Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome ( Log In | Register )
Easy as 1,2,3!

 
Closed TopicStart new topic
> [Closed] Problems with drwtsn, dwwin & imapi, Right-clicking on desktop & folders makes the program close
puremystyc
post Nov 6 2009, 09:40 PM
Post #1


New Member
*

Group: New Member
Posts: 2
Joined: 6-November 09
Member No.: 88,705
Operating System: Windows XP



I did some Photoshop brush downloads on Wednesday (11/4/09)...I guess this may have started the problems I'm having - maybe one of the files was infected??

Thursday morning I uploaded some pictures from my camera & when I right-clicked in the picture folder to re-name several pictures at once, an error message came up saying that windows had some problem and had to close. I continued trying to re-name the pictures, but everytime I right-clicked or tried to move them to a new folder, the same thing happened & it closed. I have the task manager up a couple times a day just to check on processes running & never noticed drwtsn.exe before. I did some research and know that these programs are critical & so I haven't deleted them, though I see them as the problem. drwtsn.exe pops up first. I end that process tree. Then dwwin.exe pops up and after I end that one, imapi.exe sometimes pops up. Now why imapi.exe pops up since that has to do with CD burning, I don't know.

I have run the Mcafee scan, the CCleaner, the SystemCare scan, the Malware Bytes, the Adaware...I think that's all of them. The only thing they've found are the pretty harmless missing file extensions & cookies, which were then deleted. None have found any virus or trojan or anything. I also ran HijackThis. I didn't do anything with that...I did send it to the main analyzing site though. I've been running these scans for the last two days & still having the drwtsn & right-clicking problems. I am out of ideas. Please help!


Attached thumbnail(s)
Attached Image
 
Go to the top of the page
 
+Quote Post
CatByte
post Nov 7 2009, 05:32 AM
Post #2


Classroom Administrator Assistant
Group Icon

Group: Classroom Teacher
Posts: 6,920
Joined: 18-November 04
From: Canada
Member No.: 18,614
Operating System: xp sp3



Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT



Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.


    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.


**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries




Go to the top of the page
 
+Quote Post
puremystyc
post Nov 7 2009, 10:56 AM
Post #3


New Member
*

Group: New Member
Posts: 2
Joined: 6-November 09
Member No.: 88,705
Operating System: Windows XP



Thank you so much for your quick response!! After reading the following, please let me know if I should still do the scan that you suggested in your reply.

After trying a System Restore three times since Wednesday (they wouldn't work), I tried one more time last night and set the System Restore to Tuesday (the day before I downloaded the Photoshop Brushes) and it finally worked.

The System Restore seems to have fixed the problem I was having, as now I can right-click, move pictures, move items on my desktop and haven't had any issues from drwtsn/dwwin/imapi showing up.

It did, however, delete at the very least, half of the Photoshop Brushes I downloaded on Wednesday. I don't understand why it only got rid of about half of them and not all or none of them. That's not a big problem though, I will just go through and see which ones I'm missing & re-download them - but scan them with McAfee before I unzip them to make sure they are okay. Does it sound like it may have been one of the brushes I downloaded??

So, as I said, it seems like everything is back to normal now, but please let me know if I should still run the scan you suggested.

Thank you SO much for your time!!

~Melissa
Go to the top of the page
 
+Quote Post
CatByte
post Nov 7 2009, 11:03 AM
Post #4


Classroom Administrator Assistant
Group Icon

Group: Classroom Teacher
Posts: 6,920
Joined: 18-November 04
From: Canada
Member No.: 18,614
Operating System: xp sp3



It it hard to say what may have infected you.

Lets run the scans just to make certain there are no infections remaining.
Go to the top of the page
 
+Quote Post
CatByte
post Nov 12 2009, 05:16 PM
Post #5


Classroom Administrator Assistant
Group Icon

Group: Classroom Teacher
Posts: 6,920
Joined: 18-November 04
From: Canada
Member No.: 18,614
Operating System: xp sp3



Due to inactivity this topic will be closed.
If you need help please start a new thread.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 20th November 2009 - 07:43 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy