I need help with a Winshow virus please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by stritheor, May 10, 2005.

  1. stritheor

    stritheor Private E-2

    My girlfriend called me and told me her computer got infected with this virus and can't do anything. She downloaded HJT but can't install it. She's having problems getting internet pages to load. She ran Ad-Aware and it came up with some tracking cookies, and got rid of them, but nothing else came up. It's preventing her from opening websites with Quick Launch. It's preventing Windows from opening. RegEdit won't open unless in safe mode. AVG won't get rid of the virus no matter what option she chooses. She gets numerous errors from housecall (TrendMicro), it wouldn't install updates properly. She's about to just start deleting items in her registry that say "browser helper objects". Any advice?

    I tried walking her through the steps in the site below, but nothing on that site was on her computer. She gets lots of pop-ups advertising various things (kind of like 'only the best' i had a while back).

    http://www.securemost.com/articles/trou_3_remove_winshow.htm

    She has a:
    Gateway M350WVN
    WinXP Personal Edition
    AVG Free Edition
    Ad-AwareSE
    Spybot S&D

    All spyware removal tools were updated today.

    I'll relay all information to her as soon as I get it and post what happens until she can come here herself. Thank you in advance.

    If there's anything I left out that you need to know, I'll be on here all night, so it won't take long for me to get the info and post it.
    http://www.securemost.com/articles/trou_3_remove_winshow.htm
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. stritheor

    stritheor Private E-2

    She's telling me that she can't download anything with the internet. A message pops up saying "Your current security settings do not allow you to download this file". She has never had this problem before until the virus. She has also tried using Leech Get downloading assistant, and it won't download it either. It freezes up. The virus keeps killing her net connection so she can't get anything. She is on dial-up.

    Any other suggestions? Should she just continue throught the steps with what she has, i.e. Ad-Aware and Spybot?
     
  4. stritheor

    stritheor Private E-2

    Okay, nevermind for now. She finally got it to download and install after a lot of fussing and cussing. So, we're back on track for now hopefully. Once she's done with those, I'll post where she's at.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! If you still have problems after running the steps of the READ ME FIRST, follow the directions I gave and post a HijackThis log.
     
  6. stritheor

    stritheor Private E-2

    She couldn't run either of the online scans just as yesterday. Her internet keeps her from loading almost everything. She got to the symantec scan page, but it told her she couldn't scan because of her ActiveX control settings. She tried to change them, but her box was greyed out, it wouldn't let her change anything.

    The only way she's been able to see what processes are running is through MSInfo32. She can see dees.exe on there and we looked it up and saw that it's bad. She's trying to delete it.

    Is there any other way she can kill processes that are running without using cntl+alt+del?
     

    Attached Files:

  7. stritheor

    stritheor Private E-2

    I forgot to mention in the last post, she had to run HJT in safe mode. She couldn't get it to run at all in normal mode.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The HijackThis log you posted is from normal boot mode not safe mode. And that is what we want anyway. Safe mode is not typcially very useful. By the way HJT has a process manager that can show and kill processes. We will use it below.

    First a few notes:
    1) you did not install HJT where requested you have it on the Desktop
    C:\Documents and Settings\Kelly\My Documents\HijackThis.exe

    2) you did not exit all browsers before using HJT. Two IE sessions were running.
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\iexplore.exe

    3) SpybotSD.exe should not be running while fixing things. You should only have it running when doing a scan and you should not be using HJT at that time.

    Questions:
    1) Do you know what the below is and if valid, why is a program running from a Temp folder?
    C:\DOCUME~1\Kelly\LOCALS~1\Temp\{BC8D79F4-405E-4170-870B-2E9A11512EEA}\NaturalDesktop_full.exe

    2) Is the below Start Page valid?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.arcticcove.us/news_info.html


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\shicoxp.exe
    C:\WINDOWS\caxchg.exe
    C:\Documents and Settings\Kelly\Application Data\dees.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [shicoxp] C:\WINDOWS\shicoxp.exe
    O4 - HKLM\..\Run: [caxchg] C:\WINDOWS\caxchg.exe
    O4 - HKLM\..\Run: [Service Drivers] msnpg.exe
    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitemij32.exe
    O4 - HKLM\..\RunServices: [Service Drivers] msnpg.exe
    O4 - HKCU\..\Run: [Service Drivers] msnpg.exe
    O4 - HKCU\..\Run: [Ltho] C:\Documents and Settings\Kelly\Application Data\dees.exe
    O4 - HKCU\..\RunServices: [Service Drivers] msnpg.exe
    Nothing belongs in the Trusted Zone unless absolutely necessary to make a valid program work. 99% of the time, they are not needed.
    O15 - Trusted Zone: http://www.arcticcove.us
    O15 - Trusted Zone: http://www.astrocenter.com
    O15 - Trusted Zone: www.center.com
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4_optin/vet_install_popup.pl?3&4&04.00.10.1&unknown&unknown&http://www.viewpoint.com/pub/technology/vmp.html


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Kelly\Application Data\dees.exe
    C:\WINDOWS\shicoxp.exe
    C:\WINDOWS\caxchg.exe
    C:\windows\system32\msnpg.exe
    C:\windows\system32\elitemij32.exe <--- also delete any other files that begin with elite and end with .exe. There could be a bunch of them.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  9. stritheor

    stritheor Private E-2

    She decided to reformat instead. I'm sorry for the inconvenience and I appreciate your help.
     
  10. Kelltikelly

    Kelltikelly Private E-2

    Well that last post makes it look like I just chose to ignore the advice, Stritheor.
    After I got off work I didn't check my email (which was the only way I could get your instructions, Chaslang, because whenever I would connect I couldn't navigate to any websites, and I didn't want anymore inconvenience with all the popups and problems with my connection.)
    If I had known about this post beforehand I wouldn't have ignored it, I would have tried it for sure, but I decided to reformat because I am so pressed for time and I desperately needed my computer to get some work done.
    I am posting now not only to thank you Chaslang for all your time and effort, which is GREATLY appreciated, but to clear up a couple of things for anyone else who might be affected by this virus.

    First, I did go back and install HJT into another permanent directory, only I hadn't posted an updated log file for you to look at after I had received that advice. The fact that I got it to run in normal mode once was a fluke, and it didn't run again that way, only in safe mode later. I had the 2 IE windows open in part because I forgot they needed to be closed, but also because I couldn't manually open any windows, so I was afraid to close any for fear I wouldn't be able to navigate to websites to download these programs (which I couldn't anyway because of the virus eating up my connection.)

    On to the other stuff, you asked:
    Yes, it's a valid program that I use to change my desktop wallpapers. I had it running from a temp file because I ran it off one of my backup disks instead of installing it properly.

    Yes, it is valid, it is what I set my start page to myself.


    Lol, this is apparently the only piece of advice I had managed to follow (remember, Stritheor was walking me through this on the phone and by this time was delirious from all the stress from this stupid thing, so I obviously overlooked some things.)

    As for the rest, I hope your advice on what to remove can help someone else. I hated to reformat but at the time it seemed the only solution to get things back in working order to get everything done by a deadline.
    Thank you so much for your time.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for getting back to me. Too bad you did not wait a little longer. The steps in message # 8 would have fixed you up. You had a bunch of baddies. In order to help you avoid problems now that you have reinstalled, you need to make sure you follow all the steps in the below ASAP:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds