Need help after trojan attacks

Discussion in 'Malware Help (A Specialist Will Reply)' started by SHAGGYSGIRL, Mar 18, 2009.

  1. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I have finally gotten the Read & Run Me First to work. I still do not have any internet as all my network adapters are yellow exclamations. Need help seeing if computer is clean of all trojans, etc. and also how to get my network adapters working again. Please help, here are the logs.
     

    Attached Files:

  2. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Need help after trojan attacks - part2

    Here are the other 2 logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to remember to stay in one thread. I had just answered your first thread today tell you to try some special steps. I'm going to go close the first thread now since merging it back here would put things out of order.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I will give you somethings to do but I stongly recommend that you start backing up all necessary personal data before your PC becomes totally unbootable. Your Windows system files have become infected which is why you are having so many problems. Many executable files on your PC may be infected which could mean you will have to perform a totally clean reinstall. DO NOT back up any executable files because they could be carrying the infection and will reinfect your PC if reinstalled. I'll will try to repair some of these files from backups that are on your PC, but I can already see that the below files are infected:

    C:\WINDOWS\system32\ctfmon.exe
    c:\windows\explorer.exe
    c:\windows\system32\userinit.exe

    and so are all backups. Since the last two are required to run your PC, they will run at startup and thus the infection will always load. Do you have your Windows XP SP3 boot CD?

    I also have to warn you that even if we appear to get your PC fixed, it will still be unreliable/untrustworthy.

    First you must disable Spybot's Teatimer as requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer
    Then you need to run MSconfig and put your PC into normal startup mode as requested in step 1 of the READ & RUN ME. You should not be using MSconfig like this.
    The below files do not belong in this folder. Never save files here. Only installed program folders belong here. Move them somewhere else if you want them otherwise delete them:
    Code:
    C:\Program Files\
    proces~1.db   Mar 17 2009     1128432  "PROCESSLISTRELATED.DB"
    proces~2.db   Mar 17 2009    14358888  "PROCESSLIST.DB"
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    Spybot - Search & Destroy 1.4


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    The original disk that I have is Windows XP sp2.

    I apologize but my antivirus did not get fully closed down before running combofix. I did not see that it was running in the tray. If I need to rerun anything, let me know... still have the exclaimation points with all the network connections. Other than unable to get on the internet and booting slow, the computer seems to be running okay. Have 2 errors as the start items load 1. AVG application cannot run due to the electronic verification. 2. hpqthb08.exe (0x000007b) error. Also getting a notification that my windows is not activated and I need to activate. I cannot do this since I do not have internet and also cannot see the screen when it pulls up.

    Gayla
     
  6. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Forgot to post the logs, here they are.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you backed up important data as I suggested? If not, you better do this now before doing my next steps because at any point in time your PC could become unbootable.

    Now put your Windows XP SP2 CD into your CD drive. If any window opens up about installing Windows, just close it. I want you to copy each of the below files from the Windows CD into the C:\MGtools folder. Yes the underscore is part of the filename. I'm assuming in the below that drive D is your CD ROM drive.

    D:\i386\ctfmon.ex_
    D:\i386\explorer.ex_
    D:\i386\spoolsv.ex_
    D:\i386\userinit.ex_

    Once you have copied these files to the C:\MGtools folder, continue with the below.

    Download and save this WinFix to your C:\MGtools folder. You must download it (your browser may call it Save)! Do not Run it. And you must save it there. After you download and save it there, you should see a WinFix.bat file in your C:\MGtools folder. Double click this WinFix.bat file. A black command prompt window will open up briefly (too fast to read) and then disappear. After this finishes, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the new C:\MGlogs.zip file.


    We have not fixed anything yet!!!!! The above is preparation for my next fix. I need to verify that all of the above was completed properly before continuing.
     
  8. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Yes, I believe I have saved off all the documents, etc. that I can save.

    My windows activation expired and blocked me yesterday. I still have no internet and cannot view the activation screen to see what it says. I have to say no to the activation popup and then it will take me back to the login screen, not allowing me to login. I found a work around (the windows +u) to be able to access my desktop and documents, not sure how much I can do. Will try your fix am about to just reformat and reinstall as this is going on 3 weeks now. I use my computer for some remote access contract labor work and for online banking, etc. I really need it up and running as it is becoming an issue borrowing another computer. How quickly do you think we can get this fixed, if we can? I am at work but will try to do your suggestions on my lunch hour and get it posted back to you, assuming your steps don't take too long. If not, will have to do it later tonight.

    Gayla
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As soon as you can do what I requested, I can give you the next step which will can be quickly run. If it works, it might fix some of your problems but I'm not sure about the Windows Activation since that has nothing to do with any of these fixes.[/quote] Since we are restoring some files from SP2, it would mean that a later time that you would have to reinstall the SP3 update.
     
  10. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Tried to run the C:\MGtools\GetLogs.bat several times but could not get it to run with normal bootup. I went into safe mode and was able to run it there.

    Also, the windows activation has expired in the normal mode so I can do the windows+U command and work for a few minutes before being kicked off again. My network adapters are yellow exclamations still.

    In safe mode, windows activation is not showing and I am able to get around. Also I can see my network adapters here although I do not want to plug into the network and try it.

    Gayla
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can do the below in either safe boot or normal boot mode (which ever works). At the end though, I want you to try booting normally to see what happens too.




    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After the reboot from running ComboFix, continue with the below. If it doe snot reboot your PC, reboot it yourself.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  12. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I forgot to tell you that while I was running the C:\MGtools\GetLogs.bat I got the following error:

    processdll.exe the application failed to initalize properly (0x000007b) Click ok to terminate the application


    Gayla
     
  13. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I ran these in safe mode, here are the logs.

    In normal mode, there was no change, still the same problems, nothing looked like it changed.

    Gayla
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It didn't change. ComboFix ran in reduced functionality mode which is why. Did you get a notice about ComboFIx needing to be updated. Delete the current version of combofix.exe from your Desktop and download and save the current version there: combofix.exe

    Then before trying the fix again, make sure you disable AVG.

    Attach the two new logs again.

    Don't worry about the error with processdll.exe.
     
  15. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I did not know how to disable AVG as I could not see it in the task manager or see it loaded so I deleted AVG.

    I ran this in safe mode again but redownloaded combofix and saw the items loading. Here are the new 2 logs.

    Normal mode still has no change.

    Gayla
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You messed up the script and thus it still did not work. You now have the CFScript file named:

    CFscript.txt.lnk

    It has to be named

    CFscript.txt


    You cannot have the .lnk on the end.

    You need to run the procedure again.
     
  17. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    Tried it again. Sorry having to transfer items to and from a thumbdrive.

    Here are the logs, hopefully I did it correct this time. Ran in safe mode.

    Still no change in normal mode.

    Gayla
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay here is what I see.

    The initial fix worked as desired and the files were copied to replace the infected files with versions from SP2. However the fix was short lived because either the infection is running in memory or there are many other infected files which we are not seeing. Thus the infection almost immediately started spreading back to the files we just replaced again.

    Sorry but you have only one option. Format and reinstall. Too many system files are infected and there is no scanner that can cure them.

    However I would appreciate it if you could do the below before you move on to the format of your PC. This may help with our investigation of exactly what this infection is doing to other files.

    Download and save this WinFiles to your C:\MGtools folder. You must download it (your browser may call it Save)! Do not Run it. And you must save it there. After you download and save it there, you should see a WinFiles.bat file in your C:\MGtools folder. Double click this WinFiles.bat file. A black command prompt window will open up with a note telling you to be paitent and the window will close when the scan finishes. After this finishes, attach the C:\MGlogs.zip file which will have a new log in it.
     
    Last edited: Mar 27, 2009
  19. SHAGGYSGIRL

    SHAGGYSGIRL Private E-2

    I ended up running killdisk and reinstalling windows. So far, AVAST has not detected any problems. I would like your suggestions on a virus software. I was using AVG free version prior to this problem and spybot. I came across AVAST and was wondering what you know about it? Or should I run the Superantivrus software?

    Thanks for the help

    Gayla
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Things we recommend are all in the below link which you should work thru now:

    How to Protect yourself from malware!

    You will see that Avast is one of the programs in there. I would stick with Avast or Avira but make sure you only use one.


    If you are referring to SUPERAntiSpyware then it is not an antivirus program. It is an antispyware program as stated in the name.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds