This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] wowfx.dll problem.

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, A while ago my anti-virus was picking up the wowfx.dll trojan problem. Everytime I tried to remove it though it wouldn't so I just left it however earlier on today my laptop went a bit funny and now no matter what I click on I get the "bad image…wowfx.dll doesn't exist" or whatever it is. I searched about on the internet and saw that most people had ran hijackthis and posted their logs and people had responded accordingly. Therefore I was wondering if this is what I should do, I was a bit wary though of course as if you don't know what your doing it can mess up your computer. Help would therefore be greatly appreciated as to what to do to remove and or solve the problem. Thanks.
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Hi,

Thanks for replying with your help. Below is all the information that was produced in the C:\ComboFix.txt log. The problems I was having before seem to be resolved now, is that the problem solved or is there still more for me to do?

Regards,

Steven

ComboFix 08-10-16.08 - Steven 2008-10-17 14:33:07.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.161 [GMT 1:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Guest\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\crock+mock.config
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\wowfx.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_DNLSVC
——-\Legacy_MSDIRECT
——-\Service_dnlsvc
——-\Service_msdirect


((((((((((((((((((((((((( Files Created from 2008-09-17 to 2008-10-17 )))))))))))))))))))))))))))))))
.

2008-10-16 23:26 . 2007-12-24 17:37 138,384 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-10-16 23:24 . 2008-10-16 23:29 d——– C:\Documents and Settings\Steven\Application Data\HouseCall 6.6
2008-09-19 19:13 . 2008-09-19 19:13 d——– C:\Program Files\Rainlendar2
2008-09-19 19:13 . 2008-10-17 14:44 d——– C:\Documents and Settings\Steven\.rainlendar2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-17 13:15 ——— d—–w C:\Documents and Settings\Steven\Application Data\MailWasherPro
2008-09-19 21:12 ——— d—–w C:\Program Files\Rainlendar
2008-09-19 21:11 ——— d—–w C:\Program Files\Webcam and Screen Recorder
2008-09-15 11:57 1,846,016 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w C:\WINDOWS\system32\dllcache\win32k.sys
2008-08-31 23:04 97,928 —-a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-31 22:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-28 10:04 333,056 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-28 10:04 333,056 ——w C:\WINDOWS\system32\dllcache\srv.sys
2008-08-25 00:34 ——— d—–w C:\Program Files\IKEA HomePlanner
2008-08-25 00:34 ——— d—–w C:\Program Files\DivX
2008-08-24 23:40 ——— d—–w C:\Program Files\V300-V303-V400 USB-Handset Manager
2008-08-24 23:40 ——— d—–w C:\Program Files\pspvideo9
2008-08-24 23:40 ——— d—–w C:\Program Files\NetWaiting
2008-08-24 23:40 ——— d—–w C:\Program Files\Modem Helper
2008-08-24 23:40 ——— d—–w C:\Program Files\Microsoft Works
2008-08-24 23:40 ——— d—–w C:\Program Files\AOL 9.0
2008-08-24 23:01 76,040 —-a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-24 23:01 10,520 —-a-w C:\WINDOWS\system32\avgrsstx.dll
2008-08-24 23:01 ——— d—–w C:\Program Files\AVG
2008-08-24 22:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-24 22:22 ——— d—–w C:\Program Files\Lavasoft
2008-08-24 22:21 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-19 09:30 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
2008-08-14 10:00 2,180,352 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 10:00 2,180,352 ——w C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-14 09:58 2,136,064 ——w C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-08-14 09:51 138,368 ——w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:22 2,057,728 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 09:22 2,057,728 ——w C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-08-14 09:22 2,015,744 ——w C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 21:10 94,920 —-a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 53,448 —-a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 21:10 45,768 —-a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:10 36,552 —-a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 563,912 —-a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 325,832 —-a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 205,000 —-a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:09 1,811,656 —-a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [2008-08-22 4067328]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2006-01-11 212992]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-12 180269]
"ISUSPM Startup"="c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-07-27 221184]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-08-15 271672]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-29 1234712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]

C:\Documents and Settings\Steven\Start Menu\Programs\Startup\
wkcalrem.LNK - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-08-24 24651]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AOL 9.0 Tray Icon.lnk - C:\Program Files\AOL 9.0\aoltray.exe [2005-06-28 156784]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-06-28 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23690:TCP"= 23690:TCP:BitComet 23690 TCP
"23690:UDP"= 23690:UDP:BitComet 23690 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-01 97928]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-01 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-25 76040]
S2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-01 875288]
S3 MaRdPnp;MaRdPnp;C:\WINDOWS\system32\DRIVERS\MaRdP2K.sys [2004-09-13 49611]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000]
.
Contents of the 'Scheduled Tasks' folder

2008-07-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]

2008-10-10 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (DB4T9Q61-Steven).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe [2005-07-08 19:18]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-CDriver - c:\google.com\svchost.exe
HKCU-Run-DDriver - c:\google.com\svchost.exe
HKCU-Run-alpha - c:\google.com\svchost.exe
HKCU-Run-beta - c:\google.com\svchost.exe
HKCU-Run-gamma - c:\google.com\svchost.exe
HKCU-Run-DriverLoad - (no file)
HKCU-Run-DriverCheck - (no file)
HKCU-Run-SystemDriverLoad - (no file)
HKCU-Run-SystemDriver - (no file)
HKCU-Run-FDriver - (no file)
HKCU-Run-ADriver - (no file)


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.dell.co.uk/myway
R0 -: HKLM-Main,Start Page = hxxp://www.dell.co.uk/myway
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O17 -: HKLM\CCS\Interface\{A9DDFA6C-814E-4650-B35B-BA292C8624E4}: NameServer = 78.143.192.10,78.143.192.20

O16 -: {96816368-C1E3-414D-A193-63C3CC921990} - hxxp://jacobsbabtie-kincardine.remotemanager.co.uk/common/activex/MJPEGRender.ocx
C:\WINDOWS\Downloaded Program Files\MJPEGRender.ocx
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 14:40:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\wltrysvc.exe
C:\WINDOWS\system32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\VSO\McShield.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\PROGRA~1\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\PROGRA~1\McAfee.com\VSO\McVSEscn.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\McAfee.com\VSO\mcvsftsn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-10-17 14:54:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-17 13:54:35

Pre-Run: 1,302,278,144 bytes free
Post-Run: 1,613,475,840 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

211 — E O F — 2008-10-16 09:35:25
Hello

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.



CLICK HERE to download the HijackThis Installer:
  • Save HJTInstall.exe to your desktop.
  • Double-click on HJTInstall.exe to run the program.
  • By default it will install to C:\Program Files\Trend Micro\HijackThis.
  • Accept the license agreement by clicking the "I Accept" button.
  • Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
  • Click "Save log" to save the log file and then the log will open in Notepad.
  • Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
  • Come back here to this thread and paste the log in your next reply.
  • Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI