Google Answers Logo
View Question
 
Q: WinWildApp.exe virus/worm info? ( Answered 5 out of 5 stars,   1 Comment )
Question  
Subject: WinWildApp.exe virus/worm info?
Category: Computers > Security
Asked by: mineral-ga
List Price: $10.00
Posted: 09 Apr 2004 07:45 PDT
Expires: 09 May 2004 07:45 PDT
Question ID: 327681
Three new programs appeared in my running processes list suddenly:
eqQIL.exe, AHb.exe, and VeUshy.exe. They all appear to try to
periodically contact the internet outbound but are blocked by my (Zone
Labs) firewall.  THe firewall log shows that another new
WinWildApp.exe ran once, just before the three new programs started
trying to run.  I fear this is a virus or worm of some sort, but my
antivirus (McAffee) doesn't find anything.  Google shows no
information for these four named programs, so I don't know what they
might be. Can anyone tell me what
might be going on, and how to permanently delete these programs?
Answer  
Subject: Re: WinWildApp.exe virus/worm info?
Answered By: livioflores-ga on 09 Apr 2004 16:44 PDT
Rated:5 out of 5 stars
 
Hi mineral!!

Despite the fact that we cannot find information for these four named
programs, we can easily conclude that they are some kind of viruses,
worms, trojans or another type of badware. I will provide you some
tools and guidance that , I hope, let you to remove them from your
computer.

Note that the lastest viruses commonly use random generated names to
infect the computers, this makes difficult to find info about what
specific virus is infecting the computer.

The things that you must do are:
1.Disable System Restore if your operating system is Windows Me or XP.
For reference see:
"Disabling or enabling Windows Me System Restore"
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDocument&src=sec_doc_nam

"Disabling or enabling Windows XP System Restore"
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam


2.Use the task manager (run it by pressing simultaneously the keys
Ctrl+Alt+Del) to stop the four processes. If you are using Windows
2000 or XP look for them in the processes tab. Just do a right click
on the process that you want to end, and then select End Process.
If you want to end a process and all processes directly or indirectly
related to it, right-click the process that you want to end, and then
click End Process Tree. But this must be used only as a last resort,
for example if the processes automatically restart after you stop
them.

3.Connect to Internet and perform an online scan. Try with one of the
following free services:

"Panda ActiveScan - Free online scanner":
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

"BitDefender ScanOnline":
http://www.bitdefender.com/scan/license.php


4.Perform an online trojan scan using the following service:

"GFI - Free online Trojan scanner", an online tool dedicated to detect
trojans in your computer:
http://www.trojanscan.com/

Try also an online scan with the PestPatrol service:
"PestPAtrol's free online spyware scanner":
http://www.pestscan.com/ScanOrTrial.asp


5.If an infection is detected on the scans follow the instructions
given to remove the pests.

NOTE I: If the virus and trojan scan does not detect any infection (I
don't believe that this happens but...) and you still want to delete
this files you can do it in the common way, searching for them in
their folder location and deleting them as you can do with any other
file.


6.Scan the registry to remove all the remainder traces of the pest
from it. Use the following software to do this:
"Regcleaner": (freeware)
http://www.cybertechhelp.com/download.php?RegCleaner.exe

For documentation about this program and for guidelines about its
usage please visit:
"RegCleaner Readme":
http://freeware4u.com/shots/regcleaner/readme.htm

"Spyware Removal Guide":
http://www.clarkson.edu/~leiderjd/tutorial/spyware/spyware-4.htm


7.Use the "Microsoft System Configuration Utility" to delete the
pestware from the Start Up list if it is still on it. To see how to
use this tool please visit the following page:
"How to Use MSCONFIG":
http://netsquirrel.com/msconfig/


NOTE II: It was a good idea to install an antispyware and perform a
scan with it, the better two are:
"Ad-aware" from Lavasoft: (freeware)
http://lavasoft.element5.com/software/adaware/

"SpyBot Search and Destroy": (freeware)
http://www.safer-networking.org/index.php?page=spybotsd


This procedure will remove this four programs from your computer, but
if this does not work please let me know using the clarification
feature, telling me all the relevant details of what happened in this
attempt. I will gladly give you all the assistance needed to complete
the removing of these pests, so please don't consider this answer
ended until the problem is solved.

Best regards.
livioflores-ga
mineral-ga rated this answer:5 out of 5 stars and gave an additional tip of: $2.00
Very complete and accurate. Thanks!

Comments  
Subject: Re: WinWildApp.exe virus/worm info?
From: zavy-ga on 12 Apr 2004 03:05 PDT
 
Hi !
I had a similar problem.
For me, the WinWildApp.exe created in my temporary folder when I
started windows media player.I checked it with NAV, but no virus/worm
found.
Then I found something at symantec webpage, maybe it can help you:

http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.gaobot.ef.html

Bye

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy