winzod32.exe removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by neekee, Jun 30, 2006.

  1. neekee

    neekee Private E-2

    I have run Hihackthis but am afraid to delete anything. Hope someone can help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    HijackThis is the last step not the first step!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. neekee

    neekee Private E-2

    Got it. Will do.

    Thank you Chaslang!

    P. S. I had previously run Ad-Aware SE Personal and Spybot-Search and Destroy 1.3. I also cleaned out all temp and TIF files, ran Disk Defragmenter and Disk Cleanup.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow the READ & RUN ME from beginning to end completing all steps in order. Thus running you scans over again. Note your tools are out of date. Spybot 1.3 has not been used for more than a year. You better check Ad-Aware too. Click our links and verify you have the correct software versions and then get all updates too.
     
  5. neekee

    neekee Private E-2

    Hi Chaslang!

    Thought I would give you an update...

    I got through step 5 of the "Read and Run Me First" list and then ran into trouble. Had trouble downloading Java then finally figured that out.

    Now I am having trouble downloading Internet Explorer. (I use Mozilla Firefox.) I guess I deleted it from the program files and am now having trouble resurrecting it. :mad: Apparently the Bitdefender Scancannot be run without it.

    Also Windows Defender "encountered error 0x80501001... One or more actions could not be completed successfully. TV Media Display." It was listed as "Severe". I have three monitors. I don't know if this is causing the problem. One of the monitors doesn't always behave like the other two. For example, when in Safe Mode, one monitor stays black while the other two behave the same. Also, when rebooting (in normal mode) one screen stays black as the other two start to percolate. ???

    Computer Specs: Microsoft Windows XP Version 2002 Service Pack2, Pentium(R) 4 CPU 2.00GHz, 1.99 GHz 256 MB of Ram

    I am planning on calling Microsoft about downloading Internet Explorer.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually Internet Explorer cannot and should not be truly uninstalled from a system. This is a bad idea if you did that (as you can see). Many, many websites will only work properly with IE. Especially Microsoft. Without IE, you cannot get all of your require Windows Updates and possibly other Microsoft software updates. [/quote]

    Some one in the Software Forum may be able to give you some help with IE.

    In the mean time, substitute the below for the instructions in step 6 of the READ ME and then continue onto step 7.

    Running Ewido Anti-Malware - attach the requested log


    Also run the below procedure and attach the newfiles.txt log.

    Using ShowNew
     
  7. neekee

    neekee Private E-2

    Hi Chaslang,

    Attached are two files for Ewido and one for ShowNew.zip. I ran Ewido twice to find the original Notepad text and thought I should send both rpts.

    As I mentioned before, Windows Defender indentified problem listed as TV media Display -Severe (c:\documents and setting\mm\application data\tvmcwrd.dll) but encountered an error when it tried to delete it.

    I did not run Bitfinder or Panda. I now have access to IE but there are some quirks apparently and Dell Support in India :eek: is supposed to help resolve Monday evening. (They originally tried to restore my computer do date before I deleted IE; however, there were no restore points available, which I thought was strange. We finally got IE by reinstalling windows from the disk but we got error messages when trying to save settings.)

    Would you like for me to try to run Bitfinder and Panda?

    I will send Hijackthis log in separate post.
     

    Attached Files:

  8. neekee

    neekee Private E-2

    Chaslang, here is my Hijackthis log.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not run multiple instances of HijackThis and you must post HijackThis logs from normal boot mode as per step 7 of the READ ME.

    C:\DOCUME~1\MONIQU~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
    C:\Program Files\Spyware Tools\HijackThis.exe

    Please get a new log (after doing the below steps too) from Normal Boot mode using only this one C:\Program Files\Spyware Tools\HijackThis.exe

    Also make sure you have selected Normal Startup with MSconfig.

    Also DISABLE Spybot's Teatimer as requested in the READ ME.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
     
  10. neekee

    neekee Private E-2

    Hopefully I got it right this time!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZod32.exe
    C:\Documents and Settings\Monique Meyer\Start Menu\Programs\Startup\WinZod32.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [winndata] C:\WINDOWS\SYSTEM32\zod32.exe
    O4 - HKLM\..\RunServices: [Winupd] C:\WINDOWS\SYSTEM32\zod32.exe
    O4 - HKLM\..\RunOnce: [Winupd] C:\WINDOWS\SYSTEM32\zod32.exe
    O4 - HKLM\..\RunServicesOnce: [Winupd] C:\WINDOWS\SYSTEM32\zod32.exe
    O4 - HKCU\..\Run: [Winupd] C:\WINDOWS\SYSTEM32\zod32.exe
    O4 - HKCU\..\RunOnce: [Winupd] C:\WINDOWS\SYSTEM32\zod32.exe
    O4 - Startup: WinZod32.exe
    O4 - Global Startup: WinZod32.exe
    O21 - SSODL: winup - C:\WINDOWS\SYSTEM32\zod32.exe - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZod32.exe
    C:\Documents and Settings\Monique Meyer\Start Menu\Programs\Startup\WinZod32.exe
    C:\WINDOWS\SYSTEM32\zod32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  12. neekee

    neekee Private E-2

    Hi Chaslang!

    The new HJT log is attached.

    After booting into safe mode I was not able to locate any of the three files that you listed. The first directory had two items present: \startup\desktop.ini & Microsoft Office Shortcut. The second had one item: \startup\ Desktop.ini.

    An icon for Desktop.ini is on my Desktop as well and I don't know how it got there or what to do with it.

    Things are working better! After rebooting my computer I no longer get an error message telling me that Windows can't find a directory containing zod32.exe and to "make sure that I type the name correctly". Also (after rebooting) my computer ceases to make the awful sound that sounded like someone banging all the keys of a piano at one time.

    Are there other items in the Hijack log that may not be Malaware but by deleting may help my computer to run more efficiently?

    I have not run System Restore at this point.

    Thank you for all of your help! :)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes Norton/Symantec software. :D Be careful what you ask for, you just may get it. :D I'm only kidding, we don't particularly like Symantec because it is such a massive resource hog and we don't find it to be particularly good at blocking or fixing many malware issues. But if you are happy with it, keep it.

    Is your copy of Ewido a free trial or a paid version? If free, you should uninstall it and keep Windows Defender.

    If Ewido is a paid version, keep it, and uninstall Windows Defender.

    You don't need the below to run at Startup either, so you can have HJT fix them. This will help improve performance and startup time.
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE



    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  14. neekee

    neekee Private E-2

    Thank you for those tips!

    Question: Is there anything that I need to do to correct the error message that Windows Defender had when it could not delete "TV Media Display - Severe"?

    Also, what is desktop.ini and can I delete the icon on my desktop?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Boot in safe mode and delete the file you mentioned:

    c:\documents and setting\mm\application data\tvmcwrd.dll

    If you cannot delete it, try renaming the file to tvmcwrd.ddd. Then reboot again and try to delete the tvmcwrd.ddd file.

    It is part of Windows. See the below:

    http://msdn.microsoft.com/library/default.asp?url=/library/en-us/shellcc/platform/shell/programmersguide/shell_basics/shell_basics_extending/custom.asp

    You can delete it if you want but it is not a problem.
     
  16. neekee

    neekee Private E-2

    Help! :eek:

    I thought all was good with my computer and then yesterday it locked up several times and even shut down one of my programs. Originally when I started this thread I didn't have any major problems but I had a prompt at Start Up telling me to look for a file containing winzod32.exe and I could see processes running with that name.

    Last night I started the "Read & Run Me First" list and, as I was running Bitdefender, Norton posted message that it detected and deleted virus W32.Dozic.

    Even after finishing all the procedures in your list I am still having trouble... a program I use posted an error message, locked up and shut down. :confused:

    Could you please review my reports... again!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you follow the below instructions that were given in message number 15?
    Do this now and tell me if you still get any messages from Norton.

    You did not empty your Norton Quarantine as requested in step 0.

    You can also delete the below which have nothing to do with the infection Norton found.
    C:\WINDOWS\backup\TB041015.DAT
    C:\WINDOWS\INF\biini.inf
    C:\WINDOWS\INF\polall1r.inf
     
  18. neekee

    neekee Private E-2

    Hi Chaslang!

    Yes I did follow the System Restore instructions as stated in message 13. I did this again, just a moment ago, after reading your reply.

    I have emptied the Norton Quarantine. Last night was the first time that Norton has ever detected a virus on my computer. Also, Norton ran a scan and posted it's detection as I was running Bitdefender. For these reasons, it did not dawn on me to go back to the beginning of the "Read & Run Me First" so as to get rid of the quarantine.

    The only message I received from Norton was last night telling me that it had detected and deleted a virus.

    I deleted the files you mentioned. Thank you.

    Is there anything else that I need to do?

    Thank you mucho for all your help! :)

    P.S. I have installed Sygate Firewall and am having trouble determining what to allow and not allow. Any suggestions? I'm thinking that I should just stick with MS's firewall b/c I'm afraid my ignorance may cause more harm than MS.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not if you are no longer having any problems with things being detected.


    No! The MS firewall is totally inadequate and would still have to be told what to allow in an out anyway. In most cases you should know that an executable is related to something that you just ran. In other cases, you can search Google or Excite for the file to determine what it is.

    A site you may find useful is below:

    http://www.liutilities.com/products/wintaskspro/processlibrary/

    Another is below (click on the A to Z letters to look up the process your want to know about):

    http://www.bleepingcomputer.com/startups/
     
  20. neekee

    neekee Private E-2

    Hi Chaslang!

    My computer is working well thanks to you! Also, I'm sticking with Sygate as you advise (and thank you for the process reference websites).

    Thank you, thank you for all of your help. Major Geeks is the bomb!

    Neekee
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds