PDA

View Full Version : Infected with a myriad of worms



DeBoX
2008-04-13, 06:12
Right as the title implies, my system is stocked with stuff, but the issue here is that for some odd reason I can't get rid of anything. Right this is a long story to compress into a few sentences.

A short while ago my pc started acting really strange. My background changed into a blue sceenish kinda setup with a msg about being infected and a link to a site. Well having been in a similar siutation a few months back i ran spybot that found a nice little batch of things to take care off and figured that would be that. Well no not exactly... You see, shortly there after l noticed that i suddenly don't have access to the task manager(??) , and that certain other privilages have been limited ( access to certain folders has been resett etc).

Spybot finished the scan and the clean up, all nice and shiny. Had to reboot and all, figured this is gona be a snap. Well...no...

I login and the background is still screwed up, the pop ups still keep coming and still no access to the task manager.

I re-scan , and by king george, I find the exact same batch of nifty and crawly little critters. Still there and still going strong.

Now to make a loooooooong story short I have tried:

Safe mode
Multiple runs with this software
Multiple runs with other software
Online and offline anti virus runs

and no change what so ever. (well ok, the list has gotten a wee bit shorter)

The list of things and buggs is rather long, it's gotten a wee bit shorter over the past few days ,but a few persistent buggers keep sticking around.

Smitfraud -c
Smitfraud -c cg
virtumonde.dll

As well as several others, but l suspect that the main culprits are in the little list above.

Now can some of you lads or ladies help a poor bloke out???

I'm running a Win XP sp2 setup

and well don't really know what else is of importants to you??

Please help me out here...

thanks in advance!

Cheers
DeBoX

Blade81
2008-04-14, 11:42
Hi

Let's see your HijackThis log (taken in normal mode if possible) :)

Download and install TrendMicro HijackThis (http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe)
* Once installed open HijackThis by clicking Start > Programs > HijackThis and click the button labeled
Do a system scan only

* Click the scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
* Once the scan is complete the scan button will now read save log. Click this button to save the log file to your PC. Once you select where you would like to save the file it will open in your systems default text editor. Typically this application is Notepad. Post the log here.

DeBoX
2008-04-20, 02:45
I think l've managed to svolve the issue.

Right so this is what l did.... Found a program that was called processExplorer ( more or less like task manager, but as l mentioned earlier the bloody worms had deactivated that function for me) , did a quick install and found this little bastard :
wmsdkns.exe.

Right ,killed the process, did a scan with 3 types of software (amongst them was of course spybot). They of course found the same huge batch of little creepy buggers, but unlike before now they could all be taken out of action ( ie exterminated ).

Now l needed to just do one more thing , find the above mentioned file (wmsdkns.exe) and delete that one was well. Granted it to took a total of 4 tries to finaly get rid of the damn thing, but after that, the buggers haven't returned. :bigthumb:

Note a few things:

The file was located in the system32 folder, it was hidden, it couldn't be deleted without thrid party software and there are other files with similar names in the user profiles ( these are relating to windows media player codecs etc) . Now the last part is very important, these other files are not to be touched!!! (I deleted them and had to reinstall WMP)

I do hope this helps some other poor souls with this issue. Note this might be a solution for some of these:
Smitfraud -c
Smitfraud -c cg
virtumonde.dll


Perhaps, perhaps not...either way this worked for me and l wanted to share that with the rest of you lot.

Hope things work out ! :)

Kind regards

DeBo

Blade81
2008-04-20, 13:30
So, since the issue appears to be solved guess I'll archive this topic then. :)