Last nite I got the WPP malware. Did a search on another computer and got the instructions for removal from bleepingcomputer. At that time, I was able to get into Explorer. Followed the instructions and used a stick to download fixtm.reg and got WPP & svchast temporarily stopped. Got fixexe.reg and followed instructions. Tried to get Malwarebytes to run and it stops it and hjt and others from continuing to run. Now it won't boot all the way and I'm in the BSOD but can access task manager to TRY and run programs. Did successfully run TFC and tried others again but no luck. A number of error scome up when trying to boot that want me to run chkdsk. I can and have but that didn't get rid of the errors. Each time I boot back up I get the error messages and WPP comes back up and I can still go in to task mgr and "stop" it and svchast. I'm really up a creek here and could use your help, got myself good this time. In doing alot of reading here, I see I have a delself.bat on my Desktop. Tried to delete and it and I get blocked (like all the malware softwares), this one says Cannot delete delself" the file or directory is corrupted and unreadable. Don't know if this is relevant but probably is. Tried safe mode a number of different ways but it won't fully boot up there also. Again, I really need the help and thanks in advance.
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:
Absence of symptoms does not always mean the computer is clean
Please do not run any scans or fixes without my direction.
Finally, stay with this topic until I give you the final 'All clear' post.
Try this tool, if you can get it over to the infected PC and get it to run.
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan) Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
Don't know if the my fast reply went thru. Got exehelper to work in safe mode. Looks like it's working from the txt file.
exeHelper by Raktor - 09
Build 20090919
Run at 20:17:42 on 09/22/09
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Found file C:\WINDOWS\system32\desot.exe
Deleting file C:\WINDOWS\system32\desot.exe
Found file C:\Program Files\Windows Police Pro\Windows Police Pro.exe
Deleting file C:\Program Files\Windows Police Pro\Windows Police Pro.exe
Found file C:\WINDOWS\system32\dddesot.dll
Deleting file C:\WINDOWS\system32\dddesot.dll
Found file C:\WINDOWS\ppp3.dat
Deleting file C:\WINDOWS\ppp3.dat
Found file C:\WINDOWS\ppp4.dat
Deleting file C:\WINDOWS\ppp4.dat
Found file C:\WINDOWS\system32\sysnet.dat
Deleting file C:\WINDOWS\system32\sysnet.dat
Found file C:\WINDOWS\system32\bincd32.dat
Deleting file C:\WINDOWS\system32\bincd32.dat
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
Thankyou!! Havent rebooted yet.
1) DDS [external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt
Save both reports to your desktop.
2) RR
Please download RootRepeal.zip. Save it to your Desktop. Alternate download links here or here. Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program…use it to open the zipped file…then skip to Step 5. Otherwise…
Right click on RootRepeal.zip and select "Extract All"….
Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
Click on the Browse…button, then click on Desktop, then click OK.
Once done, check (tick) the Show extracted files box and click Finish.
Before running RootRepeal:
Disconnect from the Internet as your system will be unprotected while using this tool.
Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
When the program opens, click the Report tab at the bottom, then click the Scan button.
In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
The scan can take some time to finish. Do not use the computer while the scan is running.
When the scan has completed, a list of files will be generated in the RootRepeal window.
Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
Close and exit RootRepeal
Double-click on the file rootrepeal.txt… Notepad will open… copy/paste the file contents in your next reply.
Make sure to enable your anti-virus, Firewall and any other security programs you disabled. Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".
can I reboot or will I re-infect?
I'm still in safe mode and don't have a "desktop" to download too.
I can only use the stick to "launch" any of your requests from.
Thanks
Reboot, and it should hopefully go into normal mode.. if not, go back into safe mode.
Run DDS & RR. If they don't run, try running exeHelper again, then running them.
Download this Win32kDiag and save to your Desktop.
Double-click the Utility to run it and and let it finish.
When it states Finished! Press any key to exit, press any key to close the program.
It will save a Win32kDiag.txt file to your desktop automatically. Attach this log file to your next message.
Tried dds.pif and same result, would start and stop immediately.
BTW, I've still got alot of error messages that come up and ask me to run chkdsk.
C:\windows\$hf_mig$\KB901190
C:\windows\$hf_mig$\KB915865
C:\windows\$hf_mig$\KB926255
C:WINDOWS\$NtServicePackUninstallNLSDownlevleMapping$
C:\windows\assembly\NativeImages_v2.0.50727_32\Twain
I just proceed thru them, don't know if this is part of the issue in not getting windows to come up
Thanks
Wow, huge, huge file, it doesnt look like its repeating itself. Im getting hundreds of cannot access: Win32kDiag.exe - Corrupt File C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\dpwsockx.dll and alot of other dlls.
It finishes and asks to press any key but all I'm doing is clearing dialog boxes when I click the "ok" box. It's endless. I can't get to the file to give it to you. This is scary.
Help
I went back and tried rootrepeal again. Re-read your instructions and found the report tab and was able to check all the boxes as it was shown in your message. Got it to start the run but about 45 seconds in the program stopped. Tried to reboot and again go into safe mode and try again but same result. The previous rootrepeal did not have all the boxes checked, sorry, I messed up.
As rootrepeal started it immediately stated at the top "MBR rootkit detected" but it couldn't continue running.
As it stands now I can't get the report from win32kdiag, there's just tons of dialog boxes that say things (dll's, Software Distributions dll cache) are corrupt and I can't get the file to finish and give me a txt document to give to you. I also can't highlight the document and copy and paste to you either.
If I boot up not in safe mode, it goes to BSOD and I can open task manager to try and execute the softwares you're recommending but I have almost no luck. If I go into safe mode (any of them) I get some luck but some start and stop after a few seconds. Whatever this is, it must be "deep" and be able to thwart the malware removers and detectors. This is getting scary and i'm frustrated.
I do thankyou for the help and hope to hear from you tomorrow. From what part of the world are you from BTW. Would like to get more interface time if possible. I'm west coast Calif for your information. 2 kids and all keep us very busy..
We can keep proceeding, but this is going to be a tough one, and I'm not entirely sure what the outcome is going to be. Do you still have the original CDs to perform a format and reinstall, and do you think that's feasible in this situation?
I'm in Melbourne, Australia. Just hit 4:30pm here.
Raktor, thanks. I'm responding from work. I'm not sure I have the cd's but I'll check. I assume this reformat and reinstall would kill all the files in the computer? I've got all our family photos in there so you can see the wife would kill me, especially since today is our anniversary.
Is there any way in safe mode I can get access to my photo folders and put them on a seperate drive even if it was infected? I'm assuming that the malware is residing elsewhere in the master boot and other places, probably not in these folders.
I'd like to proceed with other "tools" than going to a total reformat.
Thanks Raktor
I found the microsoft office software disk and the original toshiba recovery/applications disk that came with it. In reading up on this elsewhere the toshiba disk would totally wipe the drive and reinstall. I don't know if there is the "repair" option that would leave my other files and just replace windows OS. Do you think this situation is in the OS and a "repair" gets deep enough? Thanks
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI