Apparent trojan; problems remain after removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by jcat, Dec 26, 2009.

  1. jcat

    jcat Private E-2

    I am a newbie, hoping I've done everything mostly right. Here is the background of my problem. I was receiving the following message on start up:

    -----------------
    The system is shutting down.
    Please save all work in progress and log off.Any unsaved changes will be lost.
    This shut down was initiated by NT\AUTHORIYSYSTEM Time before shut down(then a countdown starts at 1:00)
    Message The system process 'C:\WINDOWS\SYSTEM32\services.exe' terminated unexpectedly with status code -1073741482.The system will now shut down.)
    ------------------

    The countdown would begin, and when it reached zero sometimes the system would freeze and my only option would be a hard shutdown; other times Windows would finish booting, but it would run at a glacial pace, with no way to run any applications whatsoever.

    I found this thread reporting a similar problem:
    http://forums.majorgeeks.com/showthread.php?t=198430 - and while I couldn't follow the advice regarding shutdown -a (I could never access my start menu successfully), I did go to the Malware Removal instructions. I was able to run SAS once in normal mode - it reporting finding many trojans, reported that it removed them, required a reboot, but it did not successfully reboot, and after that I was unable to run anything else in normal mode again.

    I downloaded Malwarebytes, Combofix, and another program not mentioned on this site, SDFix, to another computer, loaded them onto a thumb drive, renamed them, and attempted, one by one, to run the exe files on the dirty computer in safe mode. I had no luck with MWB or SDFix - they would not run, even in safe mode (no error messages - I'd click the file, and essentially nothing would happen). I was, however, able to run Combofix in safe mode (I had to uninstall my AV program, which is ESET's NOD32, in order to do this - no way to fully disable it in safe mode), and it located and apparently removed infected files.

    After that, I was able to boot up normally. First I re-booted in safe mode and ran SDFix just to check - it didn't find anything. Then I booted normally and ran SAS - this time it found nothing, no trojans. But when I ran MWB, it found five trojans! It removed them, allegedly. Then I ran CCleaner.

    After a few successful reboots, I thought I might be in the clear, so I reinstalled my AV program, set up SAS and MWB to do regular scans and realtime monitoring, and then turned off System Restore, to get rid of any corrupt restore points, and rebooted yet again. But when I attempted to turn System Restore back on, the system hung. This happened two or three times. Then a new thing started: when I booted, MWB loaded first; when SAS loaded a few seconds later, MWB would crash and cause the entire system to freeze. Only solution is to exit MWB before SAS loaded.

    So clearly, something is still wrong. Another run of SDFix in Safe Mode came back negative. I've tried running Combofix again - it crashed twice with BSODs; finally it ran okay, and did not appear to find any errors, though in the process, my original combofix logfile disappeared.

    So all the scanning applications are now reporting back negative - but something is still not right. Suggestions? I have many log files; no idea which ones would be most useful, or if there are any additional ones I need. But I just have no idea what to do next!

    Oh, and I'm on Windows XP SP3.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds