gwdrive32.exe virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by varunz, Dec 17, 2010.

  1. varunz

    varunz Private E-2

    Hi all, I am Varun. I appreciate the work some people here are doing to help others. Have used the website before to remove virus infection before and I am thankful.

    Lately, I have been getting this pop up alerts from Eset nod about win32/dps trojan and similar sorts saying it has blocked those address. I have attached the log from ESET, hope that helps. Sometimes the virus blocks Internet, will not be able to browse for a while. Have to keep refreshing the page and then it works again (happens in IE and Firefox as well). I use utorrent for p2p file sharing and nothing other than that.

    When i end the process of gwdrive32.exe, Internet works fine.

    I have run the scans posted in READ and RUN me first. Have attached the logs required.

    Hope someone helps me in cleaning my Pc. Thanks in advance.
     

    Attached Files:

  2. varunz

    varunz Private E-2

    Almost forgot to attach the Eset log, I hope someone looks in to it.

    Attached combo fix log as well.
     

    Attached Files:

    Last edited: Dec 17, 2010
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    Please go to virustotal and upload the following file for analysis, and let me know the results.

    • c:\windows\system32\WinFLdrv.sys

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    c:\windows\FlyakiteOSX\Backup\ntkrnlpa.exe | c:\windows\system32\ntkrnlpa.exe
    c:\windows\FlyakiteOSX\Backup\ntoskrnl.exe | c:\windows\system32\ntoskrnl.exe
    File::
    C:\Documents and Settings\vaRunz\Application Data\systemfl.$dk
    C:\WINDOWS\system32\sys_drv.dat
    C:\WINDOWS\system32\sys_drv_2.dat
    C:\Documents and Settings\vaRunz\Application Data\ltzqai.exe
    C:\WINDOWS\gwdrive32.exe
    C:\WINDOWS\system32\88.exe
    C:\WINDOWS\temp\HTT172B.tmp
    C:\Documents and Settings\vaRunz\Local Settings\temp\16458.exe
    C:\Documents and Settings\vaRunz\Local Settings\temp\829.exe
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Userinit"="c:\windows\system32\userinit.exe," 
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "Microsoft Driver Setup"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new C:\MGTools.exe and attach the C:\MGlogs.zip into your next reply. Also include the VirusTotal results and the new SAS log.

    You must give me a description on how things are running for you now. :)
     
  5. varunz

    varunz Private E-2

    Hey Kestrel13! .. thanks for helping me on this :)

    I have done all the things you wanted me to. Have attached the logs requested with the message.

    I think its still not fixed. I saw some new files running in task manager have attached the names as well.

    Looking for further Instructions, thanks again.
     

    Attached Files:

  6. varunz

    varunz Private E-2

    The below the files I saw in task manager, hope they help.

    Trogia.exe Tqx.exe rundl32.exe cf8194.cfxxe dumphive/cfxxe

    There were many more which just popped for a sec and went off.

    Regarding virus total scan, It said the file was submitted before for analysis. Should i sign up on the web page and then try analysis?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try Jotti

    Not malware, part of Combofix.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\windows\FlyakiteOSX
    File::
    c:\windows\Trogia.exe
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      ntkrnlpa.exe
      ntoskrnl.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    You are still almost 6 months out of date with the MGTools! You must follow my last instructions regarding downloading a new copy properly.

    So please do that and then get me the new C:\MGlogs.zip. :) Don't forget the Jotti results and the log from SystemLook.
     
  8. varunz

    varunz Private E-2

    Hi again,

    I accidentally deleted ntldr and ntdetect.com files from C while deleting MGtools old folder (phew another story) ...anyways got my PC back up and running. Have run the applications and attach the logs below.


    However I was not able to run systemlookup, downloaded multiple times. I get this error "The application has failed to start because the application configuration is incorrect. Reinstalling the application may fix the problem".

    Waiting for next Instructions.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, it works great for me. Please reboot into safe mode to try and use the tool as per my previous instructions.
     
  10. varunz

    varunz Private E-2

    No luck mate! I downloaded again, logged in to safe mode as well, same error message.

    Downloaded VC++ update from MS thinking it would sort out, but nope.

    Any alternate?
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You on SP2 or SP3>?
     
  12. varunz

    varunz Private E-2

    I am on SP2, wanted to Install Sp3 guess I din have time.

    I am confused now, should i do a clean Install? It would be gruesome! :cry
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No just wait. I am further discussing this with my colleagues.
     
  14. varunz

    varunz Private E-2

    No problem, I am at work now. Can do the things after 10 hours from now.

    Have a good time.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, I have spoken to Chaslang, who says he does not think c:\windows\system32\ntkrnlpa.exe and c:\windows\system32\ntoskrnl.exe need replacing at all. This Mac emulation software makes major changes to the Windows OS and replaces system files and changes the registry to allow it to emulate a MAC. The PC now is non-standard and those scanners will have issues with many files and registry keys thus making it difficult to impossible to know what is a real problem and what is not. When I tried to replace those files earlier, I could actually have broken the Mac Emulation software. Does it work correctly? So at this point, we want to know; what actual malware problems are you having now?
     
  16. varunz

    varunz Private E-2

    MAC emulation software is working fine, have been using it for years now.

    I think with all those scans we may have fixed the malware problem, I deleted a file by the name "serivces.exe" in c:windows/system32 folder. So far I have not received any alert on ESET about those address blocked messages.

    I will monitor for 1 more day and then we can close this thread..
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're correct about the spelling on that file?
     
  18. varunz

    varunz Private E-2

    Yes, I am.


    That was starting a fake "services.exe" process in task manager. I used process explorer to locate the file and deleted it.

    That process was stopping me from browsing.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay then, one final look through a fresh set of logs.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  20. varunz

    varunz Private E-2

    Im afraid I can do that when I get back home, will post the logs as requested.


    Thanks for all your effort in helping me out with this. :)
     
  21. varunz

    varunz Private E-2

    Hi Again,

    Run the Getlogs.bat file, have attached the log below.

    So far no alerts on ESET, I think things are ok now.

    Thanks for all your help! Kudos
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds