counterspy but because I used to run it before, my copy of the program needs to be registered before I can update it so how do you want me to proceed I installed it but I haven't run a scan yet as I'm not that far yet down the list.

    EDIT: Also I installed HiJackThis to C:\Program Files\Anti Malware Programs\HiJackThis however I did not touch any settings in the program and I didn't run a scan I did this because It's easier when all programs are located in a central folder will this cause problems later? Should I reinstall to the default location or leave it. I reinstalled it before I posted for help as I knew I would need it later...
     
    Last edited: Sep 26, 2006
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you run a scan without updating? If not, try running the below instead:

    Running Ewido Anti-Malware

    As long as HijackThis is in its own folder by itself (and also not in any of the folders we request that it not be in) then all is good.
     
  6. Outlawstar15a2

    Outlawstar15a2 Corporal

    As far as counterspy is concer it'll let me run a scan, so I'll do that now.

    HiJackThis is in it's on folder in the Anti Malware Programs folder in C:\Program Files. I did this because it's easier for me to find later, I kept it out of the problem folders.
     
  7. Outlawstar15a2

    Outlawstar15a2 Corporal

    ok heres the first of the five log files for some reason the forum won't let me upload more then three files so i'll have to create a separate post i guess...
     

    Attached Files:

  8. Outlawstar15a2

    Outlawstar15a2 Corporal

    ...also the menu that appeears when you right click, or pull down a drop down menu within a window, etc. Appears to be invisible when it first appears and can only be seen when you mouse over it is there any reason why its doing that and can i change the way its displayed or is it related to my current problem.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a load of problems! We are going to have to do that other scan I gave you from Ewido to help reduce the amount of manual work; however first do the below.


    Delete all files in the below folders. Note that Windows my stop you from deleting a few from the current date this is normal.
    C:\Windows\Temp
    C:\Documents and Settings\Administrator.YOUR-AT5QGAAC3Z.000\Local Settings\Temp
    C:\Documents and Settings\Default User\Local Settings\Temp
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp
    C:\Documents and Settings\Owner\Local Settings\Application Data\Sunbelt Software\CounterSpy\Quarantine

    Now run the Ewido procedure I previously gave to you and attach the log from Ewido.

    Also goto Add/Remove programs and uninstall the below old Sun Java version:
    Java 2 Runtime Environment, SE v1.4.2_03

    You forgot too attach a log from HijackThis! I need one.
     
  10. Outlawstar15a2

    Outlawstar15a2 Corporal

    sorry about the HJjackThis log. I thought you wanted to wait on that one...

    Heres the log from ewido and HiJackThis...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must follow the directions in step 7 of the READ ME. HijackThis must be renamed as requested. Do this now and then move on to the below. Do not attach a new HJT log yet until requested at the end of the below procedure.
    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    c:\temp\salmau.dat
    c:\documents and settings\all users\desktop\Online Security Guide.url
    C:\Documents and Settings\Owner\Favorites\Going Places
    c:\windows\warnhp.html
    C:\WarezP2P.exe
    C:\WINDOWS\Eim03.exe
    C:\WINDOWS\IA\KE.vbs
    C:\WINDOWS\Justin.exe
    C:\WINDOWS\popupwithcast.exe
    C:\WINDOWS\srvftuvynh.exe
    C:\WINDOWS\system32\dwdsregt.exe
    c:\windows\uniq <--- the whole folder
    c:\program files\SearchRelevant <--- the whole folder
    c:\program files\WinAntiSpyware 2006 Scanner <--- the whole folder
    C:\Program Files\Batty2 <--- the whole folder
    C:\Program Files\DeluxeCommunications <--- the whole folder
    C:\Program Files\popupwithcast <--- the whole folder
    C:\Program Files\PSDream <--- the whole folder
    C:\Program Files\PSLister <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Oct 1, 2006
  12. Outlawstar15a2

    Outlawstar15a2 Corporal

    I couldn't find the following entries:

    C:\WINDOWS\Justin.exe
    C:\WINDOWS\system32\dwdsregt.exe
    c:\windows\uniq <--- the whole folder
    C:\Program Files\DeluxeCommunications <--- the whole folder

    they appear to have been deleted all files and folders are already visible along with extensions and protected system folders. I did that the day of the "incident", my personal Day of Darkness, is it possible they were deleted the day of the incident when i was running avast, ad aware, spybot, ewido, microsoft defender (before things got bad), and ccleaner at full capacity, if so is the threat they pose gone? Also it gave me no trouble with the file deletion the only trouble was that i couldn't find the ones listed above...

    As for the right click menu no problems to report its fully visible now.

    As for safe mode it loads regulary and I can log into the owner account the only problem is that the administrator account hangs forever but the owner account has full administrator privileges so the previous problem has a work around if I leave the administrator accoutn alone and use owner then theres no probllems loading.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach the 3 followup logs I requested.
     
  14. Outlawstar15a2

    Outlawstar15a2 Corporal

    Here are the logs that I forgot to post, I must apologize again I didn't mean to leave them out...
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I assum Ewido and CounterSpy are the free versions. If that is correct, uninstall them now.

    Sun Java has updated to version 9! So let's get you updated.

    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    2SE Runtime Environment 5.0 Update 8

    Now reboot into safe mode and delete the below:
    C:\Program Files\Common Files\misc002 <--- the whole folder
    C:\Program Files\Common Files\Yazzle1452OinUninstaller.exe
    C:\Program Files\Common Files\Yazzle1440OinUninstaller.exe
    C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
    C:\Program Files\Common Files\Yazzle1438OinUninstaller.exe
    C:\Program Files\Common Files\??mantec <--- this folder will probably looked like symantec
    C:\asdf.txt
    C:\dfndrff_e12.exe
    C:\kybrdff_e12.exe

    Reboot into normal mode!

    Attach a new log from ShowNew!

    How is everything working now?
     
  16. Outlawstar15a2

    Outlawstar15a2 Corporal

    Everything is working fine... The removal of the files during safe mode went without a hitch, and await further directions. Though I do have one question I always wanted to ask. When they discover a new malware threat how do they determine the files and registry entries that go with it? Do they load it on a isolated computer and determine what was installed?
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Who is "they"?

    You do realize that there are literally thousands of registry entries and every PC is slightly different and has different things installed.


    What is in the below folder (if anything)?
    C:\Program Files\Common Files\{5C15CD7C-088F-1033-0210-040108030001}
     
  18. Outlawstar15a2

    Outlawstar15a2 Corporal

    <--

    I have no idea... I'll do whatever you want me to do with it, I don't think it goes with the computer but theres no telling the machine has so much stuff installed on it when it came from the factory and this isn't even my computer but rather my older sister's.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I asked what it in the folder, not what is it for. If it is empty, just delete it. If it is not empty, tell me what is in it.
     
    Last edited: Oct 12, 2006
  20. Outlawstar15a2

    Outlawstar15a2 Corporal

    Nothing is in the folder, I just deleted just now. I'm experiencing no problems on this end what should I do next?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  22. Outlawstar15a2

    Outlawstar15a2 Corporal

    Ok, working through the i'm going through the advice of your last post now. But I had a problem logging on. I typed my username and password as usual with no errors and the forum told me invalid username or password. I typed it like i always did, so I figured that maybe I had caps lock on, i checked it was off, so I figured well let me copy and paste my username and password from a text file i keep in case of emergencies no dice it was all correct down to the case for each cahracter finally after my fith try it locked me out so I waited the 15 mins and tried again with the new password i recovered and it worked but i still don't understand why it happened. I reset my password back to its original i will try logging off and on again and will tell you the result after i do the restore thing and all.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you are talking about having problems logging into. You used the word "forum" so I assume you mean here at Majorgeeks. But then you said "the new password I recovered" so I don't know what you mean because this sounds like you are talking about the password on your PC.
     
  24. Outlawstar15a2

    Outlawstar15a2 Corporal

    Ok I reset system restore there are no restore points now.

    Also I have no problems to report now I have zone alarm running now and its been running for the past several days but all I seem to get are what appear to be routine port checks though there was a few that were labeled high risk....

    As for Firefox I still have to figure out how to navigate and work the thing before I can expect the other people in the house to use it.

    I'm going to download SP2 and update again thats the only thing I need to do now after that I'll reinstall Windows Defender.

    I'll keep monitoring for threats but as of right now things are good. I'll probably dedicate all day tomorrow to a full battery of scans.....

    EDIT: Oh I was refering to the Majorgeeks forums I had trouble logging on but it's fixed now I have no trouble now. For some reason I changed my password and changed it back and now the forum lets me on now without incident.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Using Firefox is pretty straight forward. You should find it pretty easy to adapt to if you are already familar with IE.

    Surf safely!
     
  26. Outlawstar15a2

    Outlawstar15a2 Corporal

    I finally decided to use Firefox it's nice but is there any way to get to to stop notifying me when I move from a encrypted page (Firefox Themes page) to a non encrypted page (www.gamefaqs.com)?

    Also I always heard stories about how Firefox is way more secure then IE but how much better is it really, in terms of protection?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. The Firefox Themes page is not encryted as far as I know and I have no problems jumping between those two pages. I'm not sure what you are referring to but this is a question better asked in the Software Forum.

    You have to be careful on how you interprete things like this. Firefox has fewer security issues than IE. Some of this is due in part to that make that many more people use IE than Firefox and more hackers look to attack IE than they do Firefox. So people will often say Firefox is more secure and from a simplistic view that would appear to be true, but many people using Firefox still have malware issues. In the end, it all comes down to the end user and how they use their PC and what they download and click on ....etc (all of this is mentioned in the How to protect thread). Yes using Firefox can help but nothing will protect your system if you are not careful on what you do.

    I use Firefox and I use IE. On many PCs where I only use IE I never have any problems with malware. Even on WinXP SP1 and Win 2K SP4 systems with IE only, I never have malware problems. I have the typical protection software installed and use some common sense on where I surf and what I download and what I click on (and read what messages say before clicking because saying NO may not be the correct thing to click on. The messages are often designed to trick you.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds