Malware Issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rtstone, Jun 21, 2011.

  1. rtstone

    rtstone Private E-2

    Hello,

    I have followed the procedures in the malware removal thread (http://forums.majorgeeks.com/showthread.php?t=139313) exactly and was not able to remove the malware that was originally detected by hijackthis. The Trojans that were detected are as follows

    C:\WINDOWS\system32\ctfmon.exe (which is a CoolWebSearch variant)
    C:\WINDOWS\system32\browseui.dll (which is the Registry key autorun for the ctfmon.exe)

    I will attach all of the logs to this thread that were taken during the tutorial. Once I do this will someone please help me get rid of this nasty thing. It is really slowing my machine down.

    Thanks,

    Robert
     
  2. rtstone

    rtstone Private E-2

    Here is the first set of logs
     

    Attached Files:

  3. rtstone

    rtstone Private E-2

    Here is the final set of logs. If anyone can tell me how to remove this nasty trojan I will be very grateful!

    Thanks,

    Robert
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You forgot the log from SUPERAntiSpyware and note that your copy of Malwarebytes is extremely out of date ( almost 3000 database versions behind ).

    HijackThis does not detect malware. It makes no claims whatsoever about things in the log. It is just a log of various running processes and registry or which 99% are valid and normal.

    Normal and valid entries and files that you don't need to worry about.

    Are you actually having any malware problems?


    These are not slowing your PC down. They are normal. Slow PCs are not always due to malware as stated in the READ & RUN ME.



    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any/every application?
    • Is it also slow in safe boot mode?
    • Also are any processes showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't have any to remove. Your logs are clean. However who put all those entries into the Trusted Zone and why. There is very rarely a need to put things into the Trustes Zone and doing that should be done with care and only when 100% required.
     
  6. rtstone

    rtstone Private E-2

    First and foremost I know hijackthis just shows the running processes on the machine and most are valid entries. There is a tool that can be used to analyze hijackthis logs at the following url: http://hjt.networktechs.com/ and it attempts to tell you what are valid entries and what are not.

    As far as my machine being slow, what I am referring to is not a memory issue or a resources issue. If I look at my resources when my machine is responding slowly I still have 98% of my resources in system idle processes. My machine freezes when trying to open Windows Explorer and then my whole machine locks up. Then when I try to shut the machine off, a pop-up occurs that says can not shut down please close "hidden fax window". I then have to manually shut my machine off and reboot.

    As far as who put those things in a trusted zone, that would be the "geniuses" in the IT department at my office. I don't have control over most of the policies on this machine as it is a work machine. I don't have issues on my personal machines ever! I only experience these issues on machines with our corporate load of Windows XP with all the policies that they require.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attempts being the operative word... those scanalyzers are nothing but bad news. You cannot trust them at all.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds