can't get rid of trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by shibo2501, Aug 22, 2010.

  1. shibo2501

    shibo2501 Private E-2

    Hi
    I've followed all instructions in "windows XP cleaning procedure" unfortunately malware still there.

    I was downloading various torrent files when problems started so one of them must have been infected. This was one week ago.

    At first suddenly I couldn't launch any programs it always returned "impossible because this program is infected". Enve ctrl-alt-del didn't work. I couldn't go to internet except on one only site, which advised me to download a paying software to remove malware. (of course I didn't trust this site).

    So I rebooted in secure windows mode and performed a scan with avg antivirus.

    Many problems were identified, trojans and malware. The antivirue program claimed to have removed them.

    then I booted normally and things seemed to work except that I had error messages at each boot "can't find this program, please reinstall...) and also regurlarly my antivirus program claimed to have stopped an infection, always a trojan.

    Then while playing a game, suddenly every minute I would be returned to windos (with the game still running in the background).

    I performed a scan and found again all the viruses supposedly removed.

    Than I found the windows XP cleaning procedures on this site and tried it.

    Then I performed a scan and there's still a trojan. Plus I still have 3 error messages when windows starts.

    Finally windows cannot start by itself, it says it can't find the disk with booting instructions. i have to strike F12 when computer starts and then select drive C.

    Herewith enclosed 4 of the log files. There are 2 combofix files because at first scan, combofix rebooted and then my antivirus was opened again automatically and probably interfered in the scan.

    I'l post a second message for other logs needed.

    Any reply will be highly apprciated.

    Thanks
     

    Attached Files:

  2. shibo2501

    shibo2501 Private E-2

    herewith enclosed other logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I still need the log from running the C:\MGTools.exe --> C:\MGLogs.zip.

    In the meantime, let's use Combo:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    RenV::
    c:\program files\Analog Devices\Core\smax4pnp .exe
    c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint .exe
    c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService .exe
    c:\program files\Java\jre6\bin\jusched .exe
    c:\program files\Wave Systems Corp\SecureUpgrade .exe
    c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck .exe
    c:\program files\Wave Systems Corp\Services Manager\DocMgr\bin\WavXDocMgr .exe
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. shibo2501

    shibo2501 Private E-2

    please find herewith enclosed mglogs.

    About combofix, here's what happened :

    i uninstalled my antivirus program.

    Then created the txt file needed, put it and combofix on the desktop.

    Then dragged the txt file onto combofix.exe.

    Combofix started its job, then decided it needed to reboot.

    as usual, reboot doesn't work automatically. When computer tried to restart, it said no disk available. so I booted again, striked F12 ans selected C:.

    Then windows started and combofix came back, continuing its job.

    Then windows disappeared and I got a blue screen with lots of talk (there was an error, please reboot, if problem occurs again try secure mode...) and following errors :

    STOP : 0x0000001 (0xE2441000, 0x0000001C, 0x00000001, 0xB88B241D)

    mbr.sys - adress B88B241D base at B88B1000, datestamp 4add63e5

    There was nothing that could be done from that screen so I rebooted. Windows started (after striking F12 etc) but combofix was gone.

    I started the procedure all over again and got the same outcome.
     

    Attached Files:

  5. shibo2501

    shibo2501 Private E-2

    Wanted to add that I've been very careful not to click anywhere during combofix scan. All browsers and all tasks were closed.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware on your system. However, do you know what this is:

    C:\Documents and Settings\All Users\Application Data\3xb22bx.dat

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    I suggest you post in the software forum to get assistance with your BSOD issues.

    Tell me what malware issues you may still be having, if any.
     
  7. shibo2501

    shibo2501 Private E-2

    No I don't know what this file is.

    Procedure with hijackthis done.

    I enclose my last antivirus report (a few hours ago). It's in french but in short it says it found following trojan :

    TR/Patched.Gen

    I get this info every time I run a scan (every day).
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Best I can make out from my little bit of French, it is reporting a problem in your system restore folder. You can only remove that by toggling system restore.


    • Refer to the cleaning procedures pointed to by step 7 of the READ ME
      for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.


    What other issues are you having?
     
  9. shibo2501

    shibo2501 Private E-2

    Thanks a lot for your time. Unfortunately when you said no virus could be found on my system I thought there was nothing more that could be done, so I formated everything and installed windows again. I wish I had read your reply first, though, because now i have display problems (but not due to malware anymore)

    I guess I'll post another thread in another forum about that.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry to hear that. I suggest you post in the software forum for assistance with your display issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds