Computing.Net > Forums > Windows 95/98 > Trojan Virus: Spyware, wowexec

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojan Virus: Spyware, wowexec

Reply to Message Icon

Name: Deven Hariyani
Date: August 23, 2003 at 14:58:56 Pacific
OS: WinXP Pro SP2
CPU/Ram: PIII 750MHz
Comment:

Hello,
I have unknowingly downloaded a trojan virus that seems to be installing spyware all over my laptop, and I cant get rid of it. I have already used: spybot search and destroy, adaware, spy sweeper, spystopper, etc.. to remove all detected spy ware. However, there are still programs trying to get access through my firewall client and I am still getting pop up advertisements. After some investigation here is what I have found. I have noticed suspicious processes running such as: Bdeu.exe, YdicV.exe, RjaZ.exe, and Roj12unt.exe. Everytime I kill one of these processes it will regenerate with one of the above names. So, next I went to the Registry, HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ and deleted the suspicious key value: "5Z9FK624L@JD8K", data: "C:\WINDOWS\System32\Xhf5Pw5.exe" (NOTE: I have checked c:\windows\system32 and I see no signs of "Xhf5Pw5.exe" so I cannot simply delete it.) After that, I went to the c:\windows\prefetch folder and deleted all entries that referenced the above suspicious .EXEs such as "BDEU.EXE-05B9253C.pf", "YDICV.EXE-2084E07E.pf", etc. But, the virus does not die! When I shutdown/restart the computer it must be rewriting the reg keys because everything i deleted from the registry is regenerated. I need to find the root of this virus and where it lives so I can exterminate it. Does anyone have any ideas??

As another side note, I have noticed that the "wowexec" process is being used somehow. From my research on this process it emulates the Windows 3.1 16 bit environment for certain 16 applications (or viruses). Even when I try to delete this .exe from c:\windows\System32 it regenerates itself as well.



Sponsored Link
Ads by Google

Response Number 1
Name: Frenchie
Date: August 23, 2003 at 15:42:10 Pacific
Reply:


Hi Deven Hariyani, hi everyone,

You seem to mix up virus, trojan and spyware.

All the utilities you ran are antispyware... they are very good in their category but not enough for viruses or trojans.

Scan your disk with this antivirus:
-> Trend Micro online AV scan

Antivirus are usually able to detect and eradicate many trojans but some are tough!
Good antitrojans are not free... however try these:
-> HiJackThis
-> onLine scan anti-parasite
-> onLine scan anti-trojan

HTH
Good Luck Bill!

Have a good day,
Gérard from Paris, France


0

Response Number 2
Name: Frenchie
Date: August 23, 2003 at 15:48:10 Pacific
Reply:


Hi Deven Hariyani, hi everyone,

>Good Luck Bill!
I'm sorry for having named you Bill! I confused with the guy of my previous post! ;-)

I don't know XP well enough and don't dare giving directions about system or registry!
I suggest you ask question on another forum of Computing.Net:
-> Windows XP
-> Security and Virus

Have a good day,
Gérard from Paris, France


0

Response Number 3
Name: Deven
Date: August 25, 2003 at 09:03:41 Pacific
Reply:

Oh yes, I did try an anti-virus software, but it didn't find anything. I also recently tried the "Trend Micro online AV scan" that Gerard reccommended, but that didn't find anything either. However, I downloaded the latest update from Adaware for their spyware removal software, and that seemed to solve the problem. I do not see the mysterious .exes appearing anymore. Thanks for the help everyone, it is much appreciated!

Cheers,
Deven


0

Response Number 4
Name: Frenchie
Date: August 25, 2003 at 13:43:30 Pacific
Reply:


Hi Deven,

Thanks for posting back!

Cheers,
Gérard from Paris, France


0

Response Number 5
Name: gazassassin
Date: August 26, 2003 at 10:46:52 Pacific
Reply:

This is NOT Spyware you may have some running on your system but this IS NOT IT :

wowexec - wowexec.exe - Process Information
Process File: wowexec or wowexec.exe
Process Name: Windows On Windows Execution Process
Description: Windows On Windows Execution Support Process provides support for 16-bit Windows applications together with ntvdm.exe
Common Errors: N/A
System Process: No


thx 2 :

http://www.liutilities.com/products/wintaskspro/processlibrary/wowexec/


0

Related Posts

See More



Response Number 6
Name: MiD
Date: September 10, 2003 at 07:39:53 Pacific
Reply:

Don't jump the gun 'gazassassin'. If the user has a wowexec.exe in the process list, it is a valid windows component used to run 16bit apps. BUT, if you have _wowexec.exe (prefixed with a space), then it is Adware.

Use 'Spybot Search and Destroy' (freeware) to remove this and other bollox on your system.

Laters


0

Response Number 7
Name: HossMonkey
Date: September 11, 2003 at 02:03:31 Pacific
Reply:

Short Version:
I updated & ran "Spybot - Search & Destroy" (http://www.safer-networking.org/)to get rid of a mouse skip/delay thought to be caused by csrss.exe or " wowexec.exe"?

I haven't downloaded anything but BIOS & drivers with this system? Is the wowexec.exe activated/dl'd through ActiveX?

Info: Running spybot can and will render some adware/spyware programs "useless" (ie. Kazaa).

Long version:
I've just come across the same if not similar scenario? The pointer on my GF's computer was skipping around & myself being had a few times by a couple of viruses, brought up the task manager (ctrl + alt + delete) to see that csrss.exe was randomaly grabbing CPU "time"? Being somewhat familuar with processes & having never noticed this process before I did a google search which lead me to Symantic (norton's)http://www.symantec.com/avcenter/venc/data/w32.dalbug.worm.html; Reading through this link I also discovered that smss.exe was also running & suspected that this machine maybe infected with the W32.Dalbug.Worm viri? I then updated the anti virus definition & ran norton's antivirus in safe mode (twice) only to come up blank (no viri)!? I then noticed " wowexec.exe" (offset with a space)& did a a google search which lead me here. I then updated & ran "spywareblaster" (http://www.javacoolsoftware.com/spywareblaster.html) to find I was already protected? I then updated & ran "Spybot - Search & Destroy" (http://www.safer-networking.org/)to find that "alexa related:What's related link" was "activated"? I "immunized" it & rebooted to see that the mouse no longer had a skip/delay & the " wowexec.exe" was gone.

PS Thanks guys for pointing out wowexec.exe ,
I missed it in the task manager!?


0

Response Number 8
Name: Frenchie
Date: September 16, 2003 at 04:07:21 Pacific
Reply:


Hi HossMonkey, Deven Hariyani, gazassassin, MiD, hi everyone,

HossMonkey, thank you for your post... very interesting!

Have a good day,
Gérard from Paris, France


0

Sponsored Link
Ads by Google
Reply to Message Icon

screensaver won't save sc... Browser HiJacked!!!



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Trojan Virus: Spyware, wowexec

Backdoor Trojan virus on Win98 www.computing.net/answers/windows-95/backdoor-trojan-virus-on-win98/137424.html

trojan virus www.computing.net/answers/windows-95/trojan-virus/142904.html

nap.exe ? Trojan? Virus? Causing probs.. www.computing.net/answers/windows-95/napexe-trojan-virus-causing-probs/72469.html