also @ TechSpot: Top PC Games for this Holiday Season and Beyond
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Experience of Infostealer.Gampass and Infostealer.Perfwo

Closed Thread
Bookmark Thread Tools
  #1  
Old 05-06-2007
Newcomer, in training
 
Member since: May 2007, 1 posts
Experience of Infostealer.Gampass and Infostealer.Perfwo

My pc was visited by Infostealer.Gampass and Infostealer.Perfwo and it was my most pain experience in removing it. I lost 97 exe files which were infected. I would like to share here and hope to help those panic victims.

Folder created by them:
%program Files%Common Files\Microsoft Shared\Web Folders\

Files created:
%windir%\svchost.exe
%program files%\Common Files\Microsoft Shared\Web Folders\MSOSV.EXE
%program files%\Common Files\Microsoft Shared\Web Folders\MSOSVEXT.EXE

Files created after virus activated:
%program files%\Common Files\Microsoft Shared\Web Folders\TempA.exe
...
%program files%\Common Files\Microsoft Shared\Web Folders\TempM.exe
%windir%\Sysfy3\svchost.exe
%windir%\Sysfy3\Ghook.dll

These 2 trojan horse visited me with 4 more viruses, which are
- shualai.exe
- nwizhx2.exe
- nwizAsktao.exe
- cmdbcs.exe

The av (antivirus) is able to deleted the creation of Temp*.exe, svchost.exe and Ghook.dll. However, the other files are able to run at background.

Removal steps:
1. Stop the task of shualai.exe

2. Delete the following files:
- shualai.exe and shualai.dll
- nwizhx2.exe and nwizhx2.dll
- nwizAsktao.exe and nwizAsktao.dll
- cmdbcs.exe and cmdbcs.dll
(note that dll files located in %windir%\windows\system32 while exe files located in %windir%\windows\)

3. Run regedit, search the following registry and remove them.
- shualai (2 entries)
- nwizhx2 (1 entry)
- nwizAsktao (1 enty)
- cmdbcs (2 entries)

4. Remove
%windir%\svchost.exe
%program files%\Common Files\Microsoft Shared\Web Folders\MSOSV.EXE
%program files%\Common Files\Microsoft Shared\Web Folders\MSOSVEXT.EXE
%program files%\Common Files\Microsoft Shared\Web Folders\Temp(x).exe

5. Reboot

If the steps does not solve the problem, format ALL the hardisk logical partition at once.

Hope this helps.
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Help with virus please!! Infostealer.gampass Virus & Malware removal 9 04-04-2007 04:40 PM
Infostealer.gampass {VERY NERVOUS} please help Virus & Malware removal 28 04-03-2007 05:51 PM
Infostealer.Gampass Remover General Hardware 4 03-28-2007 05:55 PM
infostealer.gampass Virus & Malware removal 1 03-28-2007 03:58 AM
Infostealer.Gampass Removal Virus & Malware removal 7 03-11-2007 03:41 AM


All times are GMT -4. The time now is 10:44 PM.