CTFMONB blue screen, cock roaches..tried several things but computer still not right

Discussion in 'Malware Help (A Specialist Will Reply)' started by k.smith, May 7, 2008.

  1. k.smith

    k.smith Private E-2

    surfing net and evidently opened something I should not have. Immediately blue screen appeared with yellow warning sign. Shortly after, screen was being eaten by roaches. Did some searching and found new files (ctfmonb) as well as others. Avg picked up on 2 trojans and were healed and deleted. I ran every spyware program I knew to run along with malware and came up with very little. Ran combofix and some files were targeted but still have blue screen and computer is very slow. especially during startup. 8 minutes to load everything in auto load (avg, sound icon, activesync). I have checked desktop properties and see desktop background for ctfmonb but can not get rid of it. I have completed all of the xp cleaning procedures and programs. Please help I am at wits end.
     

    Attached Files:

  2. k.smith

    k.smith Private E-2

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    mglog attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    Welcome to Major Geeks!

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ctfmona] C:\WINDOWS\system32\ctfmona.exe

    After clicking Fix, exit HJT.


    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. k.smith

    k.smith Private E-2

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    Performed listed tasks. One exception. ran hijackthis. Found O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (and fixed). Could not find O4 - HKLM\..\Run: [ctfmona] C:\WINDOWS\system32\ctfmona.exe......... I had run Ccleaner earlier after thread started. Perhaps that deleted it?
    I did get a confirmation of fixme.reg.

    Few strange instances at boot up. At boot up, windows update flashed on tool bar, showed no signs of update and quickly went away. Still took over 8 minutes to complete auto loads and finally after 20 minutes sound icon appeared in tool bar. I was able to finally get rid of blue screen. Changed desktop to different theme then went back and checked for ctfmond and did not show.
     

    Attached Files:

  5. k.smith

    k.smith Private E-2

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    sorry meant ctfmonb
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    Your logs are clean. I'll give you a few more things to do to tweak startup but this is not malware.

    First begin by uninstalling SUPERAntiSpyware since we are finished with it now.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')

    After clicking Fix, exit HJT.

    Then reboot and see how things are working. If you still have problems, you should investigate whether you really use and need the below startup processes. You can search for the EXE or DLL files on Google to get more info about them.

    O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
    O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HPINST~1\plugin\bin\PCHButton.exe
    O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
    O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
     
  7. k.smith

    k.smith Private E-2

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    Thank you for all of your help. You all are the greatest and Majorgeeks has always been there for us. Can't say thank you enough. Computer working much better now.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. k.smith

    k.smith Private E-2

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    Very sorry chaslang. Did not know if this was still part of malware problem. Did not get hard answer from other threads. For info purposes I performed the first set of 04 fixes but left the second alone. sorry for the inconvenience, won't happen again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    No it is very unlikely to be related. Nothing that we fixed is related to the problems you have mentioned.

    Okay! I just wanted to be sure of what fixes you may have applied.
     
  11. k.smith

    k.smith Private E-2

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    I tried a fix at kellys korner and it seemed to work for me. Would like to pass it along for you to comment on and possibly help others. Researched notifications tray problems and found many people talking about past icons stream. Navigated through regedit and found my past icons stream to be extremely full. Went to kellys korner #53 and ran. It has seemed to correct my problem atleast. Thoughts are appreciated.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: CTFMONB blue screen, cock roaches..tried several things but computer still not ri

    I'm happy to hear you got your problem resolved.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds