Help needed reader_s.exe malware/trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Vpw, Jul 24, 2009.

  1. Vpw

    Vpw Private E-2

    Hello,
    Im new to this forum so pls excuse any obvious mistakes in posting. I have seen the other reader_s.exe threads, but am not sure if they will help me.

    I'd like to first explain what happened. I have a Dell 620 laptop, with a single partition (I never created multiple partitions, mistake #1) running XP. I have avast free version AV installed but nothing better (mistake #2). About 3 days back while connected to the net I probably downloaded something (through a download manager) which resulted in the infection (I don't remember running any .exes explicitly, except unzipping some files). I got a blue screen and on restarting Im getting strange behaviour:
    1. XP logon screen was replaced with a win 2k kind of logon. Explorer was not running after logon, and I had to run it from task manager. Active desktop was disabled.
    2. Found multiple instances of reader_s.exe, servises.exe (NOTE: not services.exe) and some processes like a.exe, b.exe, etc running.
    3. I checked with autoruns to disable these processes which were being run at logon, but this resulted in a blue screen.
    4. I was getting some Dell data protection messages earlier which prevented the Logon UI process from executing etc. I was trying to boot into the Last known good configuration. I managed to install and run mcafee AV, but it resulted in a blue screen after a while.
    5. Now while booting Im getting a: STOP: c000021a {Fatal System Error} The windows logon process system process terminated unexpectedly with a status of 0xc0000005 (0x00000000 0x00000000) kind of message and blue screen. When I try Safe mode boot, or last known good configuration, the same happens.

    Im not connecting to the internet with this laptop now as I read that this trojan feeds from the net. I don't think I am in a position to follow the instructions given in this forum for the Malware removel guide, Windows XP cleaning procedure, etc. though I have downloaded the .exes on another laptop - I have no way to install and run them on the infected computer.

    I would ideally like to preserve and backup as much data (no exes) from the laptop as possible as I have important stuff there. What should I do?? Is it even possible to recover from this point? Pls help! I will follow all the steps as suggested to make sense of this problem, and to recover/salvage whatever I can! Im just cursing Windows, my luck and myself (for being so lax on security earlier), for such a thing to happen.

    thanks,
    -Vardhan
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please READ everything below before doing anything.

    This may be the first thing you want to try doing before things get any worse. The below CDs may help but you will have to get help in the Software Forum on using things like these since it is outside the realm of the Malware Forum to do this as we are too busy with actual malware removal.

    http://trinityhome.org/Home/index.php?wpid=1&front_id=12

    http://www.sysresccd.org/Main_Page


    If you can no longer boot your PC, there is not much we can do for you to remove malware other than suggest you scan the drive by slaving it into another properly protected PC but slaving a laptop drive requires special hardware so this may not be an option for you. Or another option is using another PC to make CDs like the below and use them to scan your PC:

    http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html

    UBCD4Win


    However, you may want to try the below if you have your Windows boot CD or the Recovery Console installed. This could possibly get your PC bootable again.

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds