Here's what I think must go:
Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:56:56 PM, on 13-Aug-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\system32\[COLOR="Red"]kek.exe[/COLOR]
C:\WINDOWS\system32\[COLOR="Red"]mpxa.exe[/COLOR]
O2 - BHO: (no name) - {7ECF8EC7-A121-416E-998B-C3F484F91DF9} - C:\WINDOWS\system32\[COLOR="Red"]jkkKccby.dll (file missing)[/COLOR]
O2 - BHO: {ddacec84-3e24-e5aa-0644-2ffb767d9248} - {8429d767-bff2-4460-aa5e-42e348cecadd} - C:\WINDOWS\system32\[COLOR="Red"]wgxusw.dll (file missing)[/COLOR]
O2 - BHO: (no name) - {FFFB03AD-A461-4B99-9A23-D3B127D7C995} - C:\WINDOWS\system32\[COLOR="Red"]nnnmnOgE.dll (file missing)[/COLOR]
O4 - HKLM\..\Run: [295f164f] rundll32.exe "C:\WINDOWS\system32\[COLOR="Red"]idrqqvwe.dll",b[/COLOR]
O4 - HKLM\..\Run: [BM2a6c25d3] Rundll32.exe "C:\WINDOWS\system32\[COLOR="Red"]vbiebwtg.dll",s[/COLOR]
O4 - HKCU\..\Run: [mpt] c:\WINDOWS\system32\[COLOR="Red"]mpt.exe[/COLOR]
O4 - HKCU\..\Run: [kek] c:\WINDOWS\system32\[COLOR="Red"]kek.exe[/COLOR]
O4 - Global Startup: DriveGuard.lnk = C:\Program Files\[COLOR="Red"]WinDriveGuard[/COLOR]\DriveGuard.exe
O20 - Winlogon Notify: [COLOR="Red"]nnnmnOgE - nnnmnOgE.dll (file missing)[/COLOR]
O20 - Winlogon Notify: winwil32 - C:\WINDOWS\SYSTEM32\[COLOR="Red"]winwil32.dll[/COLOR]
It's best to disconnect from the internet till you get rid of this malware and exit all programs(even from system tray), close all open windows, except for your security software. But read through this, download the files required(or not) then disconnect from the net.
1. Turn off System Restore. My Computer > right click Properties > System Restore tab > check Turn off system restore on all drives > OK > answer Yes to the prompt.
2. In the task manager(Ctrl + Shift + Esc) under the processes tab, right click and end the processes kek.exe and mpxa.exe
3. Delete the files kek.exe and mpxa.exe from C:\Windows\system32 folder. You may have to do it in safe mode.
4. I'm unsure of mpt.exe. To be on the safer side, quarantine it in AVG but don't remove its entry from HJT. If quarantining it doesn't cause a problem, you can always remove its startup entry from HJT later. If you know what it is, then leave it be.
5. In task manager, if it's present, end the DriveGuard.exe process and uninstall WinDriveGuard from Control Panel > Add/Remove Programs(I doubt its that easy) so just delete the entire WinDriveGuard folder
after ending the DriveGuard.exe process or delete the folder in safe mode.
6. For winwil32.dll, if you can't delete it in safe mode, you may have to use
Process Explorer . This winwil32.dll may be what's causing the comp to restart instead of shutdown.
How to:
a. Start Process Explorer
b. In the upper pane, double click winlogon.exe to bring up its properties
c. In properties go to Threads tab, locate(select) every instance of winwil32.dll and hit the Kill button, click OK.
d. Do the same for finding(and killing) winwil32.dll in explorer.exe process and then close process explorer.
e. Try deleting winwil32.dll now.
7. Empty all the temporary folders, use
CCleaner if you need to.
8. Do another HJT scan, and Select(place a tick mark) > Fix Selected for the following entries:
Code:
O2 - BHO: (no name) - {7ECF8EC7-A121-416E-998B-C3F484F91DF9} - C:\WINDOWS\system32\jkkKccby.dll (file missing)
O2 - BHO: {ddacec84-3e24-e5aa-0644-2ffb767d9248} - {8429d767-bff2-4460-aa5e-42e348cecadd} - C:\WINDOWS\system32\wgxusw.dll (file missing)
O2 - BHO: (no name) - {FFFB03AD-A461-4B99-9A23-D3B127D7C995} - C:\WINDOWS\system32\nnnmnOgE.dll (file missing)
O4 - HKLM\..\Run: [295f164f] rundll32.exe "C:\WINDOWS\system32\idrqqvwe.dll",b
O4 - HKLM\..\Run: [BM2a6c25d3] Rundll32.exe "C:\WINDOWS\system32\vbiebwtg.dll",s
O4 - HKCU\..\Run: [kek] c:\WINDOWS\system32\kek.exe
O4 - Global Startup: DriveGuard.lnk = C:\Program Files\WinDriveGuard\DriveGuard.exe
O20 - Winlogon Notify: nnnmnOgE - nnnmnOgE.dll (file missing)
O20 - Winlogon Notify: winwil32 - C:\WINDOWS\SYSTEM32\winwil32.dll
9. Copy and paste the following into notepad and save it as "WLN.reg" with the quotes so that it saves with .reg extension and not the default .txt extension of notepad. Double click the file and answer Yes to the prompt to merge it into the registry.
Code:
Windows Registry Editor Version 5.00
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnmnOgE]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32]
Reboot and post back how it goes. In 2-3 hours a lot more members on this forum will waking up, so expect more suggestions then.