Avast WEBforum

Other => Viruses and worms => Topic started by: carlosg on July 10, 2013, 06:14:24 PM

Title: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 06:14:24 PM
Hey I've found that my computer has a trojan Dwm.exe, read about it and its a bitcoin miner. It is located here C\Users\Appdata\Local\Temp\iswizard

Ran up malwarebytes and it found these files: iswizard.7z and wuaudit.exe

Tried to delete it with more than one anti virus and couldn't manage delete or even to spot it out. Used malwarebytes as well, spotted it but couldnt remove it(even if you remove it manualy, comes back right after)

What can I do to get rid of this annoying trojan?
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: true indian on July 10, 2013, 06:18:17 PM
Clear Cache/Temp Files
Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.  Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: essexboy on July 10, 2013, 06:42:16 PM
Sometimes that temp folder protects itself, if TFC does not work then run OTL (details here http://forum.avast.com/index.php?topic=53253.0 )
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 07:10:25 PM
Thank you both, going to try it now
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 07:50:05 PM
TFC didn't work. Used OTL and theres the log.
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: essexboy on July 10, 2013, 08:09:53 PM
Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=adk&from=adk&uid=HitachiXHTS547550A9E384_120912J2360051FVD2UCX&ts=1372647993
IE:64bit: - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=adk&from=adk&uid=HitachiXHTS547550A9E384_120912J2360051FVD2UCX&ts=0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=adk&from=adk&uid=HitachiXHTS547550A9E384_120912J2360051FVD2UCX&ts=1372647993
IE - HKLM\..\SearchScopes,DefaultScope = {33BB0A4E-99AF-4226-BDF6-49120163DE86}
IE - HKLM\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=adk&from=adk&uid=HitachiXHTS547550A9E384_120912J2360051FVD2UCX&ts=0
IE - HKU\S-1-5-21-1707020488-421807252-2630900403-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.qvo6.com/?utm_source=b&utm_medium=adk&from=adk&uid=HitachiXHTS547550A9E384_120912J2360051FVD2UCX&ts=1372647993
IE - HKU\S-1-5-21-1707020488-421807252-2630900403-1001\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.qvo6.com/web/?utm_source=b&utm_medium=adk&from=adk&uid=HitachiXHTS547550A9E384_120912J2360051FVD2UCX&ts=0
O4 - HKU\S-1-5-21-1707020488-421807252-2630900403-1001..\Run: [tsiVideo] C:\Users\Abel\AppData\Local\Temp\tsiVi032.dll ()


:Files
C:\Users\Appdata\Local\Temp\iswizard

:Commands
[resethosts]
[emptytemp]
[Reboot]
THEN

Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 08:28:44 PM
OTL log
Going to run JRT now
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 08:36:17 PM
JRT log
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: essexboy on July 10, 2013, 08:49:23 PM
How is the computer now ?
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 08:51:14 PM
Should I run something to check it? The boot time is less than 1min and was around 2min and I barely install stuff, I usualy look on what I am doing but I can't guess where all that crap came from.
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: essexboy on July 10, 2013, 08:54:27 PM
QV06 is a bit of a pain and does come bundled with "free" programmes .. See here http://blog.avast.com/

The main thing is Chrome could you see if QV06 is still there
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 09:02:47 PM
It isnt, not even on ie either. Thanks a lot for the help, without you guys I couldn't even get rid of this crap. Should I keep any of the programs that I downloaded so I can keep an eye on the system? Because some anti virus don't detect some stuff and thats kinda scary..
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 10, 2013, 09:40:11 PM
Runned malwarebytes and it found 2 items, exactly the same ones that found before :(

files: iswizard.7z and wuaudit.exe

folder: C\Users\Appdata\Local\Temp\iswizard
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: essexboy on July 10, 2013, 11:15:45 PM
OK run this OTL fix and post the log that appears after reboot please

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:Files
C:\Users\Appdata\Local\Temp\iswizard

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 11, 2013, 03:09:05 AM
OTL log
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: carlosg on July 11, 2013, 05:40:41 AM
Pretty sure its fine by now, since malwarebytes can no longer find the files.
Thanks a lot for the help
Title: Re: Dwm.exe, bitcoin miner trojan
Post by: essexboy on July 11, 2013, 03:45:06 PM
If you are happy then run OTL and press the cleanup button :)