Help me please, w32.wallz and w32.hllw.gaobot on my computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Flowerchild, May 11, 2005.

  1. Flowerchild

    Flowerchild Private E-2

    Hi,

    I hope someone can help me as I am so frustrated, I have been trying to fix this myself all week :eek:

    Orginally I just had the w32.wallz on my computer today a new one w32.hllw.gaobot popped up.

    I couldnt get rid of the wallz with any virus scans and couldnt delete anything myself per nortons instructions because the registry nortons posted does not exist in my registry. So I did what anyone would do that doesnt know how to work on these things and did a system recovery on my computer, darnit the virus was still there.

    By some miracle I found your site and followed your steps on this page http://forums.majorgeeks.com/showthread.php?t=35407, here are my results...I ran symantec security check and the details were terrible, hacker exposure check and trojan horse check both at risk. I have some open ports 1025 unused windows services block, 5000 sokets de trois v1.

    adaware scan found 11 critical items which were fixed, ran scan again and it was clean but the trojan is still on my puter. Spybot found 64 problems, again, fixed those and ran scan again, said there were no threats.

    I tried to run the online trojan scan but my system was shut down with the following message 'NT Authority/system' as the reason for shut down. Right after that Nortons finds a new virus the w32.hllw.gaobot which cant be deleted.

    I followed all the steps listed on the page and everything comes back clean, well until the new virus today. I searched your site and found this thread http://forum.majorgeeks.com/showthread.php?t=61970&highlight=w32.wallz, I followed the instructions on that page as well. I downloaded microsoft windows anti spyware and it found nothing:(.


    Note, I cant run in safe mode as I am on dial up. I have windows xp.

    I just download hijackthis and will run a scan and save a file if you guys request it. I appreciate any help ya'll can give me. Thanks so much for reading this.

    Signed,

    A frustrated Flowerchild
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can run in safe mode. You just cannot run the online scans in safe mode due to having dial up.
    Hopefully you did all the other scans in safe mode. Did you run Stinger in safe mode?

    Boot into normal mode and follow the steps below exactly.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Flowerchild

    Flowerchild Private E-2

    Thank you :D I cant connect to the internet in safe mode for some reason, I did scan in safe mode and also in regular mode, I hope I didnt mess up anything. I'm embarrassed to say I dont know a thing about computers, stinger wasnt ran in safe mode because I couldnt connect to the internet. Can I add my isp in safe mode?? If thats possible I will go back and do the stinger again.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I said before. You DO NOT need to connect to the internet to run the other scans. Only the online scanners require a connection. Run Stinger in safe mode and let me know if it finds anything.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should also go to Add/Remove programs and uninstall WeatherBug.

    Are you happy with this Zero Knowledge stuff? I have quite often heard people describe their stuff as appropriately named because they have zero knowledge about what they are doing. That is not my opinion. It's just what I have heard. I personally do not use anything like that. It just is not necessary. Do you really find it necessary? If you have an AV, a fireall, spyware blocker, and a browser like Firefox that has built-in popup protection you should be set.
     
  6. Flowerchild

    Flowerchild Private E-2

    Ok, I will run stinger again and let ya know. Sorry I thought I had to be online to run stinger. I did run all the others in safe mode.

    The zero knowledge freedom thing I have never used, it was already installed on my computer, I will just uninstall it along with weather bug.

    I am off to boot in safe mode and run the scan will let ya know what happens. Thanks again:)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have to uninstall Zero Knowledge if you like it. It appears like it has a popup blocker that you are using and maybe do not even know it. I don't know what the rest of it is doing.
     
  8. Flowerchild

    Flowerchild Private E-2

    I ran the stinger and it didnt find anything, it says I have 878200 clean files. I deleted weather bug and the freedom zero knowledge, I never used freedom anyway, and no I wasnt aware it had a popup blocker lol. It wasnt doing a very good job of blocking those pop ups.

    Once I get all this w.32 junk off my puter I will dl firefox, I have heard good things about it, I just never took the time to dl it. Man I have learned some very valuable lessons since this has happened.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Besides Zero Knowledge and WeatherBug, the only item to have HJT fix is:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    This is left over from running HSremove during the cleaning steps. You only need to run that if you have an HSA hijacker which you do not have.

    Are you still having problems?
     
  10. Flowerchild

    Flowerchild Private E-2

    Thanks for your help:) So far I havent had those annoying pop ups from the site pretending to be microsoft telling me I have infected files etc. So maybe those w.32 trojan thingys are gone, I hope so anyway.

    I really appreciate your help, thanks for your patience with a not so computer advanced poster. :D
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. Flowerchild

    Flowerchild Private E-2

    Well....I thought everything was ok, but I still have issues. I dont know whats going on. I ran everything again in safe mode and found lots of malware and browser highjackers. I am not getting any virus warnings just all this severe adware, malware, highjackers etc. Most of these are trying to get into my windows update. I saved a txtfile from the adware scan if you need to see that.

    I was going to install the firewall along with the new browser this site recommends and found all these errors this morning. I keep getting a pop up that says edowpack.exe encountered a problem and needs to close then I lose my IE page.

    I ran another hijackthis and have a file if you would like to see it.
     
  13. Flowerchild

    Flowerchild Private E-2

    Ok, the w32.wallz is back or it never left. Just got the alert from nortons:(
     
  14. chuddds

    chuddds Private E-2

    NO. We have a specific way of asking people to do steps here. Do not step into threads where people are already being helped especially in this forum. Thank you.
     
    Last edited by a moderator: May 12, 2005
  15. Flowerchild

    Flowerchild Private E-2

    What???????? Mind you I am computer illiterate. :confused:
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post a new HJT log!

    Did you ever complete the steps in the link I gave you:
    How to Protect yourself from malware!

    Do not update Windows if having malware problems but you do need to check out all the other steps ASAP. You must get a firewall install or you will constantly have problems.
     
  17. Flowerchild

    Flowerchild Private E-2

    Hi Chaslang,

    I was trying to do the steps in the how to protect yourself but my computer kept crashing right around the time the downloads were almost finished, grr. I kept getting more and more worms, viruses etc and finally I couldnt enable autoprotect on nortons. I ran all the scans again in safe mode, couldnt run any of the online scans because they wouldnt load. Spybot claimed I had no issues, adware claimed many and deleted but they always came back. Yep, sigh, this computer is in bad shape. I ran stinger in safe mode twice, it did delete a sasser worm but that was all it found. It wouldnt delete the w32.wallz or the hllw.gaobot and the computer kept crashing every few minutes so I did another recovery to see if maybe I could reinstall everything and start over trying to rid this machine of this junk. Of course the trojans are still here ugh.

    I will post another hjt log as soon as I do all the steps in the read me first page since I have started over again.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By recovery, do you mean from your Windows XP console. If so, you now need to get all system updates downloaded again. The first thing I would recommend is to download and install one of the free firewalls from the link I gave you. Get it installed and then continue with the other windows updates do them a few at a time. Do not download WinXP SP2. Use Custom Install instead of Express Install. I say do a few at a time so that if you run into problems with shutdowns you do not abort in the middle of downloads.
     
  19. Flowerchild

    Flowerchild Private E-2

    Yes I thought I should dl a firewall first as well. I got to 98% and it stopped, I rebooted and am gonna try again now. Once the firewall is downloaded hopefully anyway, will it block any other trojans trying to get in? Or will it be infected since I have the w32.wallz trojan??
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No software provides 100% protection especially if not configured correctly and it will not protect you from yourself (if you say yes to something that should be no - you get what you approved). However, without a firewall you are susceptible to so much bad stuff it is amazing.

    Which one are you downloading?
     
  21. Flowerchild

    Flowerchild Private E-2

    I finally got zonealarm to download, its the only firewall I could get to dl. I will post once I get all the steps finished, this could take awhile :eek:

    Also our other computer has the exact same thing, so I am working on it as well. Should I make another thread for it? Between both of them I should learn alot about computers with your help of course. ;) I really appreciate everything.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Stay in one thread for now and let's finish getting one PC fixed and then we can look at the other.
     
  23. Flowerchild

    Flowerchild Private E-2

    I finally got all my updates and everything on the read me first page finished. I am not getting the warning from nortons about the w32.wallz or the hllw.gaobot anymore. But I didnt delete anything, so maybe stinger got them??? Stinger said I had clean files tho, didnt show any findings.

    The spybot scan showed data miners and I fixed those. Adware found 11 critical files, I fixed those and have saved a txt file if you need to see it. I have a hijackthis file for ya when youre ready to see it.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are we still talking about the first computer here? If so, post the log.
     
  25. Flowerchild

    Flowerchild Private E-2

    Yes this is still the first computer. Thanks:)
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How did you now get HijackThis installed improperly?


    C:\Documents and Settings\Owner\Desktop\hijackthis\HijackThis.exe

    In message # 3 you had it correct.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  28. Flowerchild

    Flowerchild Private E-2

    I'm sorry I did a reformat on my computer the system recovery thing and I thought I was starting over since I had to do that. Thats me just being computer dumb. The HJT file tho was right the first time around because that was before the reformat, when I redownloaded it I musta been in a hurry and not paying attention because I had been downloading all day. Sorry bout all that. I am off to fix the things you suggested will post when thats finished. Thanks for being patient:)
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to stop doing recoveries and formats. They are typically not necessary and you have start getting all of the updates and patches for all of your software installed all over again just to bring it up to date.

    So what is the purpose of you posting a log now if you have done a format of your system?
     
  30. Flowerchild

    Flowerchild Private E-2

    ok maybe I am not explaining things very well here or something. I first came here looking for help, worked on the puter with your help, something took over my puter after that because obviously I didnt do something right, whatever took over the computer took over my nortons antivirus and disabled auto protect, it crashed my computer several times etc, I couldnt even make a post here so I reformatted once. I explained I did a system recovery and started over with the steps, and posted again for help. I did what you said and downloaded all my windows updates a few at a time, downloaded everything I needed for the read me page and now here I am. Again I only reformatted once.

    well the trojan was still on my computer after reformat.

    Anyway, I just fixed the RO thing you told me to and checked this thread and thought before I do anything else you understood whats up here. Should I do the next step in your above post??
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you did not download all the updates for your PC. You do not have WinXP SP2 installed. Is there a reason for not installing SP2?

    There are no apparent malware issues showing in your HJT log.
    Have you run Avert Stinger in safe mode while physically disconnected from the internet?
    Which program is now telling you that the trojan is present and what exactly is it telling you? Is it still Norton and what version of Norton AV is it and what is your definitions version/date?
     
  32. Flowerchild

    Flowerchild Private E-2

    I downloaded all the critical updates, didnt dl sp2 because you told me not to
    . I did run stinger in safe mode, it said I had clean files. Since downloading the updates I havent been getting a virus alert from nortons. But I didnt delete anything, so I dont know if its hiding out or what. Or would the patches get rid of it? I am just really computer illiterate, really I am, its quite embarrassing. Hwclock.exe is a program that the w32.wallz trojan was hiding in, I kept trying to delete the file but couldnt, it said I wasnt allowed access. I just checked my window task manager and the processes, that program isnt running now, so I dont know if its hiding somewhere else or its gone. I also have tons of other things running that I have no idea what they are or if theyre supposed to be on my puter. Like zlclient.exe, its memory usage is 6,680, there are 2 IEXPLORE.EXE running 24,964k and 24,380k, is this normal?? There are 31 processes running and this is all new to me so I dont know.

    My nortons AV is from 2003 but I get live updates all the time, its just nortons couldnt delete the w32.wallz nor the bot one either. Thats why I am so confused because it seems now theyre gone but I didnt delete anything. I am thinking maybe stinger got them. But as I explained my task manager has all these things running and maybe I am a bit paranoid now. Thanks again for being so patient, I am learning alot from you.
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It sounds to me like there is no longer a virus on this PC! The reason I requested that you not install SP2 is because I thought you said you were still infected. If Norton is not finding anything, you should complete the SP2 update.
     
  34. Flowerchild

    Flowerchild Private E-2

    Ok, woooohoooooooo! I will get that done tomorrow. I appreciate all your help you have been a peach :D

    Now onto my office computer, should I make another thread?
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Yes, it would be a good idea to start a new thread for the other PC. Make sure you run ALL the steps in the READ ME FIRST before posting and in your post make sure your clearly state the you have run all the steps in the READ ME FIRST sticky thread.
     
  36. Flowerchild

    Flowerchild Private E-2

    Ok, could you lead me in the right direction on how to download tools when the computer is crashing every 5 mins. The computer has been taken over fully:( Windows update is another site pretending to be microsoft windows, of course I had no idea, anyway, the trojan has taken over my nortons and disabled auto protect. I have been looking for a thread here but havent found one on how to dl with a crashing computer. Thanks.
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here are somethings to try:
    - can you connect and download in safe mode
    - bring up TaskManager (or the Process Manager in HijackThis if you have it on the PC) and exit all unknown processes. Now can you download.
    - do you have a CD burner available where you can download the files to another PC and burn to CD and then use it to install on the infected PC
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds