Computing.Net > Forums > Security and Virus > winupgro.exe virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

winupgro.exe virus

Reply to Message Icon

Name: yang0809
Date: January 1, 2009 at 08:58:50 Pacific
OS: Windows XP
CPU/Ram: 1.7G/512M
Product: Ibm / T42
Subcategory: Viruses
Comment:

Hi, my laptop gets the infection with winupgro.exe. It takes 90% of the CPU. I read several threads regarding this virus. It seems like that the only hope is using combofix. Should I run it?

My OS is WinXP with SP2.

Thanks for the help.



Sponsored Link
Ads by Google

Response Number 1
Name: amvinfe
Date: January 1, 2009 at 09:25:21 Pacific
Reply:

Hi,

yes you can use ComboFix, remember before you download it to your desktop to change the name with an alpha-numeric and a special value for example @ (eg cf@12)

Finished brought in C:\ and loads on http://www.freefilehosting.net
ComboFix.txt file, type the URL to download the report.

Ciao,
Marco


0

Response Number 2
Name: yang0809
Date: January 1, 2009 at 10:06:15 Pacific
Reply:

Thanks for the reply. I have run combofix and completed. Here is the link to the result log.

http://freefilehosting.net/download...

Do I need to do anything next?


0

Response Number 3
Name: yang0809
Date: January 1, 2009 at 10:18:45 Pacific
Reply:

btw, I am using Chinese verion of windows. Hence, the log contains chinese charaters.

Also, the anti-virus program I have installed is Norton. Not sure if it matters.

Thanks


0

Response Number 4
Name: amvinfe
Date: January 2, 2009 at 09:32:01 Pacific
Reply:

Hi,
excuse me for being late

download http://swandog46.geekstogo.com/aven...

disconnect from the Internet, disable anti-virus and any forms HIPS.

Run avenger.exe, copy and paste inside the white box this script:


Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

registry keys to delete:
HKLM\system\currentcontrolset\services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\srosa
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SROSA

Files to delete:
c:\documents and settings\Terry\Application Data\drivers
C:\Documents and Settings\Terry\Application Data\drivers\srosa.sys
C:\Documents and Settings\Terry\Application Data\drivers\winupgro.exe
C:\WINDOWS\system32\wintems.exe
c:\windows\system32\ban_list.txt
c:\windows\system32\mdelk.exe
C:\Documents and Settings\Terry\Application Data\m\flec006.exe
C:\Documents and Settings\Terry\Application Data\drivers\srosa2.sys

Folders to delete:
C:\Documents and Settings\LocalService\Application Data\drivers
C:\Documents and Settings\Terry\Application Data\drivers
C:\Documents and Settings\Terry\Application Data\m

Put a check "Automatically disable any rootkits found", click "Execute".
The PC should reboot alone, otherwise you restart.


Brought in C:\ copy and paste the contents of the file avenger.txt

--
download to your desktop
http://www.suspectfile.com/systemscan
open it and make sure that all options are checked, click on "Scan Now" at the end of the scan will be released (always on your desktop inside the folder suspectfile) two files.
Go to office http://www.freefilehosting.net the zip file and write in your next reply URL where I can get it.

Remember the scan with no connection with the antivirus disabled unless then resume scanning finished.

NB
the duration of the scan may be long, it might even seem that the program is not working, do not worry is not so;)

SystemScan is recognized, mistake, by some antivirus as infected.
--

Ciao,
Marco


0

Response Number 5
Name: amvinfe
Date: January 2, 2009 at 09:48:21 Pacific
Reply:

There are still active infections, while I wait for the report SystemScan go on

Start> Run and then type regedit OK

helping with the + brought in

HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2

Open the yellow folder mountpoints2 search and delete (click with the right mouse button and then "Delete") the value

{49e82ab5-cd0a-11dd-bf27-000e3514ae26}

press the F5 key close the Registry and reboot your computer
--


0

Related Posts

See More



Response Number 6
Name: yang0809
Date: January 2, 2009 at 11:11:10 Pacific
Reply:

No problem. Thank for spending time helping me. Appreciated.

Here is the links to the zip file and the report.

zip: http://freefilehosting.net/download...
report: http://freefilehosting.net/download...

btw, there are several errors reported in avenger.txt, regarding that several registry keys cannot be found. Is it expected? I also upload the file to the web, in case you would like to take a look. http://freefilehosting.net/download...


0

Response Number 7
Name: amvinfe
Date: January 2, 2009 at 12:46:53 Pacific
Reply:

For values in the registry is normal.
All values were removed from ComboFix, I wanted to see not only that they had recreated.

ComboFix a value that never fails to remove, because it is not sought during its use, is the "drivers" in C:\Documents and Settings\ username\Application Data\drivers, and The Avenger we have removed.

The report is ok, you have some other problem?

Ciao
Marco


0

Response Number 8
Name: yang0809
Date: January 2, 2009 at 13:08:06 Pacific
Reply:

ic. Thanks a lot.

One more problem. I could not activate the auto-protect of my norton anti-virus program. It was turned off when the laptop was infected by the virus. Any idea how I can fix it? or I need to uninstall/install the program again ?


0

Response Number 9
Name: amvinfe
Date: January 2, 2009 at 14:46:25 Pacific
Reply:

winupgro.exe (Bagle malware) infected programs for security, uninstall and reinstall Norton again :)

Ciao,

Marco


0

Response Number 10
Name: yang0809
Date: January 2, 2009 at 19:51:24 Pacific
Reply:

ok.. thanks million times.


0

Response Number 11
Name: egomoo
Date: January 14, 2009 at 05:49:05 Pacific
Reply:

Here is a guide to get rid of winupgro.exe
http://www.xdelbox.com/how-to-remov...


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: winupgro.exe virus

winupgro.exe virus www.computing.net/answers/security/winupgroexe-virus/24101.html

winupgro.exe virus(mdelk.exe) www.computing.net/answers/security/winupgroexe-virusmdelkexe/24057.html

winupgro.exe virus part 2 www.computing.net/answers/security/winupgroexe-virus-part-2/24082.html