Re: wins32.exe - virus? trojan? malware?

From: MJ (mstanton_at_nospam.matrixcc.com)
Date: 07/05/05


Date: Tue, 5 Jul 2005 15:43:14 -0400

Thanks for the info. We've already ran McAfee Virus Scan, TrendMicro's
online scan, Spybot S&D, and The Cleaner by Moosoft. We've been to they
spywareguide site you included a link to and tried the removal process
suggested there, and it's not the SurferBar. What we've found when we've
googled the filename is that it could be masquerading as Microsoft Update
Machine (added by the RBOT.EZ Worm), task_mng_help (added by the
W32/AGOBOT-JB WOrm), win32_usb2 (added by a variant of the WIN32.RBOT Worm)
or SurferBar. However, in reading about these various program names, and
how to remove, the file is not in any of the directories that they list. It
is only in 2 places - a hidden system file in the System32 folder, and in
the registry (path specified in original post below).

"Art" <null@zilch.com> wrote in message
news:psjlc11aoaufgjopa6b902taaq1pkvo291@4ax.com...
> On Tue, 5 Jul 2005 12:11:55 -0400, "MJ" <mstanton@nospam.matrixcc.com>
> wrote:
>
> >We noticed the other day that no one could access any network shares on
one
> >of our W2k servers. This happened once before, and we found a
> >virus/worm/trojan (whatever you want to call it) that was the culprit.
So
> >we ran new virus scans and spyware scans and found nothing. However, in
the
> >registry under HKLM/Software/Microsoft/Windows/CurrentVersion/Run - there
> >was an entry for wins32.exe. Googling this filename turned up many
results
> >listing the file as a worm/trojan, but none of the descriptions of where
to
> >find it and how to get rid of it worked. In the registry the name is
> >wins32.exe and the data says C:\Windows\System32\wins32.exe. When we
delete
> >the registry entry, it recreates itself. In the system32 folder you can
> >only see it if you uncheck "Hide protected operating system files". We
> >renamed it there, whacked the registry entry again, but it still
returns -
> >recreating itself as a hidden system32 file and in the registry.
Luckily,
> >this server is not critical to our day-to-day operations, so we've
unplugged
> >it from the network. This file does not exist in any of our other W2k
> >Servers, so we're pretty sure it's a bad file. We are just at our wits
end
> >trying to remove it!! Any help/ideas would be greatly appreciated!!
>
> I suppose you tried this removal procedure?:
>
> http://www.spywareguide.com/product_show.php?id=615
>
> Working with just file names and no malware name is difficult since
> often there are several different malwares that use the same file
> name(s). Your best bet is to do a scan of the drive(s) using a real
> "heavy hitter" like KAV, assuming you haven't. Requests for
> help should always include the names of the av and spyware
> products you've already tried since their capabilities vary. Did
> you try Trend's Sysclean, for example?
>
> Also, it's best to post such help requests on alt.comp.virus
>
> Art
>
> http://home.epix.net/~artnpeg



Relevant Pages

  • Re: Final Report Vundo
    ... registry is more easily done from the XP partition. ... ddayv.exe and ddayv.dll in the system32 directory, ... I can also boot into ... Download and run firefox to protect your from future spyware ...
    (microsoft.public.windowsxp.configuration_manage)
  • Re: How do I get rid of this annoying site?
    ... you know why spyware is such a headache is that there are hybrids ... One registry cleaner and make sure it knows what it is doing. ... Unfortunately when you go to install ... > as once most get on your system they don't leave after uninstall. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: VX2 - My Victory!
    ... I was having problem with an unknown VX2 spyware. ... it will call a DLL. ... >> I search the registry for these two files. ... I DID NOT RESTART THE COMPUTER. ...
    (microsoft.public.security.virus)
  • Re: Home Page in IE Options Shadowed
    ... I have tried checking the registry values you list> but ... I have already tried Spyware ... If you can, uncheck it, If you can't, change the home page to what you want and then uncheck one and then reboot. ... "They who would give up an essential liberty for temporary security, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: How do I get rid of this annoying site
    ... > and your registry is forced into a total conflictive mess. ... I wish that antispyware applications were at that point, ... Same for immunization from spyware - although IE-SpyAd is pretty ... > legitimate software like Real Player and Ipod install spyware on your ...
    (microsoft.public.windowsxp.help_and_support)