Infected by a sinowal trojan. please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Heyctg, Mar 23, 2010.

  1. Heyctg

    Heyctg Private E-2

    The other day my PC which is windows xp sp2 apparently got infected. The pc locked up and let out a high pitched sound like a key was pressed in. I have avira premium and did a scan, found sinowal/gen.2 in the internet temp files and at least one dll file. Also HEUR/HTML.Malware. I removed these and deleted the files. Downloaded GMER and did a scan of everything but files, it does not show an MBR infection. Though i am less than confident. The pc often locks up now where i can move the cursor but not close any programs or even click on the start button. I am running IE 8 and have turned on the internet firewall. I have not heard the beepings ound since but programs are still becoming unsreposnive and when I close an IE window it often bleeds into other windows. Any help would be very appreciated
     
  2. Heyctg

    Heyctg Private E-2

    I did before all the steps in the guideline...here is the malwarebytes log:
    Malwarebytes' Anti-Malware 1.44
    Database version: 3907
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    3/23/2010 9:43:35 PM
    mbam-log-2010-03-23 (21-43-35).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 404516
    Time elapsed: 1 hour(s), 20 minute(s), 27 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 3

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\ck_1.05.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
    C:\Program Files\Paradox Entertainment\Crusader Kings\Crusaders.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{D947D7BA-2F2F-4BF1-A0F5-2404BD75DBFE}\RP135\A0040819.exe (Rogue.Crusader) -> Quarantined and deleted successfully.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Then please re-read step 3 from here: Windows XP Cleaning Procedure and observe the below line and what is under it:
     
  4. Heyctg

    Heyctg Private E-2

    sorry...ok, malwarebyte and combofix uploaded, rootrepeal keeps locking up.freezing even in safe mode. I had my anti virus and firewall off. i did not run the last cleaning tool because rootrepeal has not finished
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the log from SUPERAntiSpyware and you need to run MGtools as requested and attach the C:\MGlogs.zip file.
     
  6. Heyctg

    Heyctg Private E-2

    Will do, but for now i have larger issues preventing me from doing this. Windows is not booting as of yesterday. i can get to the recovery console so i think it is a logical failure and not a HD failure. But i want to be able to back up some files still before i delete the partition and do a clean wipe. Should i try fixmbr and fixboot after booting from the windows cd? I would be happy to even get into safe mode to back up the few music albums i purchased last week
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes since ComboFix detected a potential problem in your MBR, this would be worth a try. However this does not normally cause a problem with being able to boot. You could have other problems and may need to try the below from the Recovery Console.

    http://support.microsoft.com/default.aspx?scid=kb;en-us;307545&sd=tech
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds