winupdmgr.exe

Harmful - EXE

 winupdmgr.exe is a filname that is found in several virus sample analysis reports. It is a filename that mimics to resemble a genuine windows file/process called "wupdmgr.exe"

wupdmgr.exeThe locations where the genuine file is found is the system folder and in dllcache. By Default system folder would be C:\Windows\System32 in XP and Higher version of windows. 

Whereas the virus file was detected in %Windir% that is C:\Windows folder. As this file is also made to run each time the computer starts, you should be able to see winupdmgr.exe running in the Task Manager, you should End the process if you find it in the Task Manager

The analysis reports suggest that it is a Trojan Horse which can further download more harmful files on your computer. 

So, if you find this process winupdmgr.exe in the task manager, use the windows search utility to search on your hard disk for this file and then delete it if found. I have written each step that you can follow in order to remove it effectively from your computer. You can see the names of viruses associated with this filename  on this link

If you happen to have access to the rogue/virus installer, you can submit it to threatexpert site and get it analyzed. That will help you to get the precise information about the virus.   

Trying system restore

 If you know the duration since your computer is infected, you can try to restore your computer at a prior date, that will work like a miracle in removing the infection

Free removal tools

  • Special tools to remove a single virus or a family of virus.
  • Free Online virus scanners
  • Fully functioning antivirus/ antispyware
All these tools are listed below

Manual Removal

These are the steps to be taken, if you want to or need to remove the infected files manually

 

Boot in safe mode

Sometimes you will not be able to delete a file even if you find it, in that case you should boot in safe mode and then try to delete it/ them.

 Remove Processes from Task Manager 

Press Ctrl Shift Esc to open Task Manager. See in the list of the processes for a processe/s named "winupdmgr.exe"  select if found and press the End Process button, confirm and then close the Task Manager.

 Optionally you can use Windows Defender to see the path of a currently running program/ process and its publisher, so as to differentiate malware processes from windows genuine processes.

 

Removing entry from windows startup

The system configuration can be started in xp and in vista by typing msconfig in the run box/ start menu search box. In xp by clicking on Start > run . The windows startup is reversible, therefore you can check / uncheck any entry from windows startup any number of times.

After the system configuration window is open, Click on the Startup tab, that will list all the programs that are scheduled to start with windows. Expand the middle column using your mouse pointer so that you can see the full path of the program. Locate and uncheck  "winupdmgr.exe" (look for any other suspicious names)  Press Apply , Press Close/Ok , Select "Restart the computer" at the next prompt.

 View Hidden Files

Before you could delete winupdmgr.exe and its associated files you need to search for them, and before doing that you need to enable to view hidden files and folders 

  •  How to Enable to View Hidden Files and Folders in Windows XP
    •         How to Enable to View Hidden Files and Folders in Windows Vista

Delete Files:

These are the locations where winupdmgr.exe was found on different infected computers

%Windir%\winupdmgr.exe
there are additional files found
%Temp%\IXP000.TMP
%Temp%\IXP000.TMP\reptile.exe   see report 1
%Temp%\kacir.dll                         report2
%System%\scrobj.dll                     report3

 You can find more files in these reports 

%Windir% is C:\Windows or C:\Winnt. %System% refers to the System folder. By default C:\Windows\System (in Windows 95/98/Me), C:\Winnt\System32 (in Windows NT/2000), or C:\Windows\System32 (in Windows XP and Vista). Temp% is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).

Run CCleaner

After deleting winupdmgr.exe and its associated files , as there will be leftover entries in the windows regitry. CCleaner is a free temp files/registry cleaner, that will automatically clean the registry as well as remove the temp files . Click here to read more

Edit Registry

if you are comfortable in using the regedit command. The registry keys are given in the reports in the "Delete Files" section

More Problems

If you are unable to open Task Manager, registry editor, system restore, Folder Options etc

If the virus has disabled them. There are free tools and techniques to solve this problem.  They are listed here.

Tools for Windows XP

Tools for Windows Vista

Use the system file checker

If you want to make sure that the windows system files are not altered by the virus, and in case if they are altered then to repair them.

  •  How to run System File checker utility in windows XP
    •          How to run System File checker utility in windows Vista

Unable to access security related sites

It can happen if your Hosts file has been altered. To repair/ edit the hosts file. Login as administrator. open the following file in notepad
C:\ WINDOWS \system32 \drivers \etc \hosts
remove anything other than 127.0.0.1 Localhost, and save and close the file.

Using Firewall

Check your firewall for any suspicious communication from your computer to the internet and block it using firewall. Here are some of the sites that are detected to have been contacted by different instances of the winupdmgr.exe virus
sead.ath.cx
irc.haxors.net
irc.pimpinjgowns.me
cyber-gods.x0rg.com
bekri.albochat.ch
irc.xstr.info
ddd.burimilol.com
 Reference of threatexpert reports with permission from ThreatExpert.com

Search within this site

Read in your language



Useful Links