Posted 01 January 2008 - 02:40 AM
My Windows XP SP2 laptop has been infected with a trojan and I'm using my desktop to post this right now. My laptop stops responding after 30 seconds into startup and when I try to run HijackThis it gets locked up after 30 seconds as well. Basically I think it locks up every application that I run. I can't even update my numerous virus and spyware scanners and I can't install any new scanners.
It all started when I downloaded a torrent for the movie Hitman. When I tried to play the exactly 700mb .avi file, none of my players (Windows Media, DivX, Media Player Classic etc.) could recognize the file. However the torrent contained a readme that said the movies were encoded with a new codec and I had to visit this website to download either 3wPlayer or Divocodec in order to play the movie. I should have done a search on these two suspicious programs first, but it was too late. I installed Divocodec first, but I could not play the movie. Then the website told me to download 3wPlayer if Divocodec did not work, so I installed it as well. When I still could not play the movie, it was only then that I realized these two programs were malware when I searched their names on Yahoo!.
I immediately did a scan using my five or six spyware scanners at once, and Spybot S&D picked up 3wPlayer but was unable to remove it without a reboot. I think it picked up Divocodec as well. After that I went on holiday for a week and when I came back that was when the damage really started. I started getting CiD help ad popups at regular intervals even when I was using Firefox instead of IE. I updated all my spyware scanners and did another scan and removed some stuff, after which the CiD help popups seem to have disappeared.
However, that was not the end of the trouble. My laptop started locking up at certain intervals while I was running some programs, and would start responding again a few minutes later. I ran all my spyware scanners again and picked up more unwanted stuff, but this time not as many as the last scan. Therefore I did not think much about it and continued using my laptop, until my whole laptop suddenly stopped responding and every program I tried to run got locked up.
That was when I cut off the internet connection and did a search on how to remove 3wPlayer manually. I found that some of the listed files were already deleted, so I deleted the rest of the files and the registry keys in the command prompt of safe mode. I also searched for any keys with '3wplayer' in their name and deleted them.
It still did not solve the problem. I suspected Adware.Lop next, as Symantec.com said that 3wPlayer may download the adware. I did not try to remove the files or registry keys as they were randomly named and were too hard to find. However, in safe mode I did find some strangely named folders in C:\Program Files, C:\Documents and Settings\Administrator\Application Data and C:\Documents , in particular one folder called 'WEB DUMP CAMP' in Program Files with a couple of adware programs inside. I deleted the folder, cleaned up any other suspicious files I could find and rebooted my laptop in normal mode. Still no improvement, every program I tried to run locked up and only resumed about 10 minutes later. When I tried using these programs they locked up again. HijackThis locked up after about 10 seconds of scanning.
After that I suspected one of the Swizzor Trojan variants, in particular Swizzor.FG, which was the most recent version (27 Dec 2007), or Trojan.Win32.Obfuscated.en. This time I downloaded SysInternals Autoruns and it listed many suspicious drivers that said 'file not found'. I deleted all the drivers and their associated registry keys, except for one whose name started with an 'a' followed by random numbers and letters. I was able to delete the registry key but not the driver, which gave an error message saying 'Error deleting start entry: The specified device does not exist as an installed service'. On the next reboot a new driver with the same naming method appeared. The lastest example is 'aab8tyl3'. My guess is that this is the root cause of all the trouble and it is the last thing I have to remove.
I have disabled System Restore ever since I discovered that manually removing 3wPlayer did not solve the problem. Currently I have Avast! Antivirus, Avira Antivirus, AVG Antivirus, AVG Antispyware, PC Tools Antivirus, Lavasoft Ad-Aware, Spybot S&D, Super Antispyware and Spyware Terminator. It is hard to get a HijackThis log and takes time but if anyone needs it I will post it in my second post.