twump_32--Making Sure it's TOALLY gone

Discussion in 'Malware Help (A Specialist Will Reply)' started by Photorestorer87, Nov 30, 2013.

  1. Photorestorer87

    Photorestorer87 Private E-2

    Hey all,

    I'm running Windows 7-64 bit on an Acer netbook.

    I recently had an issue with the malware program twump_32.exe. I ended up completely wiping my hard drive (PRNG-3 passes), doing a clean install of Windows 7, and running several scans by different programs before cloning my hard drive and upgrading to a solid state drive. It has been a week since I swapped the hard drive, and I have been running periodic scans by malwarebytes and ESET NOD32. Today, I decided to go in and check my registry, processes, program folders, and Windows folder to make sure everything was gone. Sitting in the Windows folder was twump_32 again! malwarebytes, ESET, CCleaner, and explorer and regedit searches all failed to to detect it.

    I deleted the virus files and my TWAIN files with IObitUnlocker, ran malwarebytes,eand their rootkit program, and then followed all the steps on this page for malware removal, but I'm still concerned that the virus might still be on my computer, especially since google won't return any results when I search for twump_32 on my computer OR my iPhone. I've attached the folder from my MGtools scan. I'm wondering the following:

    1. Could the files still be hiding on my computer?
    2. Could the virus have infected my router and spread to other devices?
    3. Is there a way to check my prefetch folder for possible infection?

    Any help is greatly appreciated.

    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    For us to properly determine whether your PC has any malware you need to attach ALL of the files requested in the READ & RUN ME FIRST. MGtools alone is not enough. It is nor a malware scanner. It is an information collector.

    However if you totally wiped your PC then the likelihood that you are infected is very low. The file may be part of something you installed after you reinstalled Windows. Or if it is an infection as you are saying, then you most likely put it back on the PC by reinstalling files/programs from backups.

    Are you sure about the spelling of the file? Do you still have a copy that you could put into a ZIP file for attachment?
     
  3. Photorestorer87

    Photorestorer87 Private E-2

    Chaslang,

    Thanks for welcoming me to the forum, and for your quick reply. I did mispell the virus name. It is "twunk_32.exe." From what I have found through searching the internet, it is a known malware program. Since I used IObitUnlocker to delete the file, I do not have access to it anymore, and can't send it to you. In the unlikely event that it did slip under the radar after I had done a clean install and cloned the drive, I may have a copy in a system backup on an external hard drive that I created with Paragon Backup & Recovery. I don't know how to check it for the virus though....

    Apologies for not reading the directions carefully enough. I have attached the scan logs from the various programs. There are some logs from previous scans, which I have included. There is also a quarantine file from RogueKiller. To make things easier, I have organized the files by program and uploaded them in a zip folder.

    Interestingly, my user account folder seems to have been copied to my desktop during the whole scanning process. In the original user account folder, there is a hidden folder entitled "my documents," right next to the typical folder. When I attempt to open the hidden version, I get the "access denied," message. I'm not sure if this is typical, or the sign of a problem.

    Thanks, again, for all of your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    There were versions of this filename that were associated with infections, but those all ran from a very specific location and caused certain behaviors to occur ( like mass emailing )..
    I think what you saw and incorrectly deleted was the legit Windows file twunk_32.exe that will be found in the C:\Windows folder. You will also see a twunk_16.exe file and also related twain.dll, twain_32.dll files. This file is for the Twain Thunker server. Example >> http://www.corrupteddatarecovery.com/File-Data/twunk_32.exe-Twain-Thunker-Twain-Working-Group-1,7,0,0.asp

    This is why nothing detected it as a problem. It was legit.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds