My Windows XP System from Dell picked up a program that Windows dosen't recognize in WIDOWS\system32\wowfx.dll. everytime the computer is started i think the windows firewall throws up a warning popup that it does not recognise this program and an OK button. If you hit the button another one comes up with a different program name in the title bar. I assume it is trying to call the program. Each time I hit the button there was a little more facility with the operating system. I was afraid if I OKed enough popups wowfx.dll would eventually have assembled all the components it wanted and do its damage.
I found wowfx.dll under C:\WINDOW\system32 and renamed it. The popups no longer came up and the system completely booted with a few eratic touches like the monitor flashing multiple colors instead of the screensaver.
Then I followed all of the steps in the **IMPORTANT*** before posting -posting- The ATF Cleaner Progam, Then the the Kaspersky online Scan, then ran the Windows Update. The first thing downloaded was an anti malware program and then updated to Service Pack 3.
Finally the HiJackThis was run and its report follows:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:19:17 PM, on 12/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Just thought I'd mention that the Kaspersky online Scan download insisted that Java 1.5 be downloaded from Sun Microsystems and Sun Microsytems insisted on downloading a Yahoo tool bar to the firefox Browser right on top of the Google Tool bar.
Anyway hear is the Kaspesky Scan Report:
Wednesday, December 24, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, December 24, 2008 19:42:43
Records in database: 1510545
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan statistics
Files scanned 100176
Threat name 8
Infected objects 15
Suspicious objects 0
Duration of the scan 02:20:49
File name Threat name Threats count
C:\Documents and Settings\Barbara Billotte\Application Data\antivirus.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o 1
C:\Documents and Settings\Barbara Billotte\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmsecman.jar-69ee0e0e-57ae931c.zip Infected: Trojan-Downloader.Java.Agent.f 1
C:\Documents and Settings\Barbara Billotte\Application Data\sysdoctor.exe Infected: not-a-virus:Downloader.Win32.WinFixer.ar 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\mmz28.tmp\KillTi.exe Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\mmz31.tmp\KillTi.exe Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\mmz47.tmp\KillTi.exe Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\mmz63.tmp\KillTi.exe Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\mmz79.tmp\KillTi.exe Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\mmzA4.tmp\KillTi.exe Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\wJQs.exe Infected: Trojan.Win32.Pakes.llo 1
C:\Documents and Settings\Barbara Billotte\Local Settings\Temp\xpre.exe Infected: Trojan-Downloader.Win32.VB.axa 1
C:\Documents and Settings\Ethan Billotte.THESOURCE\Application Data\drvcleaner.exe Infected: not-a-virus:Downloader.Win32.WinFixer.m 1
C:\Documents and Settings\Terrence Billotte\Application Data\privprotect.exe Infected: not-a-virus:Downloader.Win32.WinFixer.y 1
C:\Program Files\MUSICMATCH\Common\ComponentMgr\HoldingArea\WebSys2\WebSys.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\WebSys\offline.mmz Infected: not-a-virus:RiskTool.Win32.Deleter.f 1
The selected area was scanned.
Thank you for any help. We are afraid to use the computer until its clean. We were able to back up a lot of stuff on DVD,s but....