trojan problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by noviceseeking.lol, Jun 24, 2008.

  1. noviceseeking.lol

    noviceseeking.lol Private E-2

    hi guys

    was called by a friend to help with his pc today - problem is its black screen.

    managed to get it into safemode ( but still blackscreen) and run a housecall scan which detected troj-zeroml.fv and troj-dloader.dtk.

    cant find anything on the net ( or this site) about those 2 and i am unable to run ur normal cleaning procedures without ur advice as its still blackscreened.

    i can get control alt del to work but if i save programs to desktop obviously i cant see them ( but i can see program folders on drive c)

    the problem is when u try to run a program it comes up with windows error and wont run.and housecall detected alot of vulnerabilities as well as those 2 trojans but failed to clean or resolve them.

    can u tell me how ( or should i) turn off system restore?
    how can i run ur standard clean?
    he has no back up disks (partition on drive) would it be better to just wipe it all and if so how given blackscreen probs?

    all i know is that he is running windows xp as he hasnt got a clue regarding his specs except for that.

    i cannot open alot of the stuff from ctrl alt del it just says error so i cant get to restore that way or through "my computer" to try a restore and i am not sure when he last made a safe point anyways or if that would resolve the issue.

    any advice would be appreciated especially regarding just getting ur basic clean done so i can provide you with anymore information u may need.

    many thx
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you run explorer.exe from Task Manager does the Desktop appear.

    Don't save them to the Desktop. Save them to the root folder like C:\ which is where you should attempt to put MGtools.exe from the READ & RUN ME and then run it from Task Manager by simply entering C:\MGtools.exe into the New Task (Run...) box. If that runs, you need to get the C:\MGlogs.zip file from this PC somehow and attach it here.

    We need to know exact word for word error messages and error numbers.

    What exactly did it detect and where?

    No!!!!! You may need to use it to get the PC more functional. In fact if you cannot get us any logs, you may as well just try running System Restore to go back to a restore point before all this happened.

    Does he actually have a Windows XP bootable CD that you can reinstall from?
     
  3. noviceseeking.lol

    noviceseeking.lol Private E-2

    Thx for your responses.

    1) the desktop never re-appears.....i can access task manager which comes up alone-rest of screen is black screen.

    2) there is no back up / re load Cd his copy of windows is on a hard drive partition on PC

    3) i cant access system restore or i would have attempted a restore to an earlier time

    4) the error message displayed is alot of 0's ending with a 5...something like 0x00000005.but definately all 0's then a 5

    5) right clicking or attemtping to run access ANY program results in this error code

    6) housecall detected system vulnerabilities too numerous to list (approx 100+) and the 2 trojans stated.

    7) i dont have easy access to this friends pc as he lives a distance away so when i get there i have no access to another pc and he is partially disabled so he relies on his pc for alot of things.

    the problem therefore is that anything i take to fix this must go with me i cant just go backwards and forwards.


    i was considering creating a system rescue disk on my own PC but i use vista and he is xp.........would that help or work? i have kaspersky internet security.

    8) i will attempt to run MGtools.exe as suggested but all other programs on pc i have attempted result in the error code.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And how did you attempt to run System Restore. Did you try accessing it from Task Manager? Did you try running C:\WINDOWS\SYSTEM32\Restore\rstrui.exe

    I said I need exact word for word messages with error numbers. Guesses or something like, do not help. If you want help, you have to be specific. Otherwise the help you get will be non-specific.

    I only asked about the 2 trojans.

     
  5. noviceseeking.lol

    noviceseeking.lol Private E-2

    please see attached logs

    scans indicated virtuomonde

    problems persist

    many thx for your help so far
     

    Attached Files:

  6. noviceseeking.lol

    noviceseeking.lol Private E-2

    combo scan log
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to start by disabling Spybot's Teatimer as requested in the READ & RUN ME.

    In the future, please download MGtools.exe where requested. You put it here: C:\Program Files\adam fix\MGtools.exe which is not where specified. In some instances, tools will not run properly when instructions are not followed. ;)

    What are the two below startups? If unknown, add them to the HijackThis fix below.
    O4 - Startup: Flying Fingers.lnk = C:\FINGERS\FLYING.EXE
    O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE

    What are the below files and why are they in this folder? If they are needed, move them somewhere else into a folder that indicates what they are.
    Code:
    2002-01-22 16:40 9,390,361 ----a-w C:\Documents and Settings\Syd\unpack.exe
    2002-01-22 16:33 41,806 ----a-w C:\Documents and Settings\Syd\RegSetup.exe
    2001-12-19 20:09 974,848 ----a-w C:\Documents and Settings\Syd\golf.exe
    2001-12-19 18:25 393,216 ------w C:\Documents and Settings\Syd\jgl.dll
    2001-12-19 15:23 1,273,898 ------w C:\Documents and Settings\Syd\jgld.dll
    2001-12-18 14:52 458,752 ------w C:\Documents and Settings\Syd\sound.dll
    2001-12-17 13:25 290,816 ------w C:\Documents and Settings\Syd\autorun.exe
    2001-12-14 15:12 454,719 ------w C:\Documents and Settings\Syd\Terrain.dll
    2001-11-27 10:17 291,328 ------w C:\Documents and Settings\Syd\binkw32.dll
    2001-08-20 16:54 65,536 ---h--w C:\Documents and Settings\Syd\go_ez.exe
    2001-08-20 16:53 577,536 ---h--w C:\Documents and Settings\Syd\Sid Meier's SimGolf_EZ.exe
    Uninstall the below software:
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    SurfingAdvisor

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {44106788-c419-4638-a111-e750b768df27} - (no file)
    O2 - BHO: (no name) - {9C23039D-6862-4149-A1C4-859DCB5B10F5} - (no file)
    O2 - BHO: (no name) - {A8A52F72-A465-55DC-8314-0845523C9DA5} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O20 - AppInit_DLLs: wqkvtepl.dll yxymstvr.dll

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi Chas

    i didnt install tea timer-he had it instaklled b4 thse problems started..removed it now. but didnt see it at first.apologies.

    followed your instructions all appeared successful-reg edit was successful

    SYstem is immensely improved.....(not sure its 100% still seems a little sluggish to me?)

    logs requested attached

    many thanks for your help so far

    novice
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then have HijackThis fix items like the below which are unnecessary and waste system resources. A PC with only 512 MB of RAM cannot have all this stuff loading. Windows XP runs much better with a minimum of 1 GB.

    Not according to your logs! You needed to disable it before running the procedure. Please see the below and make sure you get it disabled now:

    How to disable Spybot's TeaTimer



    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, look for the above files and folders and if they still exist, delete them yourself.

    Now run the fixme.reg patch again by double clicking on the file you saved to your Desktop in the previous fix.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jul 4, 2008
  10. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi Chas attached are the logs u requested

    system is very improved indeed (maybe clear?)

    BUT

    there is 1 issue when i run the C Cleaner in ur instructions it runs but i get an error saying

    error in InetCpl.cpl
    Missing Entry:ClearMyTracksByProcess


    i dont know if this is something to worry about-obviously no error is good.

    The reg edit said it was successful

    Many thanks
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What tab or procedure did you run in CCleaner. We only ask you to run the CCleaner. We specifically state do not run the Scan for Issues selection under the Registry tool.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. noviceseeking.lol

    noviceseeking.lol Private E-2

    Hi Chas

    thank you so much for all your help...final steps completed

    system running normally

    keep up the sterling work........a great many of us would be lost without the geeks!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds