Unable to launch any program & Other problems... Help?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kclives, Jun 5, 2011.

  1. kclives

    kclives Private E-2

    Hi this is my first post here and atm I'm really stuck as how to fix my laptop PC.

    I'm running Windows 7 64bit and a variety of problems have recently besieged my PC in a very short space of time.

    My original problem was the Google redirect problem, and to resolve it I attempted various fixes posted online such as clearing browser caches, flushing the DNS and running both MBAM and Spybot. None of these appeared to fix my problem.

    A day later some applications stopped functioning on my laptop, namely Chrome and Skype, despite reinstalls they still did not launch. At this point I ran MBAM again.

    Now after a reboot my laptop is completely unable to launch any application that is NOT an application that comes as standard with Windows (e.g. Paint and Calculator will launch).

    When I attempt to launch any application even in Safe Mode as an admin the process loads in task manager but around ~30 seconds afterwards it disappears from the processes list. All applications that do this seemingly use 0% CPU and around 1MB of memory before being killed.

    One thing I have noticed is that processes that are meant to start on boot that are killed have the description of "Wuhasys X X X X" (where the X's are often a set of numbers) under task manager. I presume the Windows Wuha.sys has been infected?

    I'm stuck as to any solution, as of now I am backing up my important Documents and preparing to do a System Restore in Safe Mode as under normal Windows the Restore process failed. If that fails I'm left will reinstalling Windows which I really don't want to go through, and as such I'm looking for any possible fixes, however time consuming they may be.

    Thanks :(
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. kclives

    kclives Private E-2

    Thanks for the reply, today I've been following a lot of stuff I've read on this site. The software I used today included MBAM, ComboFix, GooRed and TDSSkiller. I also uninstalled my copy of NOD32 and installed a fresh copy of Kaspersky.

    I've been through most of the READ ME guide and I've also been through the Google redirect guide. I've also uninstalled a lot of software and after multiple reboots in and out of safe mode I have eventually managed to get my laptop working fully, however I have two problems remaining.

    The first is that whenever firefox or iexplore is launched multiple processes are created and another process is created called either "firefoxmgr.exe" or "iexploremgr.exe" is launched. This process is identical in size to another process that occasionally launches called "wcspcpxr.exe". For all 3 the description in Task Manager is as I described in my first post "Wuhasys Gify XXXXX" where the X's are numbers.

    The second problem is that upon reinstalling a fresh copy of Kaspersky Internet Security it has detected a bunch of my files are infected with Win32.Nimnul.a, which it started to "disinfect" which started corrupting some of my programs, as a result I cancelled the disinfection.

    I think I will just undertake a full format and reinstallation of Windows as I've now managed to back up all of my critical data. Unless you could suggest otherwise.

    Thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My guess is that you have a Ramnit infection, which can be a nasty to remove. You can check this by doing an eset online scan:

    eSet Online Scan.

    However, take heed of this warning:
    Ramnit infections have really become quit nasty and dangerous. We could attempt to remove it, and we have had some success in the past, but recently it has become even more trouble to remove. It is really safer to just bite the bullet and do a clean reinstall.

    The problem is that the damage caused by this infection really makes a PC unreliable/untrustworthy. PE file infectors like Ramnit, Virut,.... etc can infect all executable files (DLL, EXE, SCR....and many more and also HTML). These infections can open back doors that truly may compromise your computer and your security. These backdoors could allow a remote attacker to access and instruct the infected computer to download and execute more malicious files.

    In many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus or by other scanning tools. Also when disinfection is attempted, the files often become corrupted and the system may become unstable or irrepairable. The longer Ramnit remains on a computer, the more files it may infect and/or corrupt so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies the Ramnit worm using a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are a major source of system infection.

    So all the above being said, and please do take serious note of the warnings, do you really wish to attempt cleaning even though the stability and security of your be cannot be guaranteed? And also note that we could spend a lot of time trying to fix it and still fail due to the number of files that have been infected. What would you like to do?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds