Unsolved

This post is more than 5 years old

1 Message

4999

November 5th, 2005 01:00

cnml.exe, winik.sys

Hello!  Does anyone know what these adware files are?  cnml.exe and winik.sys?  My computer is running very slowly, my anti-virus finds them,but when I try to delete them it says they are in use.  When I try to rename them, it says that they are write-protected.  Is there any way to get rid of them?  I would be extremely grateful for any help.  Thank you. 

2 Intern

 • 

623 Posts

November 5th, 2005 07:00

Try avast antivirus it is a good program and it is free. I am using it now. Click here Free avast! 4 Home Edition   Click Here and read the reviews Avast Home Edition, a popular choice for home computers, offers free virus protection, an intuitive interface, and regular updates. This is a solid and well-respected program to keep your computer virus-free. Click Here Awards

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

November 5th, 2005 11:00

i did a web-search and located the following info.   I cannot personally vouch for the safety of any removal instructions these pages may indicate... you should READ them, for informational purposes only... and then, I would suggest you post your HiJackThis log in the HJT forum.
 
cnml.exe :
 
winik.sys (also known as Rootkit.Win32.Agent.Q by Kaspersky)
 
                               *******************
 
 
Download the latest version of HJT(hijackthis) (version 1.99.1) from

http://majorgeeks.com/download3155.html

you must create a separate folder and place it there.... people commonly use C:\HJT.   Note:  Please do *NOT* use a TEMP (temporary) folder, *NOR* your DESKTOP, as HJT will be generating log files and backup files in the folder from which it is run... you risk accidentally losing these if you use a TEMP folder, and you will generate extreme clutter if you use your DESKTOP.

The file above comes as a compressed .ZIP file... you have to UNzip it (hopefully, you have an UNzip utility built into your Windows Explorer.   If for any reason, you're unable to UNzip it, you can download the already-unzipped .EXE file from http://downloads.malwareremoval.com/HijackThis.exe )

After Unzipping, double click on HiJackThis.EXE

Click on  Do a System Scan and Save a LogFile

This will automatically open NotePad

Copy the entire file from NotePad:  EDIT/SelectAll, EDIT/Copy

Then go to the new forum dedicated for HiJack This logs (**NOT** back here), and  PASTE the results there:

http://forums.us.dell.com/supportforums/board?board.id=si_hijack

Be sure to include a detailed description of any problems/errors/warnings you are encountering.

Hopefully, one of the HJT experts will get to it as quickly as possible.

 

WARNING:  HiJack This is a VERY POWERFUL tool.  Do *NOT* do anything else (in particular, do NOT use it to delete any entries) until you are advised to do so!!   Improper use of this tool can severely damage your system.
 
 
Supplemental note:  The procedure as worded above has been carefully edited over time, so as to expedite the process of helping people.   Nevertheless, it seems that many individuals try to be "creative", and make some variations.  It really would be to your benefit if you follow these directions EXACTLY as stated... because certain changes on your part can result in slowing-down the help process. 
Specifically, the following are 3 very common BAD deviations which will cause delays:
a)  BAD:  using an older/outdated version of HiJackThis...
The experts only work with the current version.   So if you make a post with an older version, you'll simply be advised to get the latest version, re-run it, and re-post your log.
b) BADusing a TEMP directory or your DESKTOP for HJT....
Some experts may insist you move HJT before they'll begin working with you.   Others will start the repair process, advising you to move HJT as one of the very first steps.   Failure to do so can result in losing potentially critical information.   So please,  just use the suggested  C:\HJT  directory, rather than try to be creative.
c) BAD:  posting your log in the wrong forum...
if you post your log back here, in the Virus/SpyWare forum, it will "sit idly", either until the forum moderator gets around to move it for you... or until you decide to repost your log...  in the HiJackThis forum.

2 Intern

 • 

247 Posts

November 7th, 2005 12:00

You may use this link/tool to remove the WinKRootKit (WinIK.sys) trojan and its protected files.
 
If you run the tool, please post your WinKRootKit.txt file log (located on the desktop when it is done working).
 
For any other problems, please continue to post with updates.
 
 

November 18th, 2005 05:00

I used your removal tool and it seemed to get rid of winik (thanks very much), but do I have to go through a long process with cnml or is that now gone too? I'm not sure if they are interconnected. I found several pages that seem to address the cnml issue but they are so long and laborious that even setting up my recovery console (which is the first step) is taking forever, because my CD is XP pack 1 and I have pack 2 installed. I just want to know if I am wasting my time.

Here are the instructions I am following:

http://users.dcr.net/~w-clayton/Crapware%20Generalized%20Solutions/Solutions.htm

The problems the spyware may or may not have caused have to do with installing and/or using photo editing software, a registry error with dell image expert and a library error while trying to install Arcsoft Photoimpression and Smartpanel on my Epson CX6600 printer.

Thanks for your help.

2 Intern

 • 

247 Posts

November 18th, 2005 16:00

If WinIK.sys is installed and running the tool I posted will remove the driver and the files in the random folder, including cnml.exe (Part of Adware-CommonName). Post the WinKRootKit.TXT file on your desktop and I can see if there are any notes in the log file showing something didn't work.
 
A virus or adware/spyware scan should also detect and clean up anything left behind dealing with this common malware.

Message Edited by secured2k on 11-18-2005 01:07 PM

November 19th, 2005 04:00

11/17/2005, 3:15:58 - Starting Process
11/17/2005, 3:16:00 - Found the WinKRootKit Service. Attempting to remove...
11/17/2005, 3:16:00 - Located the following:
11/17/2005, 3:16:00 - Protected Executable: C:\Program Files\swvtsrwp\cUgFDgBL.exe
11/17/2005, 3:16:00 - Protected Profile Data: C:\Program Files\swvtsrwp\profile.dat
11/17/2005, 3:16:00 - Protected Kernel Rootkit Driver: C:\WINDOWS\System32\Drivers\WinIK.sys
11/17/2005, 3:16:00 - Attempting to kill cUgFDgBL.exe and it's decendants.
11/17/2005, 3:16:02 - Unable to kill process cUgFDgBL.exe:
11/17/2005, 3:16:02 - Process does not exist.
11/17/2005, 3:16:02 - Removing Rootkit Protection.
11/17/2005, 3:16:03 - Deleting Protected File Data.
11/17/2005, 3:16:03 - Removing Registry settings in HKLM\SOFTWARE\swvtsrwp
11/17/2005, 3:16:03 - Removing Registry settings in HKCU\SOFTWARE\swvtsrwp
11/17/2005, 3:16:04 - Setting up final cleaning instruction on next reboot.
11/17/2005, 3:16:04 - Phase 1 of 2 complete. Restarting...

11/17/2005, 3:19:17 - We're back from restart. Starting Phase 2 of 2.
11/17/2005, 3:19:17 - Deleting WinKRootKit Service
11/17/2005, 3:19:17 - Deleting WinKRootKit Registry Settings
11/17/2005, 3:19:18 - Deleting WinKRootKit Kernel Driver.
11/17/2005, 3:19:18 - Phase 2 of 2 complete. We're all done here. Restarting...

11/17/2005, 12:25:59 - Starting Process
11/17/2005, 12:25:59 - Could not detect the service installed. Nothing else to do!


Adaware didn't find anything, but during its search, both times, my Fprot Anti-virus came with the same two errors that looked like this:

1\ElmoOxygen\LOCALS 1\Temp\AAWTMP\C115860062\217F13\Matrix.class
1\ElmoOxygen\LOCALS 1\Temp\AAWTMP\C115860062\217F13\Parser Class


The numbers were slightly different the second time, but I don't know if it is related to cnml.

2 Intern

 • 

247 Posts

November 19th, 2005 04:00

There should be no more references to WinIK.SYS and CNML.EXE. The files you mentioned are located in your temporary Internet Files and can be cleaned out by deleting your Temporary Internet Files.
F-Prot (and many AntiViruses) will not clean a file that is inside of a compressed archive or one that is only temporarily extracted. The .class files are Java files. Make sure you have the latest Java VM (if you need Java) from www.java.com.
 

November 19th, 2005 05:00

Do you know what might be causing such a strange problem with photo software then? I mentioned the problem in an earlier post and have tried many things to try to fix it including getting direct files from the software manufacturers. Eventually, it was decided that it was an XP issue. Dell says it is Microsoft's problem, Microsoft says it is Dell's problem since they installed the software. Regardless, I don't have any idea what to do and if it will spread to other types of software.


"The problems the spyware may or may not have caused have to do with installing and/or using photo editing software, a registry error with dell image expert and a library error while trying to install Arcsoft Photoimpression and Smartpanel on my Epson CX6600 printer."
No Events found!

Top