Removing wri.exe Trojan?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Crystal Dragon, Jun 12, 2007.

  1. Crystal Dragon

    Crystal Dragon Private E-2

    I apologize in advance if this has been asked before. I am new to this forum. I am working on a friends computer that has been infected by what I think is a trojan or virus that shut off there firewall and anti virus programs when there teen daughter opened a file from a friend. After all that got shut down they tried to rerun the anti virus and the firewall they could not, and there was a new icon on the desktop "wri.exe".

    I have two questions on this problem.

    1 - If I remove stored pictures and music from that computer would I infect another computer by loading?

    2 - Dose anyone have a procedure for removing this problem?

    I have done some research and have not found any one thing, but running mutable removal programs seams to have worked. Witch ones should I start with and how do I know when it is gone.

    I know too many questions. I would like to save the computer without a total reinstall if I can. I could sure use the help

    Thanks,
    Crystal
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Potentially yes!

    Since you could have more problems than you know about and also since we need more visibility into what malware may or may not be on the PC, the best course of action is for you to do the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Crystal Dragon

    Crystal Dragon Private E-2

    OK next step?

    I have fallowed the Malware removal steps and here is the logs from the requested programs. The only program I could not get to work was the BITDEFENDER, I could not get IE to load the page at all. I updated my java but still no luck. I did run everything else that you said to do.

    I will attach the others on the next.

    Thank you so much!!!!!
    Crystal
     

    Attached Files:

  4. Crystal Dragon

    Crystal Dragon Private E-2

    Re: OK next step?

    here are the rest of the logs.

    Crystal
     

    Attached Files:

  5. Crystal Dragon

    Crystal Dragon Private E-2

    Re: OK next step? Help Please

    How do I know if I got everything out? I don't know how to read the logs to see. Could someone take a look at them for me and let me know what to do next.

    Thank you,
    Crystal
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: OK next step? Help Please

    Please remember to remain in one thread!!!

    This post & the fact that you also started a new thread instead of remaining in your original thread, cost you more than 24 hours of additional waiting time. Did you read this sticky thread? Don't Bump! It Only Hurts You!!!

    I merged you back to your first thread!

    You ignored the part of step 0 (and repeated in step 7) where we said you must not use MSconfig and that you must be in normal startup mode. Please run MSconfig now and select Normal Startup mode. Then reboot.

    After reboot, run this ChodeFix - How download and run

    Then attach new logs from
    • GetRunKey
    • ShowNew
    • HJT
     
  7. Crystal Dragon

    Crystal Dragon Private E-2

    Sorry!!! I did not know what "Bumping" ment, I started with the read me first. I am just a minor geek.:eek: I did not ignore the step but did not know when I rebooted it went back. Here are the new logs. Thank you for your help.

    I did do some work in HijackThis while I was waiting, I hope I didn't screw anything up.

    When I restarted in normal mode I keep getting 4 pop up windows that say:
    "windows cannot find 'C:WINDOWS\system32\vwjmyj\csrss.exe'
    what is that about.

    Thank you again for your help!!!
    Crystal
     

    Attached Files:

  8. Crystal Dragon

    Crystal Dragon Private E-2

    OOps!!! Ignore the logs. need to run codefix first. will send new logs.:eek:
     
  9. Crystal Dragon

    Crystal Dragon Private E-2

    OK here are the new logs
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the CounterSpy trial since we are finished with it now
    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O3 - Toolbar: (no name) - {EF56413F-9398-4DF5-BC88-6FC3B227D5C5} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKCU\..\Run: [csrss] C:\WINDOWS\system32\ctfmon.exe
    O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://D:\content\include\XPPatchInstaller.CAB
    O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://D:\Content\include\msSecUcd.cab

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey
    3. ShowNew
    4. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  11. Crystal Dragon

    Crystal Dragon Private E-2

    Well bad news. I turned on the computer with the problem (understatement, I am on another computer now), and the pop up for the firewall said it was off. When this all started that is what happened to the AVG firewall it was using. After uninstalling AVG payed addition while I was doing all this clean up I was just using the windows firewall until everything was clean and then I was going to put a better one on.
    I turned the firewall back on and did the steps you had in the last post, uninstalled the Counter Spy, restarted then something turned off the firewall again, I turned it back on, ran Hijack This did the fixes and downloaded Avenger and ran it as you said and restarted the computer. When it restarted something turned off the AVG e-mail scanner and the firewall. Could not get ether on, got this window:

    "could not start windows firewall/internet connection sharing (ICS) service"

    Then I could not go on line. I have dial up (live in country), after trying I get on I got:

    "Error connecting to toast.net" (my ISP) "registering your computer on the network... Error 720: a connection to the remote computer could not be established you might need to change the network setting for this connection"

    With out going on line I can't post the logs. Should I give up and reinstall? Should I start over? I don't have Counter Spy any longer.

    Crystal:cry
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What do you see in this folder? C:\Avenger

    If you see this file: tcpip.sys

    Copy it back to C:\WINDOWS\system32\drivers

    Then tell me if you can connect.
     
  13. Crystal Dragon

    Crystal Dragon Private E-2

    C:\Avenger only has backup.zip

    When I restart the computer something takes over. I can't even look in My Computer until it finishes turning off the firewall, and the AVG e-mail scanner. After that I can go anywhere.

    I looked in the startup under msconfig and the only thing I don't know is:

    C:\windows\system\ctfmon.exe
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Inside this ZIP file you should see tcpip.sys. Take a look and see. If you find it, extract it to the C:\WINDOWS\system32\drivers folder

    Normal!
     
  15. Crystal Dragon

    Crystal Dragon Private E-2

    Got it. Here are the logs.
     

    Attached Files:

  16. Crystal Dragon

    Crystal Dragon Private E-2

    rest of logs
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is AVG protecting your hosts file? Avenger was not able to delete the backup (which may have infected info) at:

    C:\WINDOWS\system32\drivers\etchosts.20070614-200305.backup


    How are things working now? Your logs are clean other than the above backup hosts file.
     
  18. Crystal Dragon

    Crystal Dragon Private E-2

    I don't know if AVG is protecting the files. How do I find out?

    It still is shutting down the AVG e-mail scanner and I can't get it on and I can't turn on the firewall, just get the same error message from previous post. It dose it on start up.

    Other than that it seams to be running fine, but can't leave it like this.

    I ran spy bot again and it found nothing. CCleaner dose find files to delete each time. Could not run the online scanner. I ran the regedit part of ccleaner and it did find stuff but I waited to here from you before I let it fix anything.

    Are we giving up yet? Or you got any ideas. Hate for them to loose everything.

    Crystal
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your only problems are with AVG and also I assume you mean the Windows firewall, then do the below and do it in the order given:

    1. make sure you have the current version of AVG downloaded: AVG Free Edition
    2. make sure you have curren updates for AVG downloaded: AVG Anti-Virus Updates
    3. download this firewall because the Windows firewall is totally inadequate and often gets disabled by malware: Comodo Personal Firewall
    4. now disconnect your cable to the internet to make sure no external connection can be made. You will need to print the below or save locally for reference while offline
    5. uninstall AVG Antivirus
    6. reboot (DO NOT SKIP)
    7. delete the C:\WINDOWS\system32\drivers\etchosts.20070614-200305.backup file
    8. re-install AVG from the new download
    9. install AVG updates from what was just downloaded
    10. install Comodo Firewall
    11. reconnect to the internet
    Come back and tell me what malware problems still remain.
     
  20. Crystal Dragon

    Crystal Dragon Private E-2

    Well so far so good. I did the last steps and it all works fine.

    I do have some questions.

    I am going to leave SpyBot on the computer, dose it need to run all the time or just run it manually every now and then? If it needs to stay on what needs to be scheduled?

    The Comodo Firewall seams to slow the loading of web pages, is it a system hog?

    This computer belongs to people that do nothing for maintenance so we need to set everything to auto but not so much that it slows it down.

    Can I remove all the logs and downloads that I have done?
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think most if not all of your questions should be addressed by my final steps and the link given in it. But as to Spybot, you only run it to do a scan or to install updates and reimmunize after updating. This is also covered in the below. Also, ALL firewalls will have an impact on performance. Not having a firewall (especially a true bidirectional firewall which the Windows firewall is not) is going to lead to an infected PC which is even slower and could result in worse problems. The below steps also give a few other free firewalls you could experiment with but don't install a second until the first is uninstalled.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  22. Crystal Dragon

    Crystal Dragon Private E-2

    Wow, this has been a learning experience!!! I take in friend's computers to fix when they are having a problem, I guess a hobby, I learn from every one I fix. This is the first one with so many viruses in it.

    Thank you sooooo much for what you do. As I understand it the best way to help this site is to buy software through it. If that is true I will send everyone I know here.

    Thank You and Brightest Blessings,
    Crystal )O(
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Yes that would be very helpful thanks! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds